Search

Found 20,976 results in 921ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-52007 unknown 2y ago XXE vulnerability in XSLT parsing in `org.hl7.fhir.core`
CVE-2024-47072 unknown FIX slesdebian debian 2y ago XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
CVE-2024-51504 unknown FIX debian debian 2y ago Apache ZooKeeper: Authentication bypass with IP-based authentication in Admin Server
CVE-2023-1973 unknown FIX debian debian 2y ago Undertow Denial of Service vulnerability
CVE-2023-1932 unknown debian debian 2y ago hibernate-validator Cross-site Scripting vulnerability
CVE-2024-5910 unknown 2.5 KEVEXP 2y ago Palo Alto Networks Expedition contains a missing authentication vulnerability that allows an attacker with network access to takeover an Expedition admin account and potentially access configuration …
CVE-2024-51567 unknown 2.5 KEVEXP 2y ago CyberPanel contains an incorrect default permissions vulnerability that allows a remote, unauthenticated attacker to execute commands as root.
CVE-2024-43093 unknown 1.5 KEV 2y ago Android Framework contains an unspecified vulnerability that allows for privilege escalation.
CVE-2019-16278 unknown 2.5 KEVEXP 2y ago Nostromo nhttpd contains a directory traversal vulnerability in the http_verify() function in a non-chrooted nhttpd server allowing for remote code execution.
CVE-2024-51755 unknown FIX debian debian 2y ago Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the security policy. They are now checked via the property polic…
CVE-2024-51754 unknown FIX debian debian 2y ago Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toString()` method is not allowed by the security policy when the object is part of …
CVE-2024-51751 unknown 2y ago Gradio vulnerable to arbitrary file read with File and UploadButton components
CVE-2024-51736 unknown FIX debian debian 2y ago Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.exe` is located in the current working directory i…
CVE-2024-50345 unknown FIX debian debian 2y ago symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` class, does not parse URI with special characters t…
CVE-2024-50343 unknown FIX debian debian 2y ago symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to trick a `Validator` configured with a regular expression using the `$` metachar…
CVE-2024-50342 unknown FIX debian debian 2y ago symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the `NoPrivateNetworkHttpClient`, so…
CVE-2024-50341 unknown FIX debian debian 2y ago symfony/security-bundle is a module for the Symphony PHP framework which provides a tight integration of the Security component into the Symfony full-stack framework. The custom `user_checker` define…
CVE-2024-50340 unknown FIX debian debian 2y ago symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. When the `register_argv_argc` php directive is set to `on` , and users call any…
CVE-2024-51132 unknown 2y ago HAPI FHIR XML External Entity (XXE) vulnerability
CVE-2024-51746 unknown FIX debian debian 2y ago Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. gitsign may select the wrong Rekor entry to use during online verification when multiple entries are …
CVE-2024-36117 unknown 2y ago Reposilite vulnerable to path traversal while serving javadoc expanded files (arbitrary file read) (`GHSL-2024-074`)
CVE-2024-51127 unknown 2y ago hornetq vulnerable to file overwrite, sensitive information disclosure
CVE-2024-23590 unknown 2y ago Apache Kylin Session Fixation vulnerability
CVE-2024-8957 unknown 1.5 KEV 2y ago PTZOptics PT30X-SDI/NDI cameras contain an OS command injection vulnerability that allows a remote, authenticated attacker to escalate privileges to root via a crafted payload with the ntp_addr param…
CVE-2024-8956 unknown 1.5 KEV 2y ago PTZOptics PT30X-SDI/NDI cameras contain an insecure direct object reference (IDOR) vulnerability that allows a remote, attacker to bypass authentication for the /cgi-bin/param.cgi CGI script. If comb…
CVE-2024-42835 unknown 2y ago langflow has vulnerability in PythonCodeTool component
CVE-2024-48910 unknown FIX debian debian 2y ago DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2.
CVE-2024-48307 unknown 2y ago JeecgBoot SQL Injection vulnerability
CVE-2024-43382 unknown 2y ago Snowflake JDBC Security Advisory
CVE-2024-48063 unknown debian debian 2y ago In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.
