Search

Found 25,255 results in 2032ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-22701 unknown FIX slesdebian debian 5mo ago filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker …
CVE-2025-62182 unknown 5mo ago Pega Customer Service Framework versions 8.7.0 through 25.1.0 are affected by a Unrestricted file upload vulnerability, where a privileged user could potentially upload a malicious file.
CVE-2026-22703 unknown FIX debian debian sles 5mo ago Cosign provides code signing and transparency for containers and binaries. Prior to versions 2.6.2 and 3.0.4, Cosign bundle can be crafted to successfully verify an artifact even if the embedded Reko…
CVE-2025-68931 unknown 5mo ago Jervis's AES CBC Mode is Without Authentication
CVE-2025-68925 unknown 5mo ago Jervis Has a JWT Algorithm Confusion Vulnerability
CVE-2025-68704 unknown 5mo ago Jervis Has Weak Random for Timing Attack Mitigation
CVE-2025-68703 unknown 5mo ago Jervis's Salt for PBKDF2 derived from password
CVE-2025-68702 unknown 5mo ago Jervis Has a SHA-256 Hex String Padding Bug
CVE-2025-68701 unknown 5mo ago Jervis has Deterministic AES IV Derivation from Passphrase
CVE-2025-68698 unknown 5mo ago Jervis Has a RSA PKCS#1 Padding Vulnerability
CVE-2026-20805 unknown 1.5 KEV 5mo ago Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally.
CVE-2025-68472 unknown 5mo ago MindsDB has improper sanitation of filepath that leads to information disclosure and DOS
CVE-2025-68493 unknown 5mo ago Apache Struts 2 is Missing XML Validation
CVE-2025-15506 low 3.3 3.3 debian debian 5mo ago AcademySoftwareFoundation OpenColorIO has an out-of-bounds vulnerability
CVE-2025-15505 low 2.4 2.4 5mo ago A vulnerability was found in Luxul XWR-600 up to 4.0.1. The affected element is an unknown function of the component Web Administration Interface. The manipulation of the argument Guest Network/Wirel…
CVE-2026-0824 low 3.5 3.5 5mo ago QuestDB UI's Web Console is Vulnerable to Cross-Site Scripting
CVE-2026-22597 low 2.7 2.7 ghost 5mo ago Ghost has SSRF via External Media Inliner
CVE-2025-65091 unknown 5mo ago XWiki Full Calendar Macro vulnerable to SQL injection through Calendar.JSONService
CVE-2025-65090 unknown 5mo ago XWiki Full Calendar Macro vulnerable to data leak through Calendar.JSONService
CVE-2025-70974 unknown 5mo ago FASTJSON Includes Functionality from Untrusted Control Sphere
CVE-2025-68158 unknown FIX slesdebian debian 5mo ago Authlib is a Python library which builds OAuth and OpenID Connect servers. In versions 1.0.0 through 1.6.5, cache-backed state/request-token storage is not tied to the initiating user session, so CSR…
CVE-2026-0707 unknown 5mo ago Keycloak has Incorrect Behavior Order: Authorization Before Parsing and Canonicalization
CVE-2026-22187 unknown 5mo ago Bio-Formats performs unsafe Java deserialization of attacker-controlled memoization cache files (.bfmemo) during image processing
CVE-2026-22186 unknown 5mo ago Bio-Formats has an XML External Entity (XXE) vulnerability
CVE-2026-22244 unknown 5mo ago OpenMetadata's Server-Side Template Injection (SSTI) in FreeMarker email templates leads to RCE
CVE-2026-21885 unknown FIX debian debian 5mo ago Miniflux 2 is an open source feed reader. Prior to version 2.2.16, Miniflux's media proxy endpoint (`GET /proxy/{encodedDigest}/{encodedURL}`) can be abused to perform Server-Side Request Forgery (SS…
CVE-2025-12543 unknown debian debian 5mo ago Undertow HTTP server core doesn't properly validate the Host header in incoming HTTP requests
CVE-2025-66560 unknown 5mo ago Quarkus REST has potential worker thread starvation when HTTP connection is closed while waiting to write
CVE-2025-37164 unknown 2.5 KEVEXP 5mo ago Hewlett Packard Enterprise (HPE) OneView contains a code injection vulnerability that allows a remote unauthenticated user to perform remote code execution.
