Search

Found 25,373 results in 850ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-7080 low 3.7 3.7 11mo ago A vulnerability, which was classified as problematic, was found in Done-0 Jank up to 322caebbad10568460364b9667aa62c3080bfc17. Affected is an unknown function of the file internal/utils/jwt_utils.go …
CVE-2025-53602 unknown 11mo ago Zipkin Server vulnerable to Insecure Resource Initialization through its /heapdump endpoint
CVE-2025-7061 low 2.7 2.7 intelbras 11mo ago A vulnerability was found in Intelbras InControl up to 2.21.60.9. It has been declared as problematic. This vulnerability affects unknown code of the file /v1/operador/. The manipulation leads to csv…
CVE-2025-6554 unknown 1.5 KEVFIX debian debian 11mo ago Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
CVE-2025-53103 unknown FIX debian debian sles 11mo ago junit-platform-reporting can leak Git credentials through its OpenTestReportGeneratingListener
CVE-2025-48928 unknown 1.5 KEV 11mo ago TeleMessage TM SGNL contains an exposure of core dump file to an unauthorized control sphere Vulnerability. This vulnerability is based on a JSP application in which the heap content is roughly equiv…
CVE-2025-48927 unknown 1.5 KEV 11mo ago TeleMessage TM SGNL contains an initialization of a resource with an insecure default vulnerability. This vulnerability relies on how the Spring Boot Actuator is configured with an exposed heap dump …
CVE-2025-6932 low 3.7 3.7 11mo ago A vulnerability, which was classified as problematic, was found in D-Link DCS-7517 up to 2.02.0. This affects the function g_F_n_GenPassForQlync of the file /bin/httpd of the component Qlync Password…
CVE-2025-53106 unknown 11mo ago Graylog vulnerable to privilege escalation through API tokens
CVE-2025-26074 unknown 11mo ago Conductor vulnerable to OS command injection through unrestricted access to Java classes
CVE-2025-53003 unknown 11mo ago Janssen Config API returns results without scope verification
CVE-2025-6543 unknown 1.5 KEV 11mo ago Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured as Gateway (VPN virtual server, ICA Pro…
CVE-2025-53393 unknown 11mo ago akka-cluster-metrics uses Java serialization for cluster metrics
CVE-2025-32897 unknown 11mo ago Apache Seata Vulnerable to Deserialization of Untrusted Data
CVE-2025-6817 low 3.3 3.3 debian debian hdfgroup 11mo ago A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5C__load_entry of the file /src/H5Centry.c. The manipulation leads to resource co…
CVE-2025-6816 low 3.3 3.3 debian debian sles hdfgroup 11mo ago A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5O__fsinfo_encode of the file /src/H5Ofsinfo.c. The manipulation leads to heap-based buffe…
CVE-2025-6750 low 3.3 3.3 debian debian sles hdfgroup 1y ago A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. Affected by this issue is the function H5O__mtime_new_encode of the file src/H5Omtime.c. The manipulation leads to…
CVE-2025-6748 low 2.1 2.1 1y ago A vulnerability classified as problematic has been found in Bharti Airtel Thanks App 4.105.4 on Android. Affected is an unknown function of the file /Android/data/com.myairtelapp/files/. The manipula…
CVE-2025-5731 unknown 1y ago Infinispan CLI vulnerable to Generation of Error Message Containing Sensitive Information
CVE-2025-52890 unknown FIX debian debian 1y ago Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus versions 6.12 and 6.13generates nftables rules that partially bypass security optio…
CVE-2025-52889 unknown FIX debian debian 1y ago Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus version 6.12 and 6.13 generates nftables rules for local services (DHCP, DNS...) th…
CVE-2025-6669 low 3.7 3.7 1y ago A vulnerability was found in gooaclok819 sublinkX up to 1.8. It has been declared as problematic. This vulnerability affects unknown code of the file middlewares/jwt.go. The manipulation with the inp…
CVE-2025-52888 unknown 1y ago Allure Report allows Improper XXE Restriction via DocumentBuilderFactory
CVE-2024-54085 unknown 1.5 KEV 1y ago AMI MegaRAC SPx contains an authentication bypass by spoofing vulnerability in the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integ…
CVE-2024-0769 unknown 1.5 KEV 1y ago D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulation of the argument service with the input ../../../../htdoc…
CVE-2019-6693 unknown 1.5 KEV 1y ago Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key.
