Search

Found 20,975 results in 703ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-43757 unknown 10mo ago Liferay Portal Vulnerable to Cross-Site Scripting via DDMPortlet_definition Parameter
CVE-2025-43746 unknown 10mo ago Liferay Portal Vulnerable to Cross-Site Scripting in Dynamic Data Mapping
CVE-2025-5115 unknown FIX debian debian sles 10mo ago Eclipse Jetty affected by MadeYouReset HTTP/2 vulnerability
CVE-2025-43748 unknown 10mo ago Liferay Portal Vulnerable to Cross-Site Request Forgery
CVE-2025-43750 unknown 10mo ago Liferay Portal Unvalidated File Upload
CVE-2025-43749 unknown 10mo ago Liferay Portal Unauthenticated File Access via URL
CVE-2025-43742 unknown 10mo ago Liferay Portal Vulnerable to Cross-Site Scripting through URLs
CVE-2025-43741 unknown 10mo ago Liferay Portal Vulnerable to Cross-Site Scripting via assetTagNames Parameter
CVE-2024-39954 unknown 10mo ago Apache EventMesh Vulnerable to Server-Side Request Forgery in WebhookUtil.java
CVE-2025-43744 unknown 10mo ago Liferay Portal Vulnerable to Cross-Site Scripting via DDM Structure Field Labels
CVE-2025-43743 unknown 10mo ago Liferay Portal Enumeration Discrepancy in Calendars
CVE-2025-43745 unknown 10mo ago Liferay Portal CSRF Vulnerability via Endpoint Parameter
CVE-2025-43737 unknown 10mo ago Liferay Portal Vulnerable to Cross-Site Scripting via backURL Paramter
CVE-2025-43738 unknown 10mo ago Liferay Portal Reflected Cross-Site Scripting Vulnerability in displayType Parameter
CVE-2025-43739 unknown 10mo ago Liferay Portal Email Modification Vulnerability via Calendar Portlet
CVE-2025-43731 unknown 10mo ago Liferay Portal Vulnerable to Cross-Site Scripting
CVE-2025-3639 unknown 10mo ago Liferay Portal Login Bypass Vulnerability
CVE-2025-43733 unknown 10mo ago Liferay Portal Vulnerable to Cross-Site Scripting
CVE-2025-43732 unknown 10mo ago Liferay Portal Vulnerable to Insecure Direct Object Reference
CVE-2025-41242 unknown debian debian 10mo ago Spring Framework MVC Applications Path Traversal Vulnerability
CVE-2025-54948 unknown 1.5 KEV 10mo ago Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attacker to upload malicious code and execute commands …
CVE-2025-9092 unknown 10mo ago Bouncy Castle for Java Uncontrolled Resource Consumption Vulnerability
CVE-2025-55163 unknown FIX slesdebian debian 10mo ago Netty affected by MadeYouReset HTTP/2 DDoS vulnerability
CVE-2025-8876 unknown 1.5 KEV 10mo ago N-able N-Central contains a command injection vulnerability via improper sanitization of user input.
CVE-2025-8875 unknown 1.5 KEV 10mo ago N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution.
CVE-2025-43734 unknown 10mo ago Liferay Portal 7.4.0 and Liferay DXP have a reflected cross-site scripting (XSS) vulnerability
CVE-2025-8747 unknown FIX debian debian 10mo ago Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality
CVE-2025-8885 unknown FIX debian debian sles 10mo ago Bouncy Castle for Java on All (API modules) allows Excessive Allocation
CVE-2025-43736 unknown 10mo ago Liferay Portal and Liferay DXP have a Denial Of Service via File Upload (DOS) vulnerability
CVE-2025-8088 unknown 1.5 KEV 10mo ago RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.
