Search

Found 20,983 results in 2033ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-43044 unknown 2y ago Jenkins Remoting library arbitrary file read vulnerability
CVE-2024-42005 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. QuerySet.values() and values_list() methods on models with a JSONField are subject to SQL injection in column aliases via a c…
CVE-2024-41991 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize and urlizetrunc template filters, and the AdminURLFieldWidget widget, are subject to a potential denial-of-service…
CVE-2024-41990 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The urlize() and urlizetrunc() template filters are subject to a potential denial-of-service attack via very large inputs wit…
CVE-2024-41989 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.0 before 5.0.8 and 4.2 before 4.2.15. The floatformat template filter is subject to significant memory consumption when given a string representation of a number i…
CVE-2024-32113 unknown 2.5 KEVEXP 2y ago Apache OFBiz contains a path traversal vulnerability that could allow for remote code execution.
CVE-2023-45146 unknown 2y ago XXL-RPC Deserialization of Untrusted Data vulnerability
CVE-2023-42809 unknown 2y ago Redisson vulnerable to Deserialization of Untrusted Data
CVE-2023-28857 unknown 2y ago Apereo CAS vulnerable to credential leaks for LDAP authentication
CVE-2022-23554 unknown 2y ago Alpine allows Authentication Filter bypass
CVE-2022-23553 unknown 2y ago Alpine allows URL access filter bypass
CVE-2024-42447 unknown 2y ago Apache Airflow Providers FAB Insufficient Session Expiration vulnerability
CVE-2018-0824 unknown 2.5 KEVEXP 2y ago Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script.
CVE-2024-36116 unknown 2y ago Path traversal in Reposilite javadoc file expansion (arbitrary file creation/overwrite) (`GHSL-2024-073`)
CVE-2024-36115 unknown 2y ago Reposilite artifacts vulnerable to Stored Cross-site Scripting
CVE-2024-36268 unknown 2y ago Apache Inlong Code Injection vulnerability
CVE-2024-27182 unknown 2y ago Apache Linkis arbitrary file deletion vulnerability
CVE-2024-27181 unknown 2y ago Apache Linkis vulnerable to privilege escalation
CVE-2024-41948 unknown 2y ago biscuit-java vulnerable to public key confusion in third party block
CVE-2024-23444 unknown 2y ago Elasticsearch stores private key on disk unencrypted
CVE-2024-41947 unknown 1.0 EXP 2y ago XWiki Platform vulnerable to Cross-Site Scripting (XSS) through conflict resolution
CVE-2024-37901 unknown 2y ago XWiki Platform vulnerable to remote code execution from account via SearchSuggestConfigSheet
CVE-2024-37900 unknown 2y ago XWiki Platform vulnerable to Cross-site Scripting through attachment filename in uploader
CVE-2024-37898 unknown 2y ago XWiki Platform vulnerable to document deletion and overwrite from edit
CVE-2024-41110 unknown FIX debian debian sles 2y ago Moby is an open-source project created by Docker for software containerization. A security vulnerability has been detected in certain versions of Docker Engine, which could allow an attacker to bypas…
CVE-2023-48396 unknown 2y ago Apache SeaTunnel Web Authentication vulnerability
CVE-2024-40094 unknown 2y ago GraphQL Java does not properly consider ExecutableNormalizedFields (ENFs) as part of preventing denial of service
CVE-2024-37085 unknown 1.5 KEV 2y ago VMware ESXi contains an authentication bypass vulnerability. A malicious actor with sufficient Active Directory (AD) permissions can gain full access to an ESXi host that was previously configured to…
CVE-2024-5217 unknown 1.5 KEV 2y ago ServiceNow Washington DC, Vancouver, and earlier Now Platform releases contain an incomplete list of disallowed inputs vulnerability in the GlideExpression script. An unauthenticated user could explo…
CVE-2024-4879 unknown 2.5 KEVEXP 2y ago ServiceNow Utah, Vancouver, and Washington DC Now Platform releases contain a jelly template injection vulnerability in UI macros. An unauthenticated user could exploit this vulnerability to execute …
CVE-2023-45249 unknown 2.5 KEVEXP 2y ago Acronis Cyber Infrastructure (ACI) allows an unauthenticated user to execute commands remotely due to the use of default passwords.