CVE-2009-0556 unknown 1.5 KEV 5mo ago Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an invalid index…
CVE-2026-21892 unknown FIX debian debian 5mo ago Parsl is a Python parallel scripting library. A SQL Injection vulnerability exists in the parsl-visualize component of versions prior to 2026.01.05. The application constructs SQL queries using unsaf…
CVE-2025-69230 unknown FIX slesdebian debian 5mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, reading multiple invalid cookies can lead to a logging storm. If the cookies attribute is…
CVE-2025-69229 unknown FIX slesdebian debian 5mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. In versions 3.13.2 and below, handling of chunked messages can result in excessive blocking CPU usage when receiving a …
CVE-2025-69228 unknown FIX slesdebian debian 5mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a request to be crafted in such a way that an AIOHTTP server's memory fills up uncontro…
CVE-2025-69227 unknown FIX slesdebian debian 5mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow for an infinite loop to occur when assert statements are bypassed, resulting in a DoS a…
CVE-2025-69226 unknown FIX slesdebian debian 5mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below enable an attacker to ascertain the existence of absolute path components through the path no…
CVE-2025-69225 unknown FIX slesdebian debian 5mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below contain parser logic which allows non-ASCII decimals to be present in the Range header. There…
CVE-2025-69224 unknown FIX slesdebian debian 5mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below of the Python HTTP parser may allow a request smuggling attack with the presence of non-ASCII…
CVE-2025-69223 unknown FIX slesdebian debian 5mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be a…
CVE-2025-61916 unknown 5mo ago Spinnaker vulnerable to SSRF due to improper restrictions on http from user input
CVE-2025-68280 unknown 5mo ago Apache SIS has Improper Restriction of XML External Entity Reference vulnerability
CVE-2026-21452 unknown debian debian 5mo ago MessagePack for Java Vulnerable to Remote DoS via Malicious EXT Payload Allocation
CVE-2025-66518 unknown 5mo ago Apache Kyuubi Server vulnerable to Path Traversal
CVE-2025-15022 unknown 5mo ago Vaadin vulnerable to Cross-site Scripting
CVE-2025-15454 low 3.1 3.1 5mo ago A vulnerability was detected in zhanglun lettura up to 0.1.22. This issue affects some unknown processing of the file src/components/ArticleView/ContentRender.tsx of the component RSS Handler. The ma…
CVE-2025-47411 unknown 5mo ago Apache StreamPipes has Improper Privilege Management issue
CVE-2025-68131 unknown FIX debian debian sles 5mo ago CBORDecoder reuse can leak shareable values across decode calls
CVE-2025-68950 unknown FIX debian debian sles 5mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, Magick fails to check for circular references between two MVGs, leading to a …
CVE-2025-68618 unknown FIX debian debian sles 5mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, using Magick to read a malicious SVG file resulted in a DoS attack. Version 7…
CVE-2025-67746 unknown FIX debian debian sles 5mo ago Composer is a dependency manager for PHP. In versions on the 2.x branch prior to 2.2.26 and 2.9.3, attackers controlling remote sources that Composer downloads from might in some way inject ANSI cont…
CVE-2025-15248 low 3.5 3.5 5mo ago A security flaw has been discovered in sunhailin12315 product-review 商品评价系统 up to 91ead6890b4065bb45b7602d0d73348e75cb4639. This affects an unknown part of the component Write a Review. Performing ma…
CVE-2023-54164 unknown FIX slesdebian debian 5mo ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: fix iso_conn related locking and validity issues sk->sk_state indicates whether iso_pi(sk)->conn is valid. Operat…
CVE-2025-69015 low 3.8 3.8 5mo ago Missing Authorization vulnerability in Automattic Crowdsignal Forms crowdsignal-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Crowdsignal Forms: fro…
CVE-2025-15245 low 3.3 3.3 5mo ago A vulnerability was found in D-Link DCS-850L 1.02.09. Affected is the function uploadfirmware of the component Firmware Update Service. The manipulation of the argument DownloadFile results in path t…
CVE-2025-15244 low 3.7 3.7 phpems 5mo ago A vulnerability has been found in PHPEMS up to 11.0. This impacts an unknown function of the component Purchase Request Handler. The manipulation leads to race condition. The attack may be initiated …
