Search

Found 33,989 results in 1267ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-65430 unknown FIX debian debian 6mo ago django-allauth does not reject access tokens for inactive users
CVE-2025-66388 unknown 6mo ago Apache Airflow exposes secret values to authenticated UI users via rendered templates
CVE-2025-37731 unknown 6mo ago Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates
CVE-2025-14711 critical 9.8 9.8 fantasticlbp 6mo ago A flaw has been found in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This vulnerability affects unknown code of the file /controller/api/hotelList.php. This manipulatio…
CVE-2025-14710 critical 9.8 9.8 fantasticlbp 6mo ago A vulnerability was detected in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This affects an unknown part of the file /controller/api/OrderList.php. The manipulation of …
CVE-2025-14704 critical 9.8 9.8 6mo ago A vulnerability was found in Shiguangwu sgwbox N3 2.0.25. The impacted element is an unknown function of the file /eshell of the component API. The manipulation results in path traversal. It is possi…
CVE-2025-14611 unknown 2.5 KEVEXP 6mo ago Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for their implementation of the AES cryptoscheme. This vulnerability degrades security for public exposed endpoin…
CVE-2025-14674 unknown 6mo ago snail-job is vulnerable to Code Injection through QLExpressEngine.doEval function
CVE-2025-14673 critical 9.8 9.8 gmg137 6mo ago A vulnerability has been found in gmg137 snap7-rs up to 1.142.1. Affected is the function snap7_rs::client::S7Client::as_ct_write of the file /tests/snap7-rs/src/client.rs. The manipulation leads to …
CVE-2025-14672 critical 9.8 9.8 gmg137 6mo ago A flaw has been found in gmg137 snap7-rs up to 1.142.1. This impacts the function TSnap7MicroClient::opWriteArea of the file s7_micro_client.cpp. Executing a manipulation can lead to heap-based buffe…
CVE-2025-14668 critical 9.8 9.8 campcodes 6mo ago A vulnerability was detected in campcodes Advanced Online Examination System 1.0. This affects an unknown function of the file /query/loginExe.php. Performing a manipulation of the argument Username …
CVE-2025-14667 critical 9.8 9.8 angeljudesuarez 6mo ago A security vulnerability has been detected in itsourcecode COVID Tracking System 1.0. The impacted element is an unknown function of the file /admin/?page=system_info. Such manipulation of the argume…
CVE-2025-14666 critical 9.8 9.8 angeljudesuarez 6mo ago A weakness has been identified in itsourcecode COVID Tracking System 1.0. The affected element is an unknown function of the file /admin/?page=user. This manipulation of the argument Username causes …
CVE-2025-14664 critical 9.8 9.8 campcodes 6mo ago A vulnerability was identified in Campcodes Supplier Management System 1.0. This issue affects some unknown processing of the file /admin/view_unit.php. The manipulation of the argument chkId[] leads…
CVE-2025-14661 critical 9.8 9.8 angeljudesuarez 6mo ago A vulnerability has been found in itsourcecode Student Managemen System 1.0. Affected by this issue is some unknown functionality of the file /advisers.php. Such manipulation of the argument sy leads…
CVE-2025-14653 critical 9.8 9.8 angeljudesuarez 6mo ago A vulnerability was determined in itsourcecode Student Management System 1.0. Impacted is an unknown function of the file /addrecord.php. This manipulation of the argument ID causes sql injection. Re…
CVE-2025-14652 critical 9.8 9.8 admerc 6mo ago A vulnerability was found in itsourcecode Online Cake Ordering System 1.0. This issue affects some unknown processing of the file /admindetail.php?action=edit. The manipulation of the argument ID res…
CVE-2025-14650 critical 9.8 9.8 admerc 6mo ago A flaw has been found in itsourcecode Online Cake Ordering System 1.0. This affects an unknown part of the file /cakeshop/product.php. Executing manipulation of the argument Product can lead to sql i…
CVE-2025-14649 critical 9.8 9.8 admerc 6mo ago A vulnerability was detected in itsourcecode Online Cake Ordering System 1.0. Affected by this issue is some unknown functionality of the file /cakeshop/supplier.php. Performing manipulation of the a…