CVE-2025-55159 unknown FIX slesdebian debian 10mo ago slab is a pre-allocated storage for a uniform data type. In version 0.4.10, the get_disjoint_mut method incorrectly checked if indices were within the slab's capacity instead of its length, allowing …
CVE-2013-3893 unknown 2.5 KEVEXP 10mo ago Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code execution. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users shoul…
CVE-2007-0671 unknown 1.5 KEV 10mo ago Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachmen…
CVE-2025-4581 unknown 10mo ago Liferay Portal and Liferay DXP vulnerable to Server-Side Request Forgery
CVE-2025-4576 unknown 10mo ago Liferay Portal Reflected XSS in blogs-web
CVE-2025-53606 unknown 10mo ago Apache Seata: Deserialization of untrusted Data in Apache Seata Server
CVE-2025-48913 unknown google 10mo ago Apache CXF: Untrusted JMS configuration can lead to RCE
CVE-2025-54368 unknown FIX slesdebian debian 10mo ago uv is a Python package and project manager written in Rust. In versions 0.8.5 and earlier, remote ZIP archives were handled in a streamwise fashion, and file entries were not reconciled against the a…
CVE-2025-54799 unknown FIX debian debian 10mo ago Let's Encrypt client and ACME library written in Go (Lego). In versions 4.25.1 and below, the github.com/go-acme/lego/v4/acme/api package (thus the lego library and the lego cli as well) don't enforc…
CVE-2012-10024 unknown 1.0 EXP 10mo ago XBMC version 11.0 contains a path traversal vulnerability in its embedded HTTP server. When accessed via HTTP Basic Authentication, the server fails to properly sanitize URI input, allowing authentic…
CVE-2012-10026 unknown 1.0 EXP 10mo ago The WordPress plugin Asset-Manager version 2.0 and below contains an unauthenticated arbitrary file upload vulnerability in upload.php. The endpoint fails to properly validate and restrict uploaded f…
CVE-2025-54125 unknown 10mo ago XWiki exposes passwords and emails stored in fields not named password/email in xml.vm
CVE-2025-54124 unknown 10mo ago XWiki leaks password hashes and other accessible password properties
CVE-2025-32430 unknown 10mo ago XWiki allows Reflected XSS in two templates
CVE-2025-4604 unknown 10mo ago Liferay Portal CAPTCHA Bypass for Gogo Shell
CVE-2022-40799 unknown 1.5 KEV 10mo ago D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands on the device. The impacted products could be…
CVE-2020-25079 unknown 1.5 KEV 10mo ago D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users shou…
CVE-2020-25078 unknown 1.5 KEV 10mo ago D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be end-of-life (EoL) and/or end…
CVE-2024-52279 unknown 10mo ago Apache Zeppelin: Arbitrary file read by adding malicious JDBC connection string
CVE-2024-51775 unknown 10mo ago Apache Zeppelin: Missing Origin Validation in WebSockets vulnerability
CVE-2024-41177 unknown 10mo ago Apache Zeppelin: XSS in the Helium module
CVE-2025-24854 unknown 10mo ago Apache JSPWiki Cross-Site Scripting (XSS) Vulnerability in the Image Plugin
CVE-2025-24853 unknown 10mo ago Apache JSPWiki Cross-Site Scripting (XSS) Vulnerability via Header Link Rendering
CVE-2025-54656 unknown sles 10mo ago Apache Struts Extras Before 2 has an Improper Output Neutralization for Logs Vulnerability
CVE-2025-52490 unknown 10mo ago Couchbase Sync Gateway shows cleartext passwords in redacted and unredacted output
CVE-2025-54410 unknown debian debian sles 10mo ago Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. A firewalld vulne…
CVE-2025-54388 unknown FIX debian debian sles 10mo ago Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. In versions 28.2.…
CVE-2025-20337 unknown 1.5 KEV 10mo ago Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to explo…
CVE-2025-20281 unknown 1.5 KEV 10mo ago Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to explo…
CVE-2023-2533 unknown 1.5 KEV 10mo ago PaperCut NG/MF contains a cross-site request forgery (CSRF) vulnerability, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code.
