Search

Found 20,983 results in 1193ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-27136 unknown 2y ago Cross site scripting in Apache JSPWiki
CVE-2024-5967 unknown 2y ago Keycloak leaks configured LDAP bind credentials through the Keycloak admin console
CVE-2021-47621 unknown 2y ago ClassGraph XML External Entity Reference
CVE-2024-37899 unknown 2y ago XWiki Platform allows remote code execution from user account
CVE-2024-6162 unknown FIX debian debian 2y ago Undertow's url-encoded request path information can be broken on ajp-listener
CVE-2024-38595 unknown FIX slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: net/mlx5: Fix peer devlink set for SF representor devlink port The cited patch change register devlink flow, and neglect to refle…
CVE-2024-36543 unknown 2y ago STRIMZI incorrect access control
CVE-2024-37902 unknown 2y ago DeepJavaLibrary API absolute path traversal
CVE-2024-38460 unknown 2y ago SonarQube logs sensitive information
CVE-2024-37309 unknown 2y ago CrateDB has a Client initialized Session-Renegotiation DoS
CVE-2024-37280 unknown sles 2y ago Elasticsearch StackOverflow vulnerability
CVE-2024-34102 unknown 2.5 KEVEXP 2y ago Adobe Commerce and Magento Open Source contain an improper restriction of XML external entity reference (XXE) vulnerability that allows for remote code execution.
CVE-2024-4358 unknown 2.5 KEVEXP 2y ago Progress Telerik Report Server contains an authorization bypass by spoofing vulnerability that allows an attacker to obtain unauthorized access.
CVE-2024-32896 unknown 1.5 KEV 2y ago Android Pixel contains an unspecified vulnerability in the firmware that allows for privilege escalation.
CVE-2024-26169 unknown 1.5 KEV 2y ago Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges.
CVE-2024-1722 unknown 2y ago Keycloak Denial of Service via account lockout
CVE-2021-3754 unknown 2y ago Keycloak's improper input validation allows using email as username
CVE-2024-36265 unknown 2y ago Apache Submarine Server Core Incorrect Authorization vulnerability
CVE-2024-36263 unknown 2y ago Apache Submarine Server Core has a SQL Injection Vulnerability
CVE-2024-36264 unknown 2y ago Apache Submarine Commons Utils has a hard-coded secret
CVE-2024-4610 unknown 1.5 KEV 2y ago Arm Bifrost and Valhall GPU kernel drivers contain a use-after-free vulnerability that allows a local, non-privileged user to make improper GPU memory processing operations to gain access to already …
CVE-2024-4577 unknown 2.5 KEVEXPFIX slesdebian debian 2y ago PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823.
CVE-2024-3656 unknown 2y ago Keycloak's admin API allows low privilege users to use administrative functions
CVE-2024-35255 unknown sles 2y ago Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability
CVE-2024-35241 unknown FIX debian debian sles 2y ago Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `status`, `reinstall` and `remove` commands with packages installed from source via git containing …
CVE-2024-35242 unknown FIX debian debian sles 2y ago Composer is a dependency manager for PHP. On the 2.x branch prior to versions 2.2.24 and 2.7.7, the `composer install` command running inside a git/hg repository which has specially crafted branch na…
CVE-2024-4540 unknown 2y ago Keycloak exposes sensitive information in Pushed Authorization Requests (PAR)
CVE-2024-37568 unknown FIX slesdebian debian 2y ago lepture Authlib before 1.3.1 has algorithm confusion with asymmetric public keys. Unless an algorithm is specified in a jwt.decode call, HMAC verification is allowed with any asymmetric public key. (…
CVE-2024-36823 unknown 2y ago Weak encryption in Ninja Core
CVE-2025-51480 unknown 2y ago onnx allows Arbitrary File Overwrite in download_model_with_test_data
CVE-2024-5187 unknown FIX slesdebian debian 2y ago onnx allows Arbitrary File Overwrite in download_model_with_test_data
CVE-2024-36121 unknown 2y ago BoringSSLAEADContext in Netty Repeats Nonces
CVE-2024-36124 unknown 2y ago iq80 Snappy out-of-bounds read when uncompressing data, leading to JVM crash
CVE-2024-0336 unknown 2y ago Missing Authentication for Critical Function vulnerability in EMTA Grup PDKS allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects PDKS: from V3.04 before 20240…
CVE-2024-36042 unknown 2y ago Silverpeas authentication bypass
