Search

Found 20,975 results in 1564ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-43972 unknown FIX debian debian 1y ago An issue was discovered in GoBGP before 3.35.0. An attacker can cause a crash in the pkg/packet/bgp/bgp.go flowspec parser by sending fewer than 20 bytes in a certain context.
CVE-2025-43971 unknown FIX debian debian 1y ago An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value for softwareVersionLen.
CVE-2025-43970 unknown FIX debian debian 1y ago An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g., by ensuring that there are 12 bytes or 36 bytes (depending on the address family).
CVE-2024-41447 unknown 1y ago Alkacon OpenCMS stored cross-site scripting (XSS) vulnerability
CVE-2025-32434 unknown FIX debian debian 1y ago PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command …
CVE-2024-55238 unknown 1y ago OpenMetadata SQL Injection
CVE-2025-3760 unknown 1y ago Liferay Cross-site Scripting vulnerability
CVE-2025-31201 unknown 1.5 KEV 1y ago Apple iOS, iPadOS, macOS, and other Apple products contain an arbitrary read and write vulnerability that allows an attacker to bypass Pointer Authentication.
CVE-2025-31200 unknown 1.5 KEV 1y ago Apple iOS, iPadOS, macOS, and other Apple products contain a memory corruption vulnerability that allows for code execution when processing an audio stream in a maliciously crafted media file.
CVE-2025-24054 unknown 2.5 KEVEXP 1y ago Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-3730 unknown FIX debian debian 1y ago A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. The manipulation …
CVE-2025-22872 unknown FIX debian debian sles 1y ago The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly…
CVE-2025-32783 unknown 1y ago Unregistered users can see "public" messages from a closed wiki via notifications from a different wiki
CVE-2021-20035 unknown 1.5 KEV 1y ago SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user, whic…
CVE-2025-30215 unknown FIX debian debian 1y ago NATS Server may fail to authorize certain Jetstream admin APIs
CVE-2025-3573 unknown FIX debian debian 1y ago Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() function, which may take input from a user-controlled placeholder value. This v…
CVE-2025-3588 unknown 1y ago jsonschema2pojo has Improper Restriction of Operations within the Bounds of a Memory Buffer
CVE-2024-58136 unknown 1.5 KEV 1y ago Yii Framework contains an improper protection of alternate path vulnerability that may allow a remote attacker to execute arbitrary code. This vulnerability could affect other products that implement…
CVE-2025-27391 unknown 1y ago Apache ActiveMQ Artemis Vulnerable to Insertion of Sensitive Information into Log File
CVE-2025-31672 unknown debian debian 1y ago Apache POI OOXML Vulnerable to Improper Input Validation in OOXML File Parsing
CVE-2025-30677 unknown 1y ago Apache Pulsar Kafka Connector Logs Sensitive Information in Application Logs
CVE-2024-52981 unknown 1y ago Elasticsearch Vulnerable to Stack Overflow due to a Large Recursion
CVE-2024-52980 unknown 1y ago Elasticsearch Potential Node Crash due to Large Recursion in `innerForbidCircularReferences` Function
CVE-2025-30406 unknown 2.5 KEVEXP 1y ago Gladinet CentreStack and Triofox contains a use of hard-coded cryptographic key vulnerability in the way that the application manages keys used for ViewState integrity verification. Successful exploi…
CVE-2025-29824 unknown 1.5 KEV 1y ago Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
CVE-2025-29480 unknown debian debian sles 1y ago Buffer Overflow vulnerability in gdal 3.10.2 allows a local attacker to cause a denial of service via the OGRSpatialReference::Release function. NOTE: the Supplier indicates that the report is invali…
CVE-2025-30373 unknown 1y ago Graylog's Authenticated HTTP inputs ingest message even if Authorization header is missing or has wrong value
CVE-2025-31161 unknown 2.5 KEVEXP 1y ago CrushFTP contains an authentication bypass vulnerability in the HTTP authorization header that allows a remote unauthenticated attacker to authenticate to any known or guessable user account (e.g., c…
CVE-2025-31487 unknown 1y ago The XWiki JIRA extension allows data leak through an XXE attack by using a fake JIRA server
CVE-2025-22457 unknown 2.5 KEVEXP 1y ago Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution.
