Search

Found 20,866 results in 959ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-66516 unknown FIX debian debian 6mo ago Apache Tika has XXE vulnerability
CVE-2025-40264 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: be2net: pass wrb_params in case of OS2BMC be_insert_vlan_in_pkt() is called with the wrb_params argument being NULL at be_send_pk…
CVE-2025-40263 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: Input: cros_ec_keyb - fix an invalid memory access If cros_ec_keyb_register_matrix() isn't called (due to `buttons_switches_only`…
CVE-2025-40262 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: Input: imx_sc_key - fix memory corruption on unload This is supposed to be "priv" but we accidentally pass "&priv" which is an ad…
CVE-2025-40261 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: nvme: nvme-fc: Ensure ->ioerr_work is cancelled in nvme_fc_delete_ctrl() nvme_fc_delete_assocation() waits for pending I/O to com…
CVE-2025-40257 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: mptcp: fix a race in mptcp_pm_del_add_timer() mptcp_pm_del_add_timer() can call sk_stop_timer_sync(sk, &entry->add_timer) while a…
CVE-2025-40254 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: remove never-working support for setting nsh fields The validation of the set(nsh(...)) action is completely wr…
CVE-2025-40250 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Clean up only new IRQ glue on request_irq() failure The mlx5_irq_alloc() function can inadvertently free the entire rma…
CVE-2025-40214 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: af_unix: Initialise scc_index in unix_add_edge(). Quang Le reported that the AF_UNIX GC could garbage-collect a receive queue of …
CVE-2024-3884 unknown debian debian 6mo ago Undertow OutOfMemory when parsing form data encoding with application/x-www-form-urlencoded
CVE-2025-55182 unknown 2.5 KEVEXP aws 6mo ago Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Ser…
CVE-2025-66453 unknown slesdebian debian 6mo ago Rhino has high CPU usage and potential DoS when passing specific numbers to `toFixed()` function
CVE-2025-65955 unknown FIX debian debian sles 6mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests …
CVE-2025-13472 unknown 6mo ago BlazeMeter Jenkins Plugin is Missing Authorization for Available Resources
CVE-2021-26828 unknown 1.5 KEV 6mo ago OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.
CVE-2025-61727 unknown FIX debian debian sles 6mo ago An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com doe…
CVE-2025-64460 unknown FIX slesdebian debian 6mo ago Django is vulnerable to DoS via XML serializer text extraction
CVE-2025-13372 unknown FIX slesdebian debian 6mo ago Django is vulnerable to SQL injection in column aliases
CVE-2025-10939 unknown 6mo ago Keycloak unable to restrict access to the admin console
CVE-2025-11538 unknown 6mo ago Keycloak has debug default bind address
CVE-2025-48633 unknown 1.5 KEV 6mo ago Android Framework contains an unspecified vulnerability that allows for information disclosure.
CVE-2025-48572 unknown 1.5 KEV 6mo ago Android Framework contains an unspecified vulnerability that allows for privilege escalation.
CVE-2025-55749 unknown 6mo ago XWiki Jetty Package (XJetty) allows accessing any application file through URL
CVE-2025-64775 unknown 6mo ago Apache Struts is Vulnerable to DoS via File Leak
CVE-2025-12183 unknown debian debian 6mo ago LZ4 Java Compression has Out-of-bounds memory operations which can cause DoS
CVE-2025-66372 unknown 6mo ago Mustangproject allows exfiltrating files via XXE attacks
CVE-2021-26829 unknown 1.5 KEV 6mo ago OpenPLC ScadaBR contains a cross-site scripting vulnerability via system_settings.shtm.
