Search

Found 25,318 results in 1175ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-62594 unknown FIX debian debian sles 7mo ago ImageMagick is a software suite to create, edit, compose, or convert bitmap images. ImageMagick versions prior to 7.1.2-8 are vulnerable to denial-of-service due to unsigned integer underflow and div…
CVE-2025-62262 unknown 7mo ago Liferay Portal Vulnerable to Information Exposure Through a Log File Vulnerability in LDAP Import Feature
CVE-2025-62263 unknown 7mo ago Liferay Portal Vulnerable to Cross-Site Scripting
CVE-2025-62253 unknown 7mo ago Liferay Portal Vulnerable to Open Redirect via the _com_liferay_layout_admin_web_portlet_GroupPagesPortlet_redirect parameter
CVE-2025-11419 unknown 7mo ago Keycloak TLS Client-Initiated Renegotiation Denial of Service
CVE-2025-62782 unknown 7mo ago InventoryGui allows item duplication with experimental "Bundle" item in GUIs which use GuiStorageElement
CVE-2025-62783 unknown 7mo ago InventoryGui affected by item duplication in GUIs which use GuiStorageElement
CVE-2025-12251 low 3.5 3.5 7mo ago A vulnerability has been found in OpenWGA 7.11.12 Build 737. This impacts an unknown function of the component Admin UI. The manipulation leads to cross site scripting. The attack can be initiated re…
CVE-2025-12224 low 3.5 3.5 7mo ago A flaw has been found in Iqbolshoh php-business-website up to 10677743a8dfc281f85291a27cf63a0bce043c24. This vulnerability affects unknown code of the file admin/contact.php. This manipulation of the…
CVE-2025-12194 unknown debian debian sles 8mo ago Bouncy Castle Vulnerable to Uncontrolled Resource Consumption
CVE-2025-40022 unknown FIX slesdebian debian 8mo ago In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Fix incorrect boolean values in af_alg_ctx Commit 1b34cbbf4f01 ("crypto: af_alg - Disallow concurrent writes in …
CVE-2025-62254 unknown 8mo ago Liferay Portal ComboServlet denial of service via large file combination
CVE-2025-59287 unknown 2.5 KEVEXP 8mo ago Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.
CVE-2025-62255 unknown 8mo ago Liferay Portal Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page
CVE-2025-60837 unknown 8mo ago MCMS reflected cross-site scripting (XSS) vulnerability
CVE-2025-62256 unknown 8mo ago Liferay Portal and DXP do not properly restrict access to OpenAPI
CVE-2025-12110 unknown 8mo ago Keycloak does not invalidate offline sessions when the offline_access scope is removed
CVE-2025-11429 unknown 8mo ago Keycloak does not invalidate sessions when "Remember Me" is disabled
CVE-2025-62247 unknown 8mo ago Liferay Portal and DXP are Missing Authorization in Collection Provider
CVE-2025-62248 unknown 8mo ago Liferay Portal and Liferay DXP vulnerable to reflected cross-site scripting (XSS)
CVE-2025-62710 unknown 8mo ago Sakai kernel-impl: predictable PRNG used to generate server‑side encryption key in EncryptionUtilityServiceImpl
CVE-2025-11966 unknown 8mo ago Vert.x-Web vulnerable to Stored Cross-site Scripting in directory listings via file names
CVE-2025-11965 unknown 8mo ago Vert.x-Web Access Control Flaw in StaticHandler’s Hidden File Protection for Files Under Hidden Directories
CVE-2025-61932 unknown 1.5 KEV 8mo ago Motex LANSCOPE Endpoint Manager contains an improper verification of source of a communication channel vulnerability allowing an attacker to execute arbitrary code by sending specially crafted packet…
CVE-2025-61748 low 3.7 3.7 FIX rhel slesdebian debian oracle 8mo ago RHSA-2025:18824: java-21-openjdk security update (Moderate)
CVE-2025-62249 unknown 8mo ago Liferay Portal reflected cross-site scripting (XSS) vulnerability in the google_gaget
CVE-2025-62250 unknown 8mo ago Liferay Portal fails to verify messages from the cluster network is trusted
CVE-2025-57738 unknown 8mo ago Apache Syncope allows malicious administrators to inject Groovy code
CVE-2025-61884 unknown 1.5 KEV 8mo ago Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication.
CVE-2025-33073 unknown 2.5 KEVEXP 8mo ago Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the …
CVE-2025-2747 unknown 1.5 KEV 8mo ago Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects.
CVE-2025-2746 unknown 1.5 KEV 8mo ago Kentico Xperience CMS contains an authentication bypass using an alternate path or channel vulnerability that could allow an attacker to control administrative objects.