CVE-2017-3506 unknown 1.5 KEV 2y ago Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an OS command injection vulnerability that allows an attacker to execute arbitrary code via a specially crafted HTTP req…
CVE-2024-36114 unknown 2y ago Decompressors can crash the JVM and leak memory content in Aircompressor
CVE-2024-5520 unknown 2y ago OpenCMS Cross-Site Scripting vulnerability
CVE-2015-2309 unknown FIX debian debian 2y ago Symfony has unsafe methods in the Request class
CVE-2024-24919 unknown 2.5 KEVEXP 2y ago Check Point Quantum Security Gateways contain an unspecified information disclosure vulnerability. The vulnerability potentially allows an attacker to access information on Gateways connected to the …
CVE-2024-4978 unknown 1.5 KEV 2y ago Justice AV Solutions (JAVS) Viewer installer contains a malicious version of ffmpeg.exe, named fffmpeg.exe (SHA256: 421a4ad2615941b177b6ec4ab5e239c14e62af2ab07c6df1741e2a62223223c4). When run, this c…
CVE-2024-35219 unknown 2y ago OpenAPI Generator Online - Arbitrary File Read/Delete
CVE-2024-5274 unknown 1.5 KEVFIX debian debian 2y ago Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2024-0851 unknown 2y ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Grup Arge Energy and Control Systems Smartpower allows SQL Injection. This issue affects Smartpo…
CVE-2023-46442 unknown 2y ago Soot Infinite Loop vulnerability
CVE-2024-22588 unknown 2y ago Kwik does not discard unused encryption keys
CVE-2024-5273 unknown 2y ago Jenkins Report Info Plugin Path Traversal vulnerability
CVE-2024-5165 unknown 2y ago Eclipse Ditto vulnerable to Cross-site Scripting
CVE-2024-29392 unknown 2y ago Silverpeas Core vulnerable to Cross Site Scripting
CVE-2024-35197 unknown FIX slesdebian debian 2y ago gitoxide is a pure Rust implementation of Git. On Windows, fetching refs that clash with legacy device names reads from the devices, and checking out paths that clash with such names writes arbitrary…
CVE-2024-35186 unknown FIX slesdebian debian 2y ago gitoxide is a pure Rust implementation of Git. During checkout, `gix-worktree-state` does not verify that paths point to locations in the working tree. A specially crafted repository can, when cloned…
CVE-2024-4947 unknown 1.5 KEVFIX debian debian 2y ago Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVE-2023-43208 unknown 2.5 KEVEXP 2y ago NextGen Healthcare Mirth Connect contains a deserialization of untrusted data vulnerability that allows for unauthenticated remote code execution via a specially crafted request.
CVE-2024-4761 unknown 1.5 KEVFIX debian debian 2y ago Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
CVE-2021-40655 unknown 1.5 KEV 2y ago D-Link DIR-605 routers contain an information disclosure vulnerability that allows attackers to obtain a username and password by forging a post request to the /getcfg.php page.
CVE-2014-100005 unknown 2.5 KEVEXP 2y ago D-Link DIR-600 routers contain a cross-site request forgery (CSRF) vulnerability that allows an attacker to change router configurations by hijacking an existing administrator session.
CVE-2024-28087 unknown 2y ago Bonitasoft Runtime Community edition's contains an insecure direct object references vulnerability
CVE-2024-32888 unknown 2y ago Amazon JDBC Driver for Redshift SQL Injection via line comment generation
CVE-2024-32077 unknown 2y ago Apache Airflow: XSS vulnerability in Task Instance Log/Log Details
CVE-2024-3462 unknown 2y ago Ant Media Server does not properly authorize non-administrative API calls
CVE-2024-34365 unknown 2y ago Apache Karaf Cave: Cave SSRF and arbitrary file access
CVE-2024-30172 unknown FIX debian debian sles 2y ago Bouncy Castle crafted signature and public key can be used to trigger an infinite loop
CVE-2024-30171 unknown FIX debian debian sles 2y ago Bouncy Castle affected by timing side-channel for RSA key exchange ("The Marvin Attack")
CVE-2024-29857 unknown FIX debian debian sles 2y ago Bouncy Castle certificate parsing issues cause high CPU usage during parameter evaluation.
CVE-2024-30051 unknown 1.5 KEV 2y ago Microsoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges.
CVE-2024-30040 unknown 1.5 KEV 2y ago Microsoft Windows MSHTML Platform contains an unspecified vulnerability that allows for a security feature bypass.