CVE-2025-6536 low 3.3 3.3 debian debian 1y ago A vulnerability has been found in Tarantool up to 3.3.1 and classified as problematic. Affected by this vulnerability is the function tm_to_datetime in the library src/lib/core/datetime.c. The manipu…
CVE-2025-6527 low 3.1 3.1 1y ago A vulnerability, which was classified as problematic, was found in 70mai M300 up to 20250611. Affected is an unknown function of the component Web Server. The manipulation leads to improper access co…
CVE-2025-6524 low 3.1 3.1 1y ago A vulnerability classified as problematic has been found in 70mai 1S up to 20250611. This affects an unknown part of the component Video Services. The manipulation leads to improper authentication. A…
CVE-2025-49574 unknown 1y ago Quarkus potentially leaks data when duplicating a duplicated context
CVE-2025-4563 low 2.5 FIX arch archdebian debian sles 1y ago A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled,…
CVE-2025-6509 low 3.5 3.5 1y ago A vulnerability was found in seaswalker spring-analysis up to 4379cce848af96997a9d7ef91d594aa129be8d71. It has been declared as problematic. Affected by this vulnerability is the function echo of the…
CVE-2025-6497 low 3.3 3.3 debian debian 1y ago A vulnerability was found in HTACG tidy-html5 5.8.0. It has been rated as problematic. This issue affects the function prvTidyParseNamespace of the file src/parser.c. The manipulation leads to reacha…
CVE-2025-6496 low 3.3 3.3 debian debian 1y ago A vulnerability was found in HTACG tidy-html5 5.8.0. It has been declared as problematic. This vulnerability affects the function InsertNodeAsParent of the file src/parser.c. The manipulation leads t…
CVE-2025-6494 low 3.3 3.3 FIX slesdebian debian 1y ago A vulnerability was found in sparklemotion nokogiri c29c920907366cb74af13b4dc2230e9c9e23b833. It has been classified as problematic. This affects the function hashmap_get_with_hash of the file gumbo-…
CVE-2025-6490 low 3.3 3.3 FIX slesdebian debian 1y ago A vulnerability was found in sparklemotion nokogiri c29c920907366cb74af13b4dc2230e9c9e23b833 and classified as problematic. This issue affects the function hashmap_set_with_hash of the file gumbo-par…
CVE-2025-6401 low 3.5 3.5 1y ago A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101. It has been classified as problematic. This affects an unknown part of the file /boafrm/formFilter of the component HTTP POST Message…
CVE-2025-6384 unknown 1y ago Crafter Studio Groovy Sandbox Bypass
CVE-2025-6275 low 3.3 3.3 debian debian webassembly 1y ago A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been declared as problematic. Affected by this vulnerability is the function GetFuncOffset of the file src/interp/binary-reader-inte…
CVE-2025-6274 low 3.3 3.3 debian debian webassembly 1y ago A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been classified as problematic. Affected is the function OnDataCount of the file src/interp/binary-reader-interp.cc. The manipulatio…