CVE-2025-3136 unknown debian debian 1y ago A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0. This issue affects the function torch.cuda.memory.caching_allocator_delete of the file c10/cuda/CUDACachingAlloc…
CVE-2025-31130 unknown FIX debian debian 1y ago gitoxide is an implementation of git written in Rust. Before 0.42.0, gitoxide uses SHA-1 hash implementations without any collision detection, leaving it vulnerable to hash collision attacks. gitoxid…
CVE-2025-3121 unknown debian debian 1y ago A vulnerability classified as problematic has been found in PyTorch 2.6.0. Affected is the function torch.jit.jit_module_from_flatbuffer. The manipulation leads to memory corruption. Local access is …
CVE-2025-29085 unknown 1y ago Vipshop Saturn Console Vulnerable to SQL Injection via ClusterKey Component
CVE-2025-31728 unknown 1y ago Jenkins AsakusaSatellite Plugin Does not Mask API Keys via Job Configuration Form
CVE-2025-31727 unknown 1y ago Jenkins AsakusaSatellite Plugin Stores API Keys Unencrypted in Job `config.xml` Files
CVE-2025-31726 unknown 1y ago Jenkins Stack Hammer Plugin Stores API Keys Unencrypted in Job `config.xml` Files
CVE-2025-31725 unknown 1y ago Jenkins monitor-remote-job Plugin Stores Passwords Unencrypted
CVE-2025-31724 unknown 1y ago Jenkins Cadence vManager Plugin Stores Verisium Manager vAPI keys Unencrypted
CVE-2025-31723 unknown 1y ago Jenkins Simple Queue Plugin Cross-Site Request Forgery (CSRF)
CVE-2025-31722 unknown 1y ago Jenkins Templating Engine Plugin Vulnerable to Arbitrary Code Execution
CVE-2025-31721 unknown 1y ago Jenkins Missing Permission Check
CVE-2025-31720 unknown 1y ago Jenkins Missing Permission Check
CVE-2025-27556 unknown FIX slesdebian debian 1y ago An issue was discovered in Django 5.1 before 5.1.8 and 5.0 before 5.0.14. The NFKC normalization is slow on Windows. As a consequence, django.contrib.auth.views.LoginView, django.contrib.auth.views.L…
CVE-2025-31129 unknown 1y ago jooby-pac4j: deserialization of untrusted data
CVE-2025-30177 unknown 1y ago Apache Camel Missing Header Out Filter Leads to Potential Bypass/Injection Vulnerability
CVE-2025-30065 unknown 1y ago Apache Parquet Avro Module Vulnerable to Arbitrary Code Execution
CVE-2024-56325 unknown 1y ago Apache Pinot Vulnerable to Authentication Bypass
CVE-2025-27427 unknown 1y ago Apache ActiveMQ Artemis User Without Create Address Permissions can Modify Address Routing-Type
CVE-2025-29908 unknown 1y ago Netty QUIC hash collision DoS attack
CVE-2025-31125 unknown 1.5 KEV 1y ago Vite Vitejs contains an improper access control vulnerability that exposes content of non-allowed files using ?inline&import or ?raw?import. Only apps explicitly exposing the Vite dev server to the n…
CVE-2025-3001 unknown FIX debian debian 1y ago A vulnerability classified as critical was found in PyTorch 2.6.0. This vulnerability affects the function torch.lstm_cell. The manipulation leads to memory corruption. The attack needs to be approac…
CVE-2025-3000 unknown debian debian 1y ago A vulnerability classified as critical has been found in PyTorch 2.6.0. This affects the function torch.jit.script. The manipulation leads to memory corruption. It is possible to launch the attack on…
CVE-2025-2999 unknown FIX debian debian 1y ago A vulnerability was found in PyTorch 2.6.0. It has been rated as critical. Affected by this issue is the function torch.nn.utils.rnn.unpack_sequence. The manipulation leads to memory corruption. Atta…
CVE-2025-2998 unknown FIX debian debian 1y ago A vulnerability was found in PyTorch 2.6.0. It has been declared as critical. Affected by this vulnerability is the function torch.nn.utils.rnn.pad_packed_sequence. The manipulation leads to memory c…
CVE-2025-2961 unknown 1y ago Solon Vulnerable to Path Traversal
CVE-2024-20439 unknown 1.5 KEV 1y ago Cisco Smart Licensing Utility contains a static credential vulnerability that allows an unauthenticated, remote attacker to log in to an affected system and gain administrative credentials.