CVE-2024-45477 unknown 2y ago Apache NiFi Cross-site Scripting vulnerability
CVE-2024-38821 unknown 2y ago Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications
CVE-2024-49771 unknown 2y ago MPXJ has a Potential Path Traversal Vulnerability
CVE-2024-49760 unknown FIX debian debian 2y ago OpenRefine has a path traversal in LoadLanguageCommand
CVE-2024-47883 unknown FIX debian debian 2y ago Butterfly has path/URL confusion in resource handling leading to multiple weaknesses
CVE-2024-47882 unknown FIX debian debian 2y ago OpenRefine's error page lacks escaping, leading to potential Cross-site Scripting on import of malicious project
CVE-2024-47881 unknown FIX debian debian 2y ago OpenRefine's SQLite integration allows filesystem access, remote code execution (RCE)
CVE-2024-47880 unknown FIX debian debian 2y ago OpenRefine has a reflected cross-site scripting vulnerability (XSS) from POST request in ExportRowsCommand
CVE-2024-47879 unknown FIX debian debian 2y ago OpenRefine's PreviewExpressionCommand, which is eval, lacks protection against cross-site request forgery (CSRF)
CVE-2024-47878 unknown FIX debian debian 2y ago OpenRefine has a reflected cross-site scripting vulnerability (XSS) in GData extension (authorized.vt)
CVE-2024-45031 unknown 2y ago Apache Syncope: Stored XSS in Console and Enduser
CVE-2024-37383 unknown 2.5 KEVEXPFIX debian debian 2y ago RoundCube Webmail contains a cross-site scripting (XSS) vulnerability in the handling of SVG animate attributes that allows a remote attacker to run malicious JavaScript code.
CVE-2024-20481 unknown 1.5 KEV 2y ago Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a missing release of resource after effective lifetime vulnerability that could allow an unauthenticated, remote att…
CVE-2024-47575 unknown 2.5 KEVEXP 2y ago Fortinet FortiManager contains a missing authentication vulnerability in the fgfmd daemon that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted re…
CVE-2024-8980 unknown 2y ago Liferay Portal and Liferay DXP Vulnerable to CSRF in the Script Console
CVE-2024-38002 unknown 2y ago Liferay Portal and Liferay DXP Workflow Component Does Not Check User Permissions
CVE-2024-26273 unknown 2y ago Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the Content Page Editor
CVE-2024-26272 unknown 2y ago Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the Content Page Editor
CVE-2024-26271 unknown 2y ago Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the My Account Widget
CVE-2024-38094 unknown 1.5 KEV 2y ago Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution.
CVE-2024-9537 unknown 1.5 KEV 2y ago ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component.
CVE-2024-38820 unknown debian debian 2y ago Spring Framework DataBinder Case Sensitive Match Exception
CVE-2024-49580 unknown 2y ago JetBrains Ktor information disclosure
CVE-2024-40711 unknown 1.5 KEV 2y ago Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthenticated user to perform remote code execution.
CVE-2024-45217 unknown FIX debian debian 2y ago Insecure Default Initialization of Resource vulnerability in Apache Solr
CVE-2024-45216 unknown FIX debian debian 2y ago Improper Authentication vulnerability in Apache Solr
CVE-2024-47874 unknown FIX slesdebian debian 2y ago Starlette is an Asynchronous Server Gateway Interface (ASGI) framework/toolkit. Prior to version 0.40.0, Starlette treats `multipart/form-data` parts without a `filename` as text form fields and buff…
CVE-2024-47876 unknown 2y ago SAK-50571 Sakai Kernel users created with type roleview can login as a normal user
CVE-2024-30088 unknown 1.5 KEV 2y ago Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation.
CVE-2024-28987 unknown 2.5 KEVEXP 2y ago SolarWinds Web Help Desk contains a hardcoded credential vulnerability that could allow a remote, unauthenticated user to access internal functionality and modify data.
CVE-2024-6763 unknown debian debian sles 2y ago Eclipse Jetty URI parsing of invalid authority
CVE-2024-8184 unknown FIX debian debian sles 2y ago Eclipse Jetty's ThreadLimitHandler.getRemote() vulnerable to remote DoS attacks
CVE-2024-6762 unknown FIX debian debian sles 2y ago Eclipse Jetty's PushSessionCacheFilter can cause remote DoS attacks
CVE-2024-7318 unknown 2y ago Keycloaks's One Time Passcode (OTP) is valid longer than expiration timeSeverity
CVE-2024-7341 unknown 2y ago Keycloak has session fixation in Elytron SAML adapters
CVE-2024-8883 unknown 2y ago Keycloak has Vulnerable Redirect URI Validation Results in Open Redirect
CVE-2024-8698 unknown 2y ago Improper Verification of SAML Responses Leading to Privilege Escalation in Keycloak
CVE-2023-50780 unknown 2y ago Apache ActiveMQ Artemis: Authenticated users could perform RCE via Jolokia MBeans
CVE-2024-9823 unknown FIX debian debian sles 2y ago Eclipse Jetty has a denial of service vulnerability on DosFilter
CVE-2023-25581 unknown 2y ago pac4j-core affected by a Java deserialization vulnerability
CVE-2024-21534 unknown 2y ago JSONPath Plus Remote Code Execution (RCE) Vulnerability
CVE-2024-4658 unknown 2y ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TE Informatics Nova CMS allows SQL Injection. This issue affects Nova CMS: before 5.0.