CVE-2025-6273 low 3.3 3.3 debian debian webassembly 1y ago A vulnerability was found in WebAssembly wabt up to 1.0.37 and classified as problematic. This issue affects the function LogOpcode of the file src/binary-reader-objdump.cc. The manipulation leads to…
CVE-2025-6272 low 3.3 3.3 wasm3_project 1y ago A vulnerability has been found in wasm3 0.5.0 and classified as problematic. This vulnerability affects the function MarkSlotAllocated of the file source/m3_compile.c. The manipulation leads to out-o…
CVE-2025-6271 low 3.3 3.3 swftools 1y ago A vulnerability, which was classified as problematic, was found in swftools up to 0.9.2. This affects the function wav_convert2mono in the library lib/wav.c of the component wav2swf. The manipulation…
CVE-2025-48059 unknown 1y ago PowSyBl Core Contains a Polynomial ReDoS in RegexCriterion
CVE-2025-48058 unknown 1y ago PowSyBl Core contains Polynomial REDoS’es
CVE-2025-47771 unknown 1y ago PowSyBl Core allows deserialization of untrusted SparseMatrix data
CVE-2025-47293 unknown 1y ago PowSyBl Core XML Reader allows XXE and SSRF
CVE-2025-32896 unknown 1y ago Apache SeaTunnel: Unauthenticated insecure access
CVE-2022-49957 unknown FIX slesdebian debian 1y ago In the Linux kernel, the following vulnerability has been resolved: kcm: fix strp_init() order and cleanup strp_init() is called just a few lines above this csk->sk_user_data check, it also initial…
CVE-2025-3248 unknown 2.5 KEVEXP 1y ago Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests.
CVE-2025-6141 low 3.3 3.3 FIX slesdebian debian 1y ago A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipu…
CVE-2025-6140 low 3.3 3.3 FIX slesdebian debian gabime 1y ago A vulnerability, which was classified as problematic, was found in spdlog up to 1.15.1. This affects the function scoped_padder in the library include/spdlog/pattern_formatter-inl.h. The manipulation…
CVE-2025-6139 low 3.9 3.9 1y ago A vulnerability, which was classified as problematic, has been found in TOTOLINK T10 4.1.8cu.5207. Affected by this issue is some unknown functionality of the file /etc/shadow.sample. The manipulatio…
CVE-2025-6170 low 2.5 2.5 FIX arch arch slesdebian debian redhatxmlsoft 1y ago A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, …
CVE-2025-49124 unknown FIX slesdebian debian 1y ago Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects A…
CVE-2025-3594 unknown 1y ago Liferay Portal path traversal vulnerability with the downloading and installation of Xuggler
CVE-2025-3526 unknown 1y ago Liferay Portal SessionClicks does not restrict the saving of request parameters in the HTTP session
CVE-2025-3602 unknown 1y ago Liferay Portal does not limit the depth of a GraphQL queries
CVE-2025-6107 low 3.1 3.1 1y ago A vulnerability was found in comfyanonymous comfyui 0.3.40. It has been classified as problematic. Affected is the function set_attr of the file /comfy/utils.py. The manipulation leads to dynamically…
CVE-2025-43200 unknown 1.5 KEV 1y ago Apple iOS, iPadOS, macOS, watchOS, and visionOS, contain an unspecified vulnerability when processing a maliciously crafted photo or video shared via an iCloud Link.