CVE-2025-3261 unknown 6mo ago ThingsBoard allows an authenticated user to upload malicious SVG images
CVE-2025-54057 unknown 6mo ago Apache SkyWalking has a stored XSS vulnerability
CVE-2025-66035 unknown FIX debian debian 6mo ago Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF tok…
CVE-2025-62728 unknown 6mo ago Hive Metastore Server is vulnerable to SQL Injection
CVE-2025-59390 unknown 6mo ago Apache Druid’s Kerberos authenticator uses a weak fallback secret
CVE-2025-66021 unknown 6mo ago OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitization
CVE-2025-9624 unknown debian debian 6mo ago OpenSearch is vulnerable to DoS via complex query_string inputs
CVE-2025-58360 unknown 2.5 KEVEXP 6mo ago OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accepts XML input through a specific endpoint /geoserver/wms operation…
CVE-2025-21621 unknown 6mo ago GeoServer has a Reflected Cross-Site Scripting (XSS) vulnerability in its WMS GetFeatureInfo HTML format
CVE-2025-65998 unknown 6mo ago Apache Syncope's AES encryption stores hard-coded passwords in internal database
CVE-2025-62609 unknown 7mo ago MLX has Wild Pointer Dereference in load_gguf()
CVE-2025-62608 unknown 7mo ago MLX has heap-buffer-overflow in load()
CVE-2025-61757 unknown 1.5 KEV 7mo ago Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager.
CVE-2025-47914 unknown FIX debian debian sles 7mo ago SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.
CVE-2025-58181 unknown FIX debian debian sles 7mo ago SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.
CVE-2025-64408 unknown 7mo ago Apache Causeway vulnerable to deserialization in Java
CVE-2025-12119 unknown FIX debian debian 7mo ago A mongoc_bulk_operation_t may read invalid memory if large options are passed.
CVE-2025-13223 unknown 1.5 KEVFIX debian debian 7mo ago Google Chromium V8 contains a type confusion vulnerability that allows for heap corruption.
CVE-2025-65089 unknown 7mo ago XWiki view file macro: User can view content of office file without view rights on the attachment
CVE-2025-12383 unknown 7mo ago Eclipse Jersey has a Race Condition
CVE-2025-65015 unknown FIX debian debian 7mo ago joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions from 1.3.3 to before 1.3.5 and from 1.4.0 to before 1.4.2, the …
CVE-2025-54990 unknown 7mo ago XWiki AdminTools application doesn't set permissions on the AdminTools space
CVE-2025-58034 unknown 2.5 KEVEXP 7mo ago Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI comman…
CVE-2025-65073 unknown FIX debian debian 7mo ago OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization.
CVE-2025-13266 unknown 7mo ago vlife-base has Path Traversal vulnerability
CVE-2025-13265 unknown 7mo ago lsFusion Server is vulnerable to Path Traversal through its unpackFile function
CVE-2025-13261 unknown 7mo ago lsFusion Platform has a Path Traversal vulnerability
CVE-2025-64446 unknown 2.5 KEVEXP 7mo ago Fortinet FortiWeb contains a relative path traversal vulnerability that may allow an unauthenticated attacker to execute administrative commands on the system via crafted HTTP or HTTPS requests.
CVE-2025-64507 unknown FIX debian debian 7mo ago Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incus user in an environment where an unprivileged user may have root access to a c…
CVE-2025-64500 unknown FIX debian debian 7mo ago Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundation component defines an object-oriented layer for the HTTP specification. Start…
CVE-2025-64099 unknown 7mo ago OpenAM: Using arbitrary OIDC requested claims values in id_token and user_info is allowed
CVE-2025-62780 unknown 7mo ago changedetection.io: Stored XSS in Watch update via API
CVE-2025-63396 unknown debian debian 7mo ago An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.profiler.profile (PythonTracer) to crash or hang during finalization, leading to a Denial of Service (D…
CVE-2025-40163 unknown FIX slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: sched/deadline: Stop dl_server before CPU goes offline IBM CI tool reported kernel warning[1] when running a CPU removal operatio…
CVE-2025-9242 unknown 1.5 KEV 7mo ago WatchGuard Firebox contains an out-of-bounds write vulnerability in the OS iked process that may allow a remote unauthenticated attacker to execute arbitrary code.
CVE-2025-62215 unknown 2.5 KEVEXP 7mo ago Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful exploitation of this vulnerability could ena…
CVE-2025-12480 unknown 1.5 KEV 7mo ago Gladinet Triofox contains an improper access control vulnerability that allows access to initial setup pages even after setup is complete.
CVE-2025-64518 unknown 7mo ago CycloneDX Core (Java): BOM validation is vulnerable to XML External Entity injection
CVE-2025-21042 unknown 1.5 KEV 7mo ago Samsung mobile devices contain an out-of-bounds write vulnerability in libimagecodec.quram.so. This vulnerability could allow remote attackers to execute arbitrary code.