CVE-2025-15242 low 3.1 3.1 phpems 5mo ago A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function of the component Coupon Handler. Performing a manipulation results in race condition. The attack can be …
CVE-2025-15241 low 3.5 3.5 5mo ago A security vulnerability has been detected in CloudPanel Community Edition up to 2.5.1. The affected element is an unknown function of the file /admin/users of the component HTTP Header Handler. Such…
CVE-2026-0810 unknown debian debian 5mo ago A flaw was found in gix-date. The `gix_date::parse::TimeBuf::as_str` function can generate strings containing invalid non-UTF8 characters. This issue violates the internal safety invariants of the `T…
CVE-2025-14847 unknown 2.5 KEVEXP 5mo ago MongoDB Server contains an improper handling of length parameter inconsistency vulnerability in Zlib compressed protocol headers. This vulnerability may allow a read of uninitialized heap memory by a…
CVE-2025-15151 low 3.7 3.7 5mo ago A vulnerability was determined in TaleLin Lin-CMS up to 0.6.0. This affects an unknown part of the file /tests/config.py of the component Tests Folder. This manipulation of the argument username/pass…
CVE-2025-15149 low 2.4 2.4 5mo ago A vulnerability has been found in rawchen ecms up to b59d7feaa9094234e8aa6c8c6b290621ca575ded. Affected by this vulnerability is the function updateProductServlet of the file src/servlet/product/upda…
CVE-2025-15141 low 3.1 3.1 halo 5mo ago A vulnerability was determined in Halo up to 2.21.10. This issue affects some unknown processing of the file /actuator of the component Configuration Handler. Executing a manipulation can lead to inf…
CVE-2025-15134 low 3.5 3.5 5mo ago A security flaw has been discovered in yourmaileyes MOOC up to 1.17. This affects the function subreview of the file mooc/controller/MainController.java of the component Submission Handler. Performin…
CVE-2025-15125 low 3.1 3.1 jeecg 5mo ago A security flaw has been discovered in JeecgBoot up to 3.9.0. Affected is the function queryDepartPermission of the file /sys/permission/queryDepartPermission. The manipulation of the argument depart…
CVE-2025-15124 low 3.1 3.1 jeecg 5mo ago A vulnerability was identified in JeecgBoot up to 3.9.0. This impacts the function getParameterMap of the file /sys/sysDepartPermission/list. The manipulation of the argument departId leads to improp…
CVE-2025-15123 low 3.1 3.1 jeecg 5mo ago A vulnerability was determined in JeecgBoot up to 3.9.0. This affects an unknown function of the file /sys/sysDepartPermission/datarule/. Executing manipulation can lead to improper authorization. It…
CVE-2025-15122 low 3.1 3.1 jeecg 5mo ago A vulnerability was found in JeecgBoot up to 3.9.0. The impacted element is the function loadDatarule of the file /sys/sysDepartRole/datarule/. Performing manipulation of the argument departId/roleId…
CVE-2025-15120 low 3.1 3.1 jeecg 5mo ago A flaw has been found in JeecgBoot up to 3.9.0. Impacted is the function getDeptRoleList of the file /sys/sysDepartRole/getDeptRoleList. This manipulation of the argument departId causes improper aut…
CVE-2025-15119 low 3.1 3.1 jeecg 5mo ago A vulnerability was detected in JeecgBoot up to 3.9.0. This issue affects the function queryPageList of the file /sys/sysDepartRole/list. The manipulation of the argument deptId results in improper a…
CVE-2025-15108 low 3.7 3.7 5mo ago A vulnerability was detected in PandaXGO PandaX up to fb8ff40f7ce5dfebdf66306c6d85625061faf7e5. This affects an unknown function of the file config.yml of the component JWT Secret Handler. The manipu…
CVE-2025-15095 low 3.5 3.5 sles 5mo ago A security vulnerability has been detected in postmanlabs httpbin up to 0.6.1. This affects an unknown function of the file httpbin-master/httpbin/core.py. The manipulation leads to cross site script…
CVE-2025-15084 low 3.1 3.1 youlai 5mo ago A vulnerability was identified in youlaitech youlai-mall 1.0.0/2.0.0. The impacted element is the function orderService.payOrder of the file mall-oms/oms-boot/src/main/java/com/youlai/mall/oms/contro…
CVE-2023-54130 unknown FIX slesdebian debian 5mo ago In the Linux kernel, the following vulnerability has been resolved: hfs/hfsplus: avoid WARN_ON() for sanity check, use proper error handling Commit 55d1cbbbb29e ("hfs/hfsplus: use WARN_ON for sanit…
CVE-2025-68351 unknown FIX slesdebian debian 5mo ago In the Linux kernel, the following vulnerability has been resolved: exfat: fix refcount leak in exfat_find Fix refcount leaks in `exfat_find` related to `exfat_get_dentry_set`. Function `exfat_get…
CVE-2025-68613 unknown 2.5 KEVEXP 6mo ago n8n contains an improper control of dynamically managed code resources vulnerability in its workflow expression evaluation system that allows for remote code execution.