CVE-2025-54380 unknown 11mo ago Opencast still publishes global system account credentials
CVE-2025-54385 unknown 11mo ago XWiki Platform vulnerable to SQL injection through XWiki#searchDocuments API
CVE-2025-32429 unknown 1.0 EXP 11mo ago XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
CVE-2025-53015 unknown FIX debian debian sles 11mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0, infinite lines occur when writing during a specific XMP file conversion co…
CVE-2025-50481 unknown 1.0 EXP 11mo ago Mezzanine CMS vulnerable to Cross-site Scripting
CVE-2025-51471 unknown 11mo ago Ollama vulnerable to Cross-Domain Token Exposure
CVE-2025-51481 unknown 11mo ago Dagster Local File Inclusion vulnerability
CVE-2025-54309 unknown 1.5 KEV 11mo ago CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via…
CVE-2025-49706 unknown 2.5 KEVEXP 11mo ago Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view…
CVE-2025-49704 unknown 2.5 KEVEXP 11mo ago Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-…
CVE-2025-2776 unknown 1.5 KEV 11mo ago SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read pr…
CVE-2025-2775 unknown 1.5 KEV 11mo ago SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primi…
CVE-2025-54121 unknown FIX slesdebian debian 11mo ago Starlette is a lightweight ASGI (Asynchronous Server Gateway Interface) framework/toolkit, designed for building async web services in Python. In versions 0.47.1 and below, when parsing a multi-part …
CVE-2025-7962 unknown debian debian sles 11mo ago Jakarta Mail vulnerable to SMTP Injection
CVE-2025-50151 unknown debian debian 11mo ago Apache Jena doesn't validate file access paths in configuration files uploaded by users with administrator access
CVE-2025-49656 unknown debian debian 11mo ago Apache Jena allows users with administrator access to create databases files outside the files area of the Fuseki server
CVE-2025-53770 unknown 2.5 KEVEXP 11mo ago Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could b…
CVE-2025-54313 unknown 1.5 KEV sles 11mo ago Prettier eslint-config-prettier contains an embedded malicious code vulnerability. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.
CVE-2025-25257 unknown 2.5 KEVEXP 11mo ago Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.
CVE-2025-54068 unknown 1.5 KEV 11mo ago Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.
CVE-2024-9408 unknown 11mo ago Eclipse GlassFish is vulnerable to Server Side Request Forgery attacks through specific endpoints
CVE-2024-9343 unknown 11mo ago Eclipse GlassFish is vulnerable to Stored XSS attacks through its Administration Console
CVE-2024-9342 unknown 11mo ago Eclipse GlassFish is vulnerable to Login Brute Force attacks through unlimited failed login attempts
CVE-2024-10032 unknown 11mo ago Eclipse GlassFish is vulnerable to Stored XSS attacks through its Administration Console
CVE-2024-10031 unknown 11mo ago Eclipse GlassFish is vulnerable to Stored XSS attacks through configuration file modifications
CVE-2024-10029 unknown 11mo ago Eclipse GlassFish is vulnerable to Reflected XSS attacks through its Administration Console
CVE-2025-22227 unknown 11mo ago Reactor Netty HTTP is vulnerable to credential leaks during chained redirects
CVE-2025-53622 unknown 11mo ago DSpace is vulnerable to Path Traversal attacks when importing packages using Simple Archive Format
CVE-2025-53621 unknown 11mo ago DSpace is vulnerable to XML External Entity injection during archive imports
CVE-2025-48795 unknown 11mo ago Apache CXF is vulnerable to DoS attacks as entire files are read into memory and logged
CVE-2025-53836 unknown 11mo ago XWiki Rendering is vulnerable to RCE attacks when processing nested macros
CVE-2025-53835 unknown 11mo ago XWiki Rendering is vulnerable to XSS attacks through insecure XHTML syntax
CVE-2025-53643 unknown FIX slesdebian debian 11mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a request smuggling vulnerability due to not parsing trail…
CVE-2025-53689 unknown FIX debian debian 11mo ago Apache Jackrabbit vulnerable to blind XXE attack due to insecure document build
CVE-2025-47812 unknown 2.5 KEVEXP 11mo ago Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injection of arbitrary Lua code into user session files. This can be used to execute arb…
CVE-2024-41169 unknown 11mo ago Apache Zeppelin exposes server resources to unauthenticated attackers
CVE-2025-48924 unknown FIX debian debian sles 11mo ago Uncontrolled Recursion vulnerability in Apache Commons Lang. This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.…
CVE-2025-53864 unknown 11mo ago Nimbus JOSE + JWT is vulnerable to DoS attacks when processing deeply nested JSON
CVE-2025-5777 unknown 2.5 KEVEXP 11mo ago Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a…
CVE-2025-53743 unknown 11mo ago Jenkins Applitools Eyes Plugin vulnerability does not mask API keys on its job configuration form