CVE-2024-9286 unknown 2y ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in TRtek Software Distant Education Platform allows SQL Injection, Parameter Injection. This issue …
CVE-2024-28168 unknown FIX debian debian sles 2y ago Apache XML Graphics FOP XML External Entity Reference ('XXE') vulnerability
CVE-2024-9380 unknown 1.5 KEV 2y ago Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass …
CVE-2024-9379 unknown 1.5 KEV 2y ago Ivanti Cloud Services Appliance (CSA) contains a SQL injection vulnerability in the admin web console in versions prior to 5.0.2, which can allow a remote attacker authenticated as administrator to r…
CVE-2024-23113 unknown 1.5 KEV 2y ago Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb contain a format string vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted r…
CVE-2024-9622 unknown 2y ago HTTP Request Smuggling Leading to Client Timeouts in resteasy-netty4
CVE-2024-9621 unknown 2y ago Quarkus CXF logs passwords and other secrets
CVE-2024-45231 unknown FIX slesdebian debian 2y ago An issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view implementing password reset flows, allows remote attackers to…
CVE-2024-45230 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.1 before 5.1.1, 5.0 before 5.0.9, and 4.2 before 4.2.16. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via ve…
CVE-2024-43573 unknown 1.5 KEV 2y ago Microsoft Windows MSHTML Platform contains an unspecified spoofing vulnerability which can lead to a loss of confidentiality.
CVE-2024-43572 unknown 1.5 KEV 2y ago Microsoft Windows Management Console contains unspecified vulnerability that allows for remote code execution.
CVE-2024-43047 unknown 1.5 KEV 2y ago Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services while maintaining memory maps of HLOS memory.
CVE-2024-47211 unknown FIX debian debian 2y ago In OpenStack Ironic before 21.4.4, 22.x and 23.x before 23.0.3, 23.x and 24.x before 24.1.3, and 25.x and 26.x before 26.1.0, there is a lack of checksum validation of supplied image_source URLs when…
CVE-2024-47855 unknown FIX slesdebian debian 2y ago JSON-lib mishandles an unbalanced comment string
CVE-2024-47561 unknown 2y ago Apache Avro Java SDK: Arbitrary Code Execution when reading Avro Data (Java SDK)
CVE-2024-47554 unknown FIX debian debian sles 2y ago Apache Commons IO: Possible denial of service attack on untrusted input to XmlStreamReader
CVE-2024-45519 unknown 1.5 KEV 2y ago Synacor Zimbra Collaboration Suite (ZCS) contains an unspecified vulnerability in the postjournal service that may allow an unauthenticated user to execute commands.
CVE-2024-47807 unknown 2y ago Jenkins OpenId Connect Authentication Plugin lacks issuer claim validation
CVE-2024-47806 unknown 2y ago Jenkins OpenId Connect Authentication Plugin lacks audience claim validation
CVE-2024-47805 unknown 2y ago Jenkins Credentials plugin reveals encrypted values of credentials to users with Extended Read permission
CVE-2024-47804 unknown 2y ago Jenkins item creation restriction bypass vulnerability
CVE-2024-47803 unknown 2y ago Jenkins exposes multi-line secrets through error messages
CVE-2024-29824 unknown 2.5 KEVEXP 2y ago Ivanti Endpoint Manager (EPM) contains a SQL injection vulnerability in Core server that allows an unauthenticated attacker within the same network to execute arbitrary code.
CVE-2024-47534 unknown FIX debian debian 2y ago go-tuf is a Go implementation of The Update Framework (TUF). The go-tuf client inconsistently traces the delegations. For example, if targets delegate to "A", and to "B", and "B" delegates to "C", th…
CVE-2024-9329 unknown 2y ago Eclipse Glassfish improperly handles http parameters
CVE-2024-45772 unknown sles 2y ago Deserialization of Untrusted Data vulnerability in Apache Lucene Replicator.
CVE-2023-25280 unknown 1.5 KEV 2y ago D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafted payload with the ping_addr parameter t…
CVE-2020-15415 unknown 1.5 KEV 2y ago DrayTek Vigor3900, Vigor2960, and Vigor300B devices contain an OS command injection vulnerability in cgi-bin/mainfunction.cgi/cvmcfgupload that allows for remote code execution via shell metacharacte…