CVE-2025-15005 low 3.7 3.7 couchcms 6mo ago A security flaw has been discovered in CouchCMS up to 2.4. Affected is an unknown function of the file couch/config.example.php of the component reCAPTCHA Handler. The manipulation of the argument K_…
CVE-2023-52163 unknown 1.5 KEV 6mo ago Digiever DS-2105 Pro contains a missing authorization vulnerability which could allow for command injection via time_tzsetup.cgi.
CVE-2025-68478 unknown 6mo ago External Control of File Name or Path in Langflow
CVE-2025-13467 unknown 6mo ago Keycloak LDAP User Federation provider enables admin-triggered untrusted Java deserialization
CVE-2025-14955 low 3.7 3.7 open5gs 6mo ago A vulnerability was found in Open5GS up to 2.7.5. Affected by this vulnerability is the function ogs_pfcp_handle_create_pdr in the library lib/pfcp/handler.c of the component PFCP. The manipulation r…
CVE-2025-66524 unknown 6mo ago Apache NiFi GetAsanaObject Processor has Remote Code Execution via Unsafe Deserialization
CVE-2025-68390 unknown 6mo ago Elasticsearch privileged authenticated users can cause DoS through Excessive Resource Allocation
CVE-2025-68384 unknown 6mo ago Elasticsearch has Excessive Allocation of Resources via Submission of Oversized User Settings Data
CVE-2025-14733 unknown 1.5 KEV 6mo ago WatchGuard Fireware OS iked process contains an out of bounds write vulnerability in the OS iked process. This vulnerability may allow a remote unauthenticated attacker to execute arbitrary code and …
CVE-2025-68161 unknown FIX debian debian sles 6mo ago Apache Log4j does not verify the TLS hostname in its Socket Appender
CVE-2025-14763 unknown aws 6mo ago Amazon S3 Encryption Client for Java has a Key Commitment Issue
CVE-2025-14841 low 3.3 3.3 FIX debian debian 6mo ago A flaw has been found in OFFIS DCMTK up to 3.6.9. The impacted element is the function DcmQueryRetrieveIndexDatabaseHandle::startFindRequest/DcmQueryRetrieveIndexDatabaseHandle::startMoveRequest in t…
CVE-2025-14836 low 2.7 2.7 zzcms 6mo ago A flaw has been found in ZZCMS 2025. Affected by this vulnerability is an unknown functionality of the file /reg/user_save.php of the component User Data Storage Module. This manipulation causes clea…
CVE-2024-29371 unknown FIX slesdebian debian 6mo ago jose4j is vulnerable to DoS via compressed JWE content
CVE-2025-67895 unknown 6mo ago Apache Airflow Providers Edge3 exposes internal API allowing RCE in web server context
CVE-2025-59374 unknown 1.5 KEV 6mo ago ASUS Live Update contains an embedded malicious code vulnerability client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could caus…
CVE-2025-40602 unknown 1.5 KEV 6mo ago SonicWall SMA1000 contains a missing authorization vulnerability that could allow for privilege escalation appliance management console (AMC) of affected devices.
CVE-2025-20393 unknown 1.5 KEV 6mo ago Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat actors to execute arbitrary commands with…
CVE-2025-68154 unknown FIX debian debian 6mo ago systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` function in systeminformation is vulnerable to OS command injection on Windows syste…
CVE-2025-68146 unknown FIX slesdebian debian 6mo ago filelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTOU) race condition allows local attackers to corrupt or truncate arbitrary user …
CVE-2025-68142 unknown FIX debian debian 6mo ago PyMdown Extensions is a set of extensions for the `Python-Markdown` markdown project. Versions prior to 10.16.1 have a ReDOS bug found within the figure caption extension (`pymdownx.blocks.caption`).…
CVE-2025-68315 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to detect potential corrupted nid in free_nid_list As reported, on-disk footer.ino and footer.nid is the same and out-o…
CVE-2025-68307 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_xmit_callback(): fix handling of failed transmitted URBs The driver lacks the cleanup of failed transfers of …
CVE-2025-68251 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: erofs: avoid infinite loops due to corrupted subpage compact indexes Robert reported an infinite loop observed by two crafted ima…
CVE-2025-68239 unknown FIX slesdebian debian google 6mo ago In the Linux kernel, the following vulnerability has been resolved: binfmt_misc: restore write access before closing files opened by open_exec() bm_register_write() opens an executable file using o…