CVE-2023-49921 unknown 2y ago Elasticsearch Insertion of Sensitive Information into Log File
CVE-2024-29069 unknown FIX debian debian 2y ago In snapd versions prior to 2.62, snapd failed to properly check the destination of symbolic links when extracting a snap. The snap format is a squashfs file-system image and so can contain symbolic …
CVE-2024-29068 unknown FIX debian debian 2y ago In snapd versions prior to 2.62, snapd failed to properly check the file type when extracting a snap. The snap format is a squashfs file-system image and so can contain files that are non-regular fil…
CVE-2024-1724 unknown FIX debian debian 2y ago In snapd versions prior to 2.62, when using AppArmor for enforcement of sandbox permissions, snapd failed to restrict writes to the $HOME/bin path. In Ubuntu, when this path exists, it is automatica…
CVE-2024-41667 unknown 2y ago OpenAM FreeMarker template injection
CVE-2024-37084 unknown 2y ago Remote code execution in Spring Cloud Data Flow
CVE-2024-39676 unknown 2y ago Apache Pinot: Unauthorized endpoint exposed sensitive information
CVE-2023-48362 unknown 2y ago XML External Entity Reference (XXE) in the XML Format Plugin in Apache Drill
CVE-2024-40767 unknown FIX debian debian 2y ago In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a desc…
CVE-2024-39891 unknown 1.5 KEV 2y ago Twilio Authy contains an information disclosure vulnerability in its API that allows an unauthenticated endpoint to accept a request containing a phone number and respond with information about wheth…
CVE-2012-4792 unknown 2.5 KEVEXP 2y ago Microsoft Internet Explorer contains a use-after-free vulnerability that allows a remote attacker to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not p…
CVE-2024-25638 unknown FIX debian debian 2y ago DNSJava DNSSEC Bypass
CVE-2024-38503 unknown 2y ago Apache Syncope Improper Input Validation vulnerability
CVE-2024-23321 unknown 2y ago Apache RocketMQ Vulnerable to Unauthorized Exposure of Sensitive Data
CVE-2024-6960 unknown 2y ago H2O vulnerable to Deserialization of Untrusted Data
CVE-2024-41172 unknown 2y ago Apache CXF allows unrestricted memory consumption in CXF HTTP clients
CVE-2024-32007 unknown 2y ago Apache CXF Denial of Service vulnerability in JOSE
CVE-2024-29736 unknown 2y ago Apache CXF: SSRF vulnerability via WADL stylesheet parameter
CVE-2024-40642 unknown 2y ago Absent Input Validation in BinaryHttpParser
CVE-2024-39900 unknown 2y ago The OpenSearch reporting plugin improperly controls tenancy access to reporting resources
CVE-2024-29178 unknown 2y ago Apache StreamPark: FreeMarker SSTI RCE Vulnerability
CVE-2024-40644 unknown FIX debian debian 2y ago gitoxide An idiomatic, lean, fast & safe pure Rust implementation of Git. `gix-path` can be tricked into running another `git.exe` placed in an untrusted location by a limited user account on Windows…
CVE-2024-29120 unknown 2y ago Apache StreamPark: Information leakage vulnerability
CVE-2023-7272 unknown 2y ago Eclipse Parsson stack overflow when parsing deeply nested input
CVE-2024-31411 unknown 2y ago Apache StreamPipes has potential remote code execution (RCE) via file upload
CVE-2024-31979 unknown 2y ago Apache StreamPipes has possibility of SSRF in pipeline element installation process
CVE-2024-30471 unknown 2y ago Apache StreamPipes potentially allows creation of multiple identical accounts
CVE-2024-29737 unknown 2y ago Apache StreamPark: maven build params could trigger remote command execution
CVE-2023-52291 unknown 2y ago Apache StreamPark: Unchecked maven build params could trigger remote command execution
CVE-2024-28995 unknown 2.5 KEVEXP 2y ago SolarWinds Serv-U contains a path traversal vulnerability that allows an attacker access to read sensitive files on the host machine.
CVE-2022-22948 unknown 2.5 KEVEXP 2y ago VMware vCenter Server contains an incorrect default file permissions vulnerability that allows a remote, privileged attacker to gain access to sensitive information.
