Search

Found 25,320 results in 1292ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-43766 unknown 10mo ago Liferay Portal allows unrestricted upload of file in the style books component
CVE-2025-43765 unknown 10mo ago Liferay Portal stored cross-site scripting in text field of the web content structure
CVE-2025-43767 unknown 10mo ago Liferay Portal allows open redirect in /c/portal/edit_info_item parameter redirect
CVE-2025-43770 unknown 10mo ago Liferay Portal vulnerable to Reflected XSS with the referer and forward parameter
CVE-2025-43769 unknown 10mo ago Liferay Portal vulnerable to Stored XSS in Components portlet
CVE-2025-43768 unknown 10mo ago Liferay Portal JSONWS API endpoint shares sensitive information
CVE-2025-43762 unknown 10mo ago Liferay Portal users can upload an unlimited amount of files
CVE-2025-43761 unknown 10mo ago Liferay Portal Reflected XSS in CKeditor 4.21.0 endpoint
CVE-2025-43759 unknown 10mo ago Liferay Portal users are able to add system admin portlets to pages
CVE-2025-43758 unknown 10mo ago Liferay Portal's unauthenticated users can access loaded files via URL before submitting the object entry
CVE-2025-43760 unknown 10mo ago Liferay Portal Reflected Cross-Site Scripting Vulnerability via PortalUtil.escapeRedirect
CVE-2025-43751 unknown 10mo ago Liferay Portal User Enumeration Vulnerability via the Create Account Page
CVE-2025-51825 unknown 10mo ago JeecgBoot SQL Injection Vulnerability
CVE-2025-9340 unknown 10mo ago Bouncy Castle for Java has Out-of-Bounds Write Vulnerability
CVE-2025-9341 unknown 10mo ago Bouncy Castle for Java has Uncontrolled Resource Consumption Vulnerability
CVE-2025-43752 unknown 10mo ago Liferay Portal's Unlimited File Upload Could Result in DoS
CVE-2025-43753 unknown 10mo ago Liferay Portal Reflected Cross-Site Scripting Vulnerability via Form Container
CVE-2025-51606 unknown 10mo ago hippo4j Includes Hard Coded Secret Key in JWT Creation
CVE-2025-43754 unknown 10mo ago Liferay Portal Username Enumeration Vulnerability
CVE-2025-43756 unknown 10mo ago Liferay Portal Reflected Cross-Site Scripting Vulnerability via snippet Parameter
CVE-2025-43755 unknown 10mo ago Liferay Portal Stored Cross-Site Scripting Vulnerability via GroupPagesPortlet_type Parameter
CVE-2025-55743 unknown 10mo ago UnoPim vulnerable to remote code execution through Arbitrary File upload
CVE-2025-9301 low 3.3 3.3 debian debian sles 10mo ago A vulnerability was determined in cmake 4.1.20250725-gb5cce23. This affects the function cmForEachFunctionBlocker::ReplayItems of the file cmForEachCommand.cxx. This manipulation causes reachable ass…
CVE-2025-43300 unknown 1.5 KEV 10mo ago Apple iOS, iPadOS, and macOS contain an out-of-bounds write vulnerability in the Image I/O framework.