CVE-2025-67897 unknown FIX debian debian 7mo ago In Sequoia before 2.1.0, aes_key_unwrap panics if passed a ciphertext that is too short. A remote attacker can take advantage of this issue to crash an application by sending a victim an encrypted me…
CVE-2025-64326 unknown 7mo ago Weblate leaks the IP of project member inviting user to be reviewer in Audit log
CVE-2025-10713 unknown 7mo ago WSO2 Carbon Mediation vulnerable to XML External Entity (XXE) attacks
CVE-2025-64459 unknown 1.0 EXPFIX debian debian 7mo ago Django vulnerable to SQL injection via _connector keyword argument in QuerySet and Q objects.
CVE-2025-64458 unknown FIX debian debian 7mo ago Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
CVE-2025-48703 unknown 1.5 KEV 7mo ago CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in…
CVE-2025-11371 unknown 2.5 KEVEXP 7mo ago Gladinet CentreStack and Triofox contains a files or directories accessible to external parties vulnerability that allows unintended disclosure of system files.
CVE-2025-11953 unknown 1.5 KEV 7mo ago React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server and run arbitrary e…
CVE-2025-62275 unknown 7mo ago Liferay Portal and DXP do not check permissions of images in a blog entry
CVE-2025-62276 unknown 7mo ago Liferay Portal and DXP use an incorrect cache-control header
CVE-2025-62267 unknown 7mo ago Liferay Portal and DXP affected by multiple cross-site scripting (XSS) vulnerabilities in web content template’s select structure page
CVE-2025-62264 unknown 7mo ago Liferay Portal Vulnerable to Reflected XSS via the selectedLanguageId Parameter
CVE-2025-57108 unknown debian debian 7mo ago Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector me…
CVE-2025-57107 unknown debian debian 7mo ago Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accesso…
CVE-2025-57106 unknown debian debian 7mo ago Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing…
CVE-2025-62265 unknown 7mo ago Liferay Portal is vulnerable to XSS in the Blogs widget
CVE-2025-62266 unknown 7mo ago Liferay Portal is vulnerable to DNS rebinding attacks
CVE-2025-62257 unknown 7mo ago Liferay Portal vulnerable to password enumeration
CVE-2025-13327 unknown FIX slesdebian debian 7mo ago A flaw was found in uv. This vulnerability allows an attacker to execute malicious code during package resolution or installation via specially crafted ZIP (Zipped Information Package) archives that …
CVE-2025-61724 unknown FIX debian debian sles 7mo ago The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, this can cause excessive CPU consumption.
CVE-2025-58188 unknown FIX debian debian sles google 7mo ago Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arb…
CVE-2025-58186 unknown FIX debian debian sles 7mo ago Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of very small cookies such as "a=;", an attacker can make an HTTP …
CVE-2025-58185 unknown FIX debian debian sles 7mo ago Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion.
CVE-2025-47912 unknown FIX debian debian sles 7mo ago The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host compon…
CVE-2025-61723 unknown FIX debian debian sles google 7mo ago The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input. This affects programs which parse untrusted PEM inputs.
CVE-2025-58189 unknown FIX debian debian sles 7mo ago When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.
CVE-2025-58187 unknown FIX debian debian sles google 7mo ago Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate. This affects programs which validate ar…
CVE-2025-61725 unknown FIX debian debian sles 7mo ago The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption.
CVE-2025-64150 unknown 7mo ago Jenkins Publish to Bitbucket Plugin is missing a permissions check
CVE-2025-64149 unknown 7mo ago Jenkins Publish to Bitbucket Plugin vulnerable to CSRF and missing permissions check
CVE-2025-64148 unknown 7mo ago Jenkins Publish to Bitbucket Plugin is missing a permissions check
CVE-2025-64147 unknown 7mo ago Jenkins Curseforge Publisher Plugin does not mask API Keys displayed on the job configuration form
CVE-2025-64145 unknown 7mo ago Jenkins ByteGuard Build Actions Plugin does not mask API tokens displayed on the job configuration form
CVE-2025-64144 unknown 7mo ago Jenkins ByteGuard Build Actions Plugin stores API tokens unencrypted in job config.xml files