CVE-2023-33538 unknown 1.5 KEV 1y ago TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm. The impacted products could be end-of-life (EoL) an…
CVE-2025-49585 unknown 1y ago XWiki does not require right warnings for XClass definitions
CVE-2025-49586 unknown 1y ago XWiki allows remote code execution through preview of XClass changes in AWM editor
CVE-2025-49587 unknown 1y ago XWiki does not require right warnings for notification displayer objects
CVE-2025-49584 unknown 1y ago XWiki makes title of inaccessible pages available through the class property values REST API
CVE-2025-49583 unknown 1y ago XWiki provides no warning when granting XWiki.Notifications.Code.NotificationEmailRendererClass admin right
CVE-2025-49581 unknown 1y ago XWiki allows remote code execution through default value of wiki macro wiki-type parameters
CVE-2025-49582 unknown 1y ago XWiki's required right warnings for macros are incomplete
CVE-2025-49580 unknown 1y ago XWiki allows privilege escalation through link refactoring
CVE-2025-6052 low 3.7 3.7 FIX debian debian sles gnome 1y ago A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation.…
CVE-2025-46096 unknown 1y ago Solon Vulnerable to Directory Traversal
CVE-2025-41234 unknown FIX debian debian 1y ago Spring Framework vulnerable to a reflected file download (RFD)
CVE-2024-56158 unknown 1y ago XWiki allows SQL injection in query endpoint of REST API with Oracle
CVE-2025-49146 unknown FIX debian debian sles 1y ago pgjdbc Client Allows Fallback to Insecure Authentication Despite channelBinding=require Configuration
CVE-2025-30220 unknown 1y ago [XBOW-025-068] XML External Entity (XXE) Processing Vulnerability in GeoServer WFS Service
CVE-2025-30145 unknown 1y ago GeoServer Infinite Loop Vulnerability in Jiffle process
CVE-2025-27505 unknown 1y ago GeoServer Missing Authorization on REST API Index
CVE-2024-40625 unknown 1y ago Coverage REST API Server Side Request Forgery
CVE-2024-38524 unknown 1y ago GWC Home Page communicate version and revision information
CVE-2024-34711 unknown 1y ago GeoServer has improper ENTITY_RESOLUTION_ALLOWLIST URI validation in XML Processing (SSRF)
CVE-2024-29198 unknown 1y ago GeoServer Vulnerable to Unauthenticated SSRF via TestWfsPost
CVE-2025-27819 unknown 1y ago Apache Kafka Deserialization of Untrusted Data vulnerability
CVE-2025-27818 unknown 1y ago Apache Kafka Deserialization of Untrusted Data vulnerability
CVE-2025-27817 unknown 1y ago Apache Kafka Client Arbitrary File Read and Server Side Request Forgery Vulnerability
CVE-2025-33053 unknown 2.5 KEVEXP 1y ago Microsoft Windows contains an external control of file name or path vulnerability that could allow an attacker to execute code from a remote WebDAV location specified by the WorkingDirectory attribut…
CVE-2025-5889 low 3.1 3.1 FIX slesdebian debian 1y ago A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The man…
CVE-2025-5864 low 3.7 3.7 1y ago A vulnerability was found in Tenda TDSEE App up to 1.7.12. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /app/ConfirmSmsCode of the compo…
CVE-2025-32433 unknown 2.5 KEVEXPFIX debian debian sles 1y ago Erlang Erlang/OTP SSH server contains a missing authentication for critical function vulnerability. This could allow an attacker to execute arbitrary commands without valid credentials, potentially l…
CVE-2024-42009 unknown 1.5 KEVFIX debian debian 1y ago RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desan…
CVE-2025-49128 unknown FIX debian debian 1y ago Jackson-core Vulnerable to Memory Disclosure via Source Snippet in JsonLocation
CVE-2025-49009 unknown 1y ago Para Inserts Sensitive Information into Log File for Facebook authentication
CVE-2025-5806 unknown 1y ago Jenkins Gatling Plugin Vulnerable to Cross-Site Scripting (XSS)
CVE-2025-27531 unknown 1y ago Apache InLong Deserialization of Untrusted Data Vulnerability
CVE-2025-48432 low 2.5 FIX arch arch slesdebian debian 1y ago An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially…
CVE-2025-5419 unknown 1.5 KEVFIX debian debian 1y ago Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-35036 unknown debian debian 1y ago Hibernate Validator may interpolate user-supplied input in a constraint violation message with Expression Language
CVE-2025-46548 unknown 1y ago Pekko Management may not properly apply authenticator when Basic Authentication is enabled
CVE-2025-45855 unknown 1y ago Erupt Unrestricted Upload of File with Dangerous Type vulnerability
CVE-2025-27038 unknown 1.5 KEV 1y ago Multiple Qualcomm chipsets contain a use-after-free vulnerability. This vulnerability allows for memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
CVE-2025-21480 unknown 1.5 KEV 1y ago Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing spe…