CVE-2025-54988 unknown FIX debian debian 10mo ago Apache Tika XXE Vulnerability via Crafted XFA File Inside a PDF
CVE-2025-43757 unknown 10mo ago Liferay Portal Vulnerable to Cross-Site Scripting via DDMPortlet_definition Parameter
CVE-2025-43746 unknown 10mo ago Liferay Portal Vulnerable to Cross-Site Scripting in Dynamic Data Mapping
CVE-2025-5115 unknown FIX debian debian sles 10mo ago Eclipse Jetty affected by MadeYouReset HTTP/2 vulnerability
CVE-2025-43748 unknown 10mo ago Liferay Portal Vulnerable to Cross-Site Request Forgery
CVE-2025-43750 unknown 10mo ago Liferay Portal Unvalidated File Upload
CVE-2025-43749 unknown 10mo ago Liferay Portal Unauthenticated File Access via URL
CVE-2025-43742 unknown 10mo ago Liferay Portal Vulnerable to Cross-Site Scripting through URLs
CVE-2025-43741 unknown 10mo ago Liferay Portal Vulnerable to Cross-Site Scripting via assetTagNames Parameter
CVE-2024-39954 unknown 10mo ago Apache EventMesh Vulnerable to Server-Side Request Forgery in WebhookUtil.java
CVE-2025-9193 low 3.5 3.5 10mo ago A flaw has been found in TOTVS Portal Meu RH up to 12.1.17. Impacted is an unknown function of the component Password Reset Handler. Executing manipulation of the argument redirectUrl can lead to ope…
CVE-2025-43744 unknown 10mo ago Liferay Portal Vulnerable to Cross-Site Scripting via DDM Structure Field Labels
CVE-2025-43743 unknown 10mo ago Liferay Portal Enumeration Discrepancy in Calendars
CVE-2025-43745 unknown 10mo ago Liferay Portal CSRF Vulnerability via Endpoint Parameter
CVE-2025-43737 unknown 10mo ago Liferay Portal Vulnerable to Cross-Site Scripting via backURL Paramter
CVE-2025-9165 low 2.5 2.5 FIX slesdebian debian libtiff 10mo ago A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipul…
CVE-2025-43738 unknown 10mo ago Liferay Portal Reflected Cross-Site Scripting Vulnerability in displayType Parameter
CVE-2025-43739 unknown 10mo ago Liferay Portal Email Modification Vulnerability via Calendar Portlet
CVE-2025-43731 unknown 10mo ago Liferay Portal Vulnerable to Cross-Site Scripting
CVE-2025-9119 low 2.4 2.4 10mo ago A vulnerability was determined in Netis WF2419 1.2.29433. This vulnerability affects unknown code of the file /index.htm of the component Wireless Settings Page. This manipulation of the argument SSI…
CVE-2025-3639 unknown 10mo ago Liferay Portal Login Bypass Vulnerability
CVE-2025-43733 unknown 10mo ago Liferay Portal Vulnerable to Cross-Site Scripting
CVE-2025-43732 unknown 10mo ago Liferay Portal Vulnerable to Insecure Direct Object Reference
CVE-2025-41242 unknown debian debian 10mo ago Spring Framework MVC Applications Path Traversal Vulnerability
CVE-2025-9109 low 3.7 3.7 portabilis 10mo ago A security flaw has been discovered in Portabilis i-Diario up to 1.5.0. Affected by this vulnerability is an unknown functionality of the file /password/email of the component Password Recovery Endpo…
CVE-2025-9103 low 2.4 2.4 10mo ago A vulnerability was detected in ZenCart 2.1.0. Affected by this vulnerability is an unknown functionality of the component CKEditor. The manipulation leads to cross site scripting. The attack can be …
CVE-2025-9096 low 3.5 3.5 10mo ago ExpressGateway Cross-Site Scripting Vulnerability in lib/rest/routes/apps.js
CVE-2025-54948 unknown 1.5 KEV 10mo ago Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attacker to upload malicious code and execute commands …
CVE-2025-9095 low 3.5 3.5 10mo ago ExpressGateway Cross-Site Scripting Vulnerability in lib/rest/routes/users.js
CVE-2025-9092 unknown 10mo ago Bouncy Castle for Java Uncontrolled Resource Consumption Vulnerability
CVE-2025-9005 low 3.7 3.7 mtons 10mo ago A vulnerability was determined in mtons mblog up to 3.5.0. Affected is an unknown function of the file /register. The manipulation leads to information exposure through error message. It is possible …
CVE-2025-8961 low 3.3 3.3 FIX slesdebian debian libtiff 10mo ago A weakness has been identified in LibTIFF 4.7.0. This affects the function main of the file tiffcrop.c of the component tiffcrop. Executing manipulation can lead to memory corruption. The attack can …
CVE-2025-8927 low 3.7 3.7 mtons 10mo ago A vulnerability was determined in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality of the file /email/send_code of the component Verification Code Handler. The manipulati…
CVE-2025-55163 unknown FIX slesdebian debian 10mo ago Netty affected by MadeYouReset HTTP/2 DDoS vulnerability
CVE-2025-8876 unknown 1.5 KEV 10mo ago N-able N-Central contains a command injection vulnerability via improper sanitization of user input.