CVE-2022-48833 unknown FIX slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: btrfs: skip reserved bytes warning on unmount after log cleanup failure After the recent changes made by commit c2e39305299f01 ("…
CVE-2023-49566 unknown 2y ago Apache Linkis DataSource's JDBC Datasource Module with DB2 has JNDI Injection vulnerability
CVE-2023-46801 unknown 2y ago Apache Linkis DataSource remote code execution vulnerability
CVE-2023-41916 unknown 2y ago Apache Linkis DataSource allows arbitrary file reading
CVE-2024-36522 unknown 2y ago Apache Wicket: Remote code execution via XSLT injection
CVE-2022-29946 unknown FIX debian debian 2y ago NATS.io NATS Server before 2.8.2 and Streaming Server before 0.24.6 could allow a remote attacker to bypass security restrictions, caused by the failure to enforce negative user permissions in one sc…
CVE-2024-6484 unknown 2y ago Withdrawn Advisory: Bootstrap Cross-Site Scripting (XSS) vulnerability
CVE-2024-39901 unknown 2y ago OpenSearch Observability does not properly restrict access to private tenant resources
CVE-2024-39614 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. get_supported_language_variant() was subject to a potential denial-of-service attack when used with very long strings contain…
CVE-2024-39330 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. Derived classes of the django.core.files.storage.Storage base class, when they override generate_filename() without replicati…
CVE-2024-39329 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.0 before 5.0.7 and 4.2 before 4.2.14. The django.contrib.auth.backends.ModelBackend.authenticate() method allows remote attackers to enumerate users via a timing a…
CVE-2024-38875 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 4.2 before 4.2.14 and 5.0 before 5.0.7. urlize and urlizetrunc were subject to a potential denial of service attack via certain inputs with a very large number of br…
CVE-2024-39031 unknown 2y ago Silverpeas Core Cross-site Scripting vulnerability
CVE-2024-22271 unknown 2y ago Spring Cloud Function Framework vulnerable to Denial of Service
CVE-2024-38372 unknown FIX debian debian 2y ago Undici is an HTTP/1.1 client, written from scratch for Node.js. Depending on network and process conditions of a `fetch()` request, `response.arrayBuffer()` might include portion of memory from the N…
CVE-2024-3653 unknown FIX debian debian 2y ago Undertow Missing Release of Memory after Effective Lifetime vulnerability
CVE-2024-38112 unknown 1.5 KEV 2y ago Microsoft Windows MSHTML Platform contains a spoofing vulnerability that has a high impact to confidentiality, integrity, and availability.
CVE-2024-38080 unknown 1.5 KEV 2y ago Microsoft Windows Hyper-V contains a privilege escalation vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges.
CVE-2024-23692 unknown 2.5 KEVEXP 2y ago Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability. This allows a remote, unauthenticated attacker to execute commands on the aff…
CVE-2024-5971 unknown FIX debian debian 2y ago Undertow Denial of Service vulnerability
CVE-2024-37389 unknown 2y ago Apache NiFi vulnerable to Cross-site Scripting
CVE-2024-39689 unknown FIX slesdebian debian 2y ago Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.5.30 and prior to 2024.…
CVE-2024-32498 unknown FIX debian debian 2y ago An issue was discovered in OpenStack Cinder through 24.0.0, Glance before 28.0.2, and Nova before 29.0.3. Arbitrary file access can occur via custom QCOW2 external data. By supplying a crafted QCOW2 …
CVE-2022-30636 unknown FIX debian debian 2y ago httpTokenCacheKey uses path.Base to extract the expected HTTP-01 token value to lookup in the DirCache implementation. On Windows, path.Base acts differently to filepath.Base, since Windows uses a di…
CVE-2024-20399 unknown 1.5 KEV 2y ago Cisco NX-OS contains a command injection vulnerability in the command line interface (CLI) that could allow an authenticated, local attacker to execute commands as root on the underlying operating sy…
CVE-2024-39236 unknown 2y ago Withdrawn Advisory: Gradio was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py
CVE-2024-36401 unknown 2.5 KEVEXP 2y ago OSGeo GeoServer GeoTools contains an improper neutralization of directives in dynamically evaluated code vulnerability due to unsafely evaluating property names as XPath expressions. This allows unau…
CVE-2024-24749 unknown 2y ago Classpath resource disclosure in GWC Web Resource API on Windows / Tomcat
CVE-2024-34696 unknown 2y ago GeoServer's Server Status shows sensitive environmental variables and Java properties
CVE-2024-39460 unknown 2y ago Bitbucket OAuth access token exposed in the build log by Bitbucket Branch Source Plugin
CVE-2024-39459 unknown 2y ago Secret file credentials stored unencrypted in rare cases by Plain Credentials Plugin
CVE-2024-39458 unknown 2y ago Exposure of secrets through system log in Jenkins Structs Plugin
CVE-2024-58261 unknown FIX slesdebian debian 2y ago The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupp…
CVE-2020-13965 unknown 1.5 KEVFIX debian debian 2y ago Roundcube Webmail contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to manipulate data via a malicious XML attachment.
CVE-2024-38364 unknown 2y ago DSpace Cross Site Scripting (XSS) via a deposited HTML/XML document
CVE-2024-38374 unknown 2y ago Improper Restriction of XML External Entity Reference in org.cyclonedx:cyclonedx-core-java
CVE-2024-38369 unknown 2y ago XWiki programming rights may be inherited by inclusion
CVE-2024-29868 unknown 2y ago Apache StreamPipes: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Recovery Token Generation