CVE-2025-11945 low 3.5 3.5 8mo ago A vulnerability was identified in toeverything AFFiNE up to 0.24.1. This vulnerability affects unknown code of the component Avatar Upload Image Endpoint. Such manipulation leads to cross site script…
CVE-2025-47410 unknown 8mo ago Apache Geode: CSRF attacks through GET requests to the Management and Monitoring REST API that can execute gfsh commands on the target system
CVE-2025-56316 unknown 8mo ago MCMS vulnerable SQL injection via the content_title parameter
CVE-2025-34281 unknown 8mo ago ThingsBoard vulnerable to stored cross-site scripting (XSS) vulnerability in the dashboard's Image Upload Gallery feature
CVE-2025-10044 unknown 8mo ago Keycloak error_description injection on error pages that can trigger phishing attacks
CVE-2025-11851 low 3.5 3.5 8mo ago A vulnerability has been found in Apeman ID71 EN75.8.53.20. The affected element is an unknown function of the file /set_alias.cgi. Such manipulation of the argument alias leads to cross site scripti…
CVE-2025-41254 unknown debian debian 8mo ago Spring Framework STOMP over WebSocket applications may allow attackers to send unauthorized messages
CVE-2025-41253 unknown 8mo ago Spring Cloud Gateway Server Webflux is vulnerable to Expression Language Injection
CVE-2025-62371 unknown 8mo ago OpenSearch Data Prepper plugins trust all SSL certificates by default
CVE-2025-59419 unknown FIX slesdebian debian 8mo ago Netty has SMTP Command Injection Vulnerability that Allows Email Forgery
CVE-2025-55039 unknown 8mo ago Apache Spark has Inadequate Encryption Strength
CVE-2025-39997 unknown FIX slesdebian debian 8mo ago In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: fix race condition to UAF in snd_usbmidi_free The previous commit 0718a78f6a9f ("ALSA: usb-audio: Kill timer pro…
CVE-2025-39977 unknown FIX slesdebian debian 8mo ago In the Linux kernel, the following vulnerability has been resolved: futex: Prevent use-after-free during requeue-PI syzbot managed to trigger the following race: T1 …
CVE-2025-54253 unknown 1.5 KEV 8mo ago Adobe Experience Manager Forms in JEE contains an unspecified vulnerability that allows for arbitrary code execution.
CVE-2025-59250 unknown 8mo ago JDBC Driver for SQL Server has improper input validation issue
CVE-2024-44088 unknown 8mo ago Apache Geode web-api is vulnerable to Cross-site Scripting
CVE-2025-11731 low 3.1 3.1 FIX slesdebian debian 8mo ago A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during stylesheet parsing. Due to improper type handling, the function may treat an XML d…
CVE-2025-62251 unknown 8mo ago Liferay has Incorrect Permission Assignment for Critical Resource
CVE-2025-59230 unknown 1.5 KEV 8mo ago Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to elevate privileges locally.
CVE-2025-47827 unknown 1.5 KEV 8mo ago IGEL OS contains a use of a key past its expiration date vulnerability that allows for Secure Boot bypass. The igel-flash-driver module improperly verifies a cryptographic signature. Ultimately, a cr…
CVE-2025-24990 unknown 1.5 KEV 8mo ago Microsoft Windows Agere Modem Driver contains an untrusted pointer dereference vulnerability that allows for privilege escalation. An attacker who successfully exploited this vulnerability could gain…
CVE-2016-7836 unknown 1.5 KEV 8mo ago SKYSEA Client View contains an improper authentication vulnerability that allows remote code execution via a flaw in processing authentication on the TCP connection with the management console progra…
CVE-2025-62252 unknown 8mo ago Liferay is Vulnerable to Authorization Bypass Through User-Controlled Key
CVE-2025-62246 unknown 8mo ago Liferay Mentions Web is Vulnerable to Cross-site Scripting
CVE-2025-62242 unknown 8mo ago Liferay Account Admin Web vulnerable to Authorization Bypass Through User-Controlled Key
CVE-2025-62241 unknown 8mo ago Liferay Commerce Order Content Web is Vulnerable to Authorization Bypass Through User-Controlled Key
CVE-2025-62244 unknown 8mo ago Liferay Publications vulnerable to Authorization Bypass Through User-Controlled Key
CVE-2025-62243 unknown 8mo ago Liferay Publications is vulnerable to Incorrect Authorization
CVE-2025-11645 low 2.4 2.4 8mo ago A security vulnerability has been detected in Tomofun Furbo Mobile App up to 7.57.0a on Android. This affects an unknown part of the component Authentication Token Handler. The manipulation leads to …
CVE-2025-62706 unknown FIX slesdebian debian 8mo ago Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JWE zip=DEF path performs unbounded DEFLATE decompression. A very small ciphertext can exp…
CVE-2025-62245 unknown 8mo ago Liferay Portal is vulnerable to CSRF through publication comments
CVE-2025-11581 unknown 8mo ago PowerJob OpenAPIController is missing authorization
CVE-2025-61920 unknown FIX slesdebian debian 8mo ago Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implementation accepts unbounded JWS/JWT header and signature segments. A remote atta…