CVE-2025-8875 unknown 1.5 KEV 10mo ago N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution.
CVE-2025-43734 unknown 10mo ago Liferay Portal 7.4.0 and Liferay DXP have a reflected cross-site scripting (XSS) vulnerability
CVE-2025-8747 unknown FIX debian debian 10mo ago Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality
CVE-2025-21096 low 1.9 1.9 10mo ago Improper buffer restrictions in the firmware for some Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.
CVE-2025-8885 unknown FIX debian debian sles 10mo ago Bouncy Castle for Java on All (API modules) allows Excessive Allocation
CVE-2025-43736 unknown 10mo ago Liferay Portal and Liferay DXP have a Denial Of Service via File Upload (DOS) vulnerability
CVE-2025-8088 unknown 1.5 KEV 10mo ago RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.
CVE-2025-55159 unknown FIX slesdebian debian 10mo ago slab is a pre-allocated storage for a uniform data type. In version 0.4.10, the get_disjoint_mut method incorrectly checked if indices were within the slab's capacity instead of its length, allowing …
CVE-2013-3893 unknown 2.5 KEVEXP 10mo ago Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code execution. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users shoul…
CVE-2007-0671 unknown 1.5 KEV 10mo ago Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachmen…
CVE-2025-8836 low 3.3 3.3 sles jasper_project 10mo ago A vulnerability was determined in JasPer up to 4.2.5. Affected by this issue is the function jpc_floorlog2 of the file src/libjasper/jpc/jpc_enc.c of the component JPEG2000 Encoder. The manipulation …
CVE-2025-8834 low 2.4 2.4 10mo ago A vulnerability has been found in JCG Link-net LW-N915R 17s.20.001.908. Affected is an unknown function of the file /wireless/basic.asp of the component Wireless Basic Settings Page. The manipulation…
CVE-2025-8765 low 3.5 3.5 10mo ago A vulnerability classified as problematic was found in Datacom DM955 5GT 1200 825.8010.00. Affected by this vulnerability is an unknown functionality of the component Wireless Basic Settings. The man…
CVE-2025-4581 unknown 10mo ago Liferay Portal and Liferay DXP vulnerable to Server-Side Request Forgery
CVE-2025-8737 low 3.5 3.5 10mo ago A vulnerability, which was classified as problematic, was found in zlt2000 microservices-platform up to 6.0.0. This affects the function onLogoutSuccess of the file src/main/java/com/central/oauth/ha…
CVE-2025-8735 low 3.3 3.3 debian debian 10mo ago A vulnerability classified as problematic was found in GNU cflow up to 1.8. Affected by this vulnerability is the function yylex of the file c.c of the component Lexer. The manipulation leads to null…
CVE-2025-4576 unknown 10mo ago Liferay Portal Reflected XSS in blogs-web
CVE-2025-8732 low 3.3 3.3 debian debian sles 10mo ago A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads…
CVE-2025-53606 unknown 10mo ago Apache Seata: Deserialization of untrusted Data in Apache Seata Server
CVE-2025-48913 unknown google 10mo ago Apache CXF: Untrusted JMS configuration can lead to RCE
CVE-2025-8698 low 3.3 3.3 open5gs 10mo ago A vulnerability was found in Open5GS up to 2.7.5. It has been classified as problematic. Affected is the function amf_nsmf_pdusession_handle_release_sm_context of the file src/amf/nsmf-handler.c of t…
CVE-2025-54368 unknown FIX slesdebian debian 10mo ago uv is a Python package and project manager written in Rust. In versions 0.8.5 and earlier, remote ZIP archives were handled in a streamwise fashion, and file entries were not reconciled against the a…