CVE-2024-4671 unknown 1.5 KEVFIX debian debian 2y ago Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. …
CVE-2024-4701 unknown 2y ago Genie Path Traversal vulnerability via File Uploads
CVE-2024-26579 unknown 2y ago Apache Inlong Deserialization of Untrusted Data vulnerability
CVE-2024-34517 unknown 2y ago Neo4j Cypher component mishandles IMMUTABLE privileges
CVE-2024-33748 unknown 2y ago MS Basic Cross-site Scripting vulnerability
CVE-2024-4536 unknown 2y ago Eclipse Dataspace Components vulnerable to OAuth2 client secret disclosure
CVE-2024-34447 unknown FIX debian debian sles 2y ago Bouncy Castle Java Cryptography API vulnerable to DNS poisoning
CVE-2024-31636 unknown debian debian 2y ago LIEF obtain sensitive information via the name parameter
CVE-2024-30251 unknown FIX slesdebian debian 2y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In affected versions an attacker can send a specially crafted POST (multipart/form-data) request. When the aiohttp serv…
CVE-2023-35701 unknown 2y ago Apache Hive Code Injection vulnerability
CVE-2024-4029 unknown 2y ago Wildfly vulnerable to denial of service
CVE-2024-34148 unknown 2y ago Jenkins Subversion Partial Release Manager Plugin programmatically disables the fix for CVE-2016-3721
CVE-2024-34147 unknown 2y ago Jenkins Telegram Bot Plugin stores the Telegram Bot token in plaintext
CVE-2024-34146 unknown 2y ago Jenkins Git server Plugin does not perform a permission check
CVE-2024-34145 unknown 2y ago Jenkins Script Security Plugin sandbox bypass vulnerability
CVE-2024-34144 unknown 2y ago Jenkins Script Security Plugin has sandbox bypass vulnerability involving crafted constructor bodies
CVE-2024-32114 unknown FIX debian debian 2y ago Apache ActiveMQ's default configuration doesn't secure the API web context
CVE-2024-31573 unknown FIX debian debian 2y ago XMLUnit for Java has Insecure Defaults when Processing XSLT Stylesheets
CVE-2023-7028 unknown 2.5 KEVEXP 2y ago GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultima…
CVE-2024-29988 unknown 1.5 KEV 2y ago Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature. This vulnerability can be chained with CVE-2023-388…
CVE-2023-46565 unknown FIX slesdebian debian 2y ago Buffer Overflow vulnerability in osrg gobgp commit 419c50dfac578daa4d11256904d0dc182f1a9b22 allows a remote attacker to cause a denial of service via the handlingError function in pkg/server/fsm.go.
CVE-2024-32887 unknown FIX debian debian 2y ago Sidekiq is simple, efficient background processing for Ruby. Sidekiq is reflected XSS vulnerability. The value of substr parameter is reflected in the response without any encoding, allowing an attac…
CVE-2024-1726 unknown 2y ago Quarkus: security checks in resteasy reactive may trigger a denial of service
CVE-2024-1102 unknown 2y ago Jberet: jberet-core logging database credentials
CVE-2024-28848 unknown 2y ago OpenMetadata vulnerable to a SpEL Injection in `GET /api/v1/policies/validation/condition/<expr>` (`GHSL-2023-236`)
CVE-2024-28847 unknown 2y ago OpenMetadata vulnerable to a SpEL Injection in `PUT /api/v1/events/subscriptions` (`GHSL-2023-251`)
CVE-2024-4040 unknown 2.5 KEVEXP 2y ago CrushFTP contains an unspecified sandbox escape vulnerability that allows a remote attacker to escape the CrushFTP virtual file system (VFS).
CVE-2024-20359 unknown 1.5 KEV 2y ago Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a privilege escalation vulnerability that can allow local privilege escalation from Administrator to root.
CVE-2024-20353 unknown 1.5 KEV 2y ago Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an infinite loop vulnerability that can lead to remote denial of service condition.
CVE-2024-32875 unknown FIX debian debian 2y ago Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.125.3, title arguments in Markdown for links and images not escaped in internal render hooks. Hugo users who are im…
CVE-2024-28253 unknown 2y ago OpenMetadata vulnerable to SpEL Injection in `PUT /api/v1/policies` (`GHSL-2023-252`)
CVE-2022-38028 unknown 1.5 KEV 2y ago Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with SYSTEM-level permissions.
CVE-2024-32656 unknown 2y ago Ant Media Server vulnerable to a local privilege escalation
CVE-2024-27349 unknown 2y ago Apache HugeGraph-Server: Bypass whitelist in Auth mode