CVE-2025-11580 unknown 8mo ago PowerJob has Missing Authorization in its /user/list file
CVE-2025-62239 unknown 8mo ago Liferay Portal is vulnerable to XSS through its workflow process builder
CVE-2025-62238 unknown 8mo ago Liferay Portal's Membership page is vulnerable to XSS through “name“ text field
CVE-2025-62237 unknown 8mo ago Liferay Portal Commerce is vulnerable to XSS through account "name" field
CVE-2025-11579 unknown FIX debian debian sles 8mo ago github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary sizes, which allows an attacker to provide a specially crafted RAR file and cause …
CVE-2025-37727 unknown 8mo ago Elasticsearch: Insertion of Sensitive Information into Log File via reindex API
CVE-2025-30001 unknown 8mo ago Apache StreamPark contains an Incorrect Execution-Assigned Permissions vulnerability
CVE-2025-62240 unknown 8mo ago Liferay Portal is vulnerable to XSS through its Calendar Events parameters
CVE-2025-62228 unknown 8mo ago Apache Flink CDC is vulnerable to SQL Injection through maliciously crafted identifiers
CVE-2025-9162 unknown 8mo ago Keycloak Potential Variable Reference in Model Storage Services
CVE-2025-61788 unknown 8mo ago Opencast's Paella Player 7 is vulnerable to Cross-Site Scripting
CVE-2025-43830 unknown 8mo ago Liferay Portal is vulnerable to Stored XSS through Forms text type field
CVE-2025-43829 unknown 8mo ago Liferay Portal Commerce Shop is vulnerable to Stored XSS through SVG file
CVE-2025-43771 unknown 8mo ago Liferay Portal Notifications Widget has multiple XSS vulnerabilities through various text fields
CVE-2025-43821 unknown 8mo ago Liferay Portal is vulnerable to XSS through its Commerce Product's Name text field
CVE-2025-11441 low 3.7 3.7 jhumanj 8mo ago A vulnerability was identified in JhumanJ OpnForm up to 1.9.3. The affected element is an unknown function of the component HTTP Header Handler. The manipulation of the argument X-Forwarded-For leads…
CVE-2025-43823 unknown 8mo ago Liferay Portal is vulnerable to XSS through its Commerce Search Result widget
CVE-2025-43822 unknown 8mo ago Liferay Portal has multiple Stored XSS vulnerabilities on its View Order page
CVE-2025-43824 unknown 8mo ago Liferay Profile Widget does not prevent vCard extension spoofing
CVE-2025-27915 unknown 1.5 KEV 8mo ago Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting vulnerability that exists in the Classic Web Client due to insufficient sanitization of HTML content in ICS files. When a user…
CVE-2025-52472 unknown 8mo ago XWiki Platform is vulnerable to HQL injection via wiki and space search REST API
CVE-2025-49594 unknown 8mo ago XWiki OIDC Authenticator: Users with "view" access can create tokens for any users they can view
CVE-2025-11333 low 2.4 2.4 8mo ago A vulnerability was identified in langleyfcu Online Banking System up to 57437e6400ce0ae240e692c24e6346b8d0c17d7a. This impacts an unknown function of the file /customer_add_action.php of the compone…
CVE-2025-11322 low 3.7 3.7 8mo ago NovoSGA: Manipulation of User Creation Page can lead to weak password requirements
CVE-2025-61882 unknown 2.5 KEVEXP 8mo ago Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise O…
CVE-2021-43226 unknown 1.5 KEV 8mo ago Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms.
CVE-2013-3918 unknown 2.5 KEVEXP 8mo ago Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control, icardie.dll. An attacker could exploit the vulnerability by constructing a sp…
CVE-2011-3402 unknown 2.5 KEVEXP 8mo ago Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers that allows remote attackers to execute arbitrary code via …
CVE-2010-3962 unknown 2.5 KEVEXP 8mo ago Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service…
CVE-2010-3765 unknown 2.5 KEVEXP 8mo ago Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameCo…
CVE-2025-11308 low 3.5 3.5 8mo ago A vulnerability was identified in Vanderlande Baggage 360 7.0.0. This issue affects some unknown processing of the file /api-addons/v1/messages. Such manipulation of the argument Message leads to cro…
CVE-2025-11283 low 2.4 2.4 frappe 8mo ago A vulnerability was determined in Frappe LMS 2.35.0. This affects an unknown function of the component Course Handler. Executing manipulation of the argument Description can lead to cross site script…
CVE-2025-11280 low 3.7 3.7 frappe 8mo ago A flaw has been found in Frappe LMS 2.35.0. Impacted is an unknown function of the file /files/ of the component Assignment Picture Handler. This manipulation causes direct request. The attack may be…
CVE-2025-43825 unknown 8mo ago Liferay Portal exposes sensitive user data through its Freemarker template
CVE-2025-54286 unknown FIX debian debian 8mo ago Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions >= 5.0 on Linux allows an attacker to create and start container instances without user consent via crafted HTML form submissions…