CVE-2025-2953 unknown debian debian 1y ago A vulnerability, which was classified as problematic, has been found in PyTorch 2.6.0+cu124. Affected by this issue is the function torch.mkldnn_max_pool2d. The manipulation leads to denial of servic…
CVE-2024-6875 unknown 1y ago Infinispan Potential Out of Memory Error via REST Compare API Buffer API
CVE-2025-30067 unknown 1y ago Apache Kylin Code Injection via JDBC Configuration Alteration
CVE-2024-48944 unknown 1y ago Apache Kylin Server-Side Request Forgery (SSRF) via `/kylin/api/xxx/diag` Endpoint
CVE-2025-2783 unknown 2.5 KEVEXPFIX debian debian 1y ago Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 134.0.6998.177 allowed a remote attacker to perform a sandbox escape via a malicious file. (Chromiu…
CVE-2019-9875 unknown 1.5 KEV 1y ago Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an authenticated attacker to execute arbitrary code by sending a…
CVE-2019-9874 unknown 1.5 KEV 1y ago Sitecore CMS and Experience Platform (XP) contain a deserialization vulnerability in the Sitecore.Security.AntiCSRF module that allows an unauthenticated attacker to execute arbitrary code by sending…
CVE-2024-12369 unknown 1y ago WildFly Elytron OpenID Connect Client ExtensionOIDC authorization code injection attack
CVE-2025-29315 unknown 1y ago OpenDaylight SFC Allows Unauthorized Privileged Execution via Crafted Request
CVE-2025-29314 unknown 1y ago OpenDaylight SFC Insecure Shiro Cookie Configuration
CVE-2025-29313 unknown 1y ago OpenDaylight SFC Denial of Service (DoS)
CVE-2025-22223 unknown 1y ago Spring Security Vulnerable to Authorization Bypass via Security Annotations
CVE-2025-30154 unknown 1.5 KEV 1y ago reviewdog action-setup GitHub Action contains an embedded malicious code vulnerability that dumps exposed secrets to Github Actions Workflow Logs.
CVE-2025-30474 unknown FIX debian debian sles 1y ago Apache Commons VFS Exposure of Sensitive Information to an Unauthorized Actor
CVE-2025-27553 unknown FIX debian debian sles 1y ago Apache Commons VFS Has Relative Path Traversal Vulnerability
CVE-2025-2622 unknown 1y ago aizuda snail-job Vulnerable to Deserialization via `nodeExpression` Argument
CVE-2025-26796 unknown 1y ago Apache Oozie Cross-Site Scripting (XSS)
CVE-2025-2565 unknown 1y ago Liferay Portal and Liferay DXP Reveals Data via Forms
CVE-2025-27888 unknown 1y ago Apache Druid vulnerable to Server-Side Request Forgery, Cross-site Scripting, Open Redirect
CVE-2024-8616 unknown 1y ago H2O Vulnerable to Arbitrary File Overwrite
CVE-2024-8524 unknown 1y ago AgentScope directory traversal vulnerability in /read-examples
CVE-2024-8501 unknown 1y ago AgentScope arbitrary file download vulnerability in rpc_agent_client
CVE-2024-8487 unknown 1y ago AgentScope Cross-Origin Resource Sharing (CORS) vulnerability
CVE-2024-8438 unknown 1y ago AgentScope Path Traversal in /api/file
CVE-2024-8062 unknown 1y ago H2O Vulnerable to Denial of Service (DoS) via `HEAD` Request
CVE-2024-7768 unknown 1y ago H2O Vulnerable to Denial of Service (DoS) via `/3/ImportFiles` Endpoint
CVE-2024-7765 unknown 1y ago H2O Vulnerable to Denial of Service (DoS) via Large GZIP Parsing
CVE-2024-6863 unknown 1y ago H2O Vulnerable to Execution of Arbitrary Files
CVE-2024-6854 unknown 1y ago H2O Vulnerable to Arbitrary File Overwrite via File Export
CVE-2024-10572 unknown 1y ago H2O Vulnerable to Denial of Service (DoS) and File Write
CVE-2024-10553 unknown 1y ago H2O Deserialization of Untrusted Data Vulnerability
CVE-2024-10550 unknown 1y ago H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` Endpoint
CVE-2024-10549 unknown 1y ago H2O Vulnerable to Denial of Service (DoS) via `/3/Parse` Endpoint
CVE-2024-8063 unknown 1y ago Ollama Divide by Zero Vulnerability
CVE-2024-54016 unknown 1y ago Apache Seata Vulnerable to Data Amplification
CVE-2024-47552 unknown 1y ago Apache Seata Vulnerable to Deserialization of Untrusted Data
CVE-2025-22228 unknown 1y ago Spring Security Does Not Enforce Password Length
CVE-2025-2536 unknown 1y ago Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS)
CVE-2025-29926 unknown 1y ago The WikiManager REST API allows any user to create wikis
CVE-2025-29924 unknown 1y ago XWiki uses the wrong wiki reference in AuthorizationManager
CVE-2025-30197 unknown 1y ago Jenkins Zoho QEngine Plugin Displays Unmasked API Keys
CVE-2025-30196 unknown 1y ago Jenkins AnchorChain Plugin Has a Cross-Site Scripting (XSS) Vulnerability
CVE-2025-1316 unknown 1.5 KEV 1y ago Edimax IC-7100 IP camera contains an OS command injection vulnerability due to improper input sanitization that allows an attacker to achieve remote code execution via specially crafted requests. The…