CVE-2025-54799 unknown FIX debian debian 10mo ago Let's Encrypt client and ACME library written in Go (Lego). In versions 4.25.1 and below, the github.com/go-acme/lego/v4/acme/api package (thus the lego library and the lego cli as well) don't enforc…
CVE-2012-10024 unknown 1.0 EXP 10mo ago XBMC version 11.0 contains a path traversal vulnerability in its embedded HTTP server. When accessed via HTTP Basic Authentication, the server fails to properly sanitize URI input, allowing authentic…
CVE-2012-10026 unknown 1.0 EXP 10mo ago The WordPress plugin Asset-Manager version 2.0 and below contains an unauthenticated arbitrary file upload vulnerability in upload.php. The endpoint fails to properly validate and restrict uploaded f…
CVE-2025-8586 low 3.3 3.3 libav 10mo ago A vulnerability, which was classified as problematic, was found in libav up to 12.3. This affects the function ff_seek_frame_binary of the file /libavformat/utils.c of the component MPEG File Parser.…
CVE-2025-8584 low 3.3 3.3 libav 10mo ago A vulnerability classified as problematic was found in libav up to 12.3. Affected by this vulnerability is the function av_buffer_unref of the file libavutil/buffer.c of the component AVI File Parser…
CVE-2025-54125 unknown 10mo ago XWiki exposes passwords and emails stored in fields not named password/email in xml.vm
CVE-2025-54124 unknown 10mo ago XWiki leaks password hashes and other accessible password properties
CVE-2025-32430 unknown 10mo ago XWiki allows Reflected XSS in two templates
CVE-2025-8549 low 3.7 3.7 pybbs_project 10mo ago A vulnerability was found in atjiu pybbs up to 6.0.0. It has been classified as critical. Affected is the function update of the file src/main/java/co/yiiu/pybbs/controller/admin/UserAdminController.…
CVE-2025-8548 low 3.7 3.7 pybbs_project 10mo ago A vulnerability was found in atjiu pybbs up to 6.0.0 and classified as problematic. This issue affects the function sendEmailCode of the file src/main/java/co/yiiu/pybbs/controller/api/SettingsApiCon…
CVE-2025-4604 unknown 10mo ago Liferay Portal CAPTCHA Bypass for Gogo Shell
CVE-2025-8534 low 2.5 2.5 FIX slesdebian debian libtiff 10mo ago A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads …
CVE-2022-40799 unknown 1.5 KEV 10mo ago D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands on the device. The impacted products could be…
CVE-2022-29458 low 2.5 FIX rhel sles rocky 10mo ago ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.
CVE-2020-25079 unknown 1.5 KEV 10mo ago D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users shou…
CVE-2020-25078 unknown 1.5 KEV 10mo ago D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be end-of-life (EoL) and/or end…
CVE-2025-8519 low 2.7 2.7 vvveb 10mo ago A vulnerability classified as problematic has been found in givanz Vvveb up to 1.0.5. This affects an unknown part of the file /vadmin123/index.php?module=editor/editor of the component Drag-and-Drop…
CVE-2025-8515 low 3.7 3.7 intelbras 10mo ago A weakness has been identified in Intelbras InControl 2.21.60.9. This vulnerability affects unknown code of the file /v1/operador/ of the component JSON Endpoint. Executing manipulation can lead to i…
CVE-2024-52279 unknown 10mo ago Apache Zeppelin: Arbitrary file read by adding malicious JDBC connection string