CVE-2025-14647 critical 9.8 9.8 carmelo 6mo ago A weakness has been identified in code-projects Computer Book Store 1.0. Affected is an unknown function of the file /admin_delete.php. This manipulation of the argument bookisbn causes sql injection…
CVE-2025-14646 critical 9.8 9.8 fabian 6mo ago A security flaw has been discovered in code-projects Student File Management System 1.0. This impacts an unknown function of the file /admin/delete_student.php. The manipulation of the argument stud_…
CVE-2025-14645 critical 9.8 9.8 fabian 6mo ago A vulnerability was identified in code-projects Student File Management System 1.0. This affects an unknown function of the file /admin/delete_user.php. The manipulation of the argument user_id leads…
CVE-2025-14644 critical 9.8 9.8 angeljudesuarez 6mo ago A vulnerability was determined in itsourcecode Student Management System 1.0. The impacted element is an unknown function of the file /update_subject.php. Executing manipulation of the argument ID ca…
CVE-2025-14643 critical 9.8 9.8 fabian 6mo ago A vulnerability was found in code-projects Simple Attendance Record System 2.0. The affected element is an unknown function of the file /check.php. Performing manipulation of the argument student res…
CVE-2025-14640 critical 9.8 9.8 fabian 6mo ago A flaw has been found in code-projects Student File Management System 1.0. The affected element is an unknown function of the file /admin/save_student.php. Executing manipulation of the argument stud…
CVE-2025-14639 critical 9.8 9.8 angeljudesuarez 6mo ago A vulnerability was detected in itsourcecode Student Management System 1.0. Impacted is an unknown function of the file /uprec.php. Performing manipulation of the argument ID results in sql injection…
CVE-2025-14638 critical 9.8 9.8 facebook-riares 6mo ago A security vulnerability has been detected in itsourcecode Online Pet Shop Management System 1.0. This issue affects some unknown processing of the file /pet1/update_cnp.php. Such manipulation of the…
CVE-2025-14637 critical 9.8 9.8 facebook-riares 6mo ago A weakness has been identified in itsourcecode Online Pet Shop Management System 1.0. This vulnerability affects unknown code of the file /pet1/addcnp.php. This manipulation of the argument cnpname c…
CVE-2025-14623 critical 9.8 9.8 fabian 6mo ago A weakness has been identified in code-projects Student File Management System 1.0. This issue affects some unknown processing of the file /admin/update_student.php. This manipulation of the argument…
CVE-2025-14622 critical 9.8 9.8 fabian 6mo ago A security flaw has been discovered in code-projects Student File Management System 1.0. This vulnerability affects unknown code of the file /admin/save_user.php. The manipulation of the argument fir…
CVE-2025-14621 critical 9.8 9.8 fabian 6mo ago A vulnerability was identified in code-projects Student File Management System 1.0. This affects an unknown part of the file /admin/update_user.php. The manipulation of the argument user_id leads to …
CVE-2025-14620 critical 9.8 9.8 fabian 6mo ago A vulnerability was determined in code-projects Student File Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/login_query.php. Executing manipulation of …
CVE-2025-14619 critical 9.8 9.8 fabian 6mo ago A vulnerability was found in code-projects Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file login_query.php. Performing manipulation of the a…
CVE-2025-14590 critical 9.8 9.8 carmelo 6mo ago A security vulnerability has been detected in code-projects Prison Management System 2.0. Impacted is an unknown function of the file /admin/search1.php. The manipulation of the argument keyname lead…
CVE-2025-14588 critical 9.8 9.8 angeljudesuarez 6mo ago A security flaw has been discovered in itsourcecode Student Management System 1.0. This vulnerability affects unknown code of the file /update_program.php. Performing manipulation of the argument ID …
CVE-2025-14587 critical 9.8 9.8 facebook-riares 6mo ago A vulnerability was identified in itsourcecode Online Pet Shop Management System 1.0. This affects an unknown part of the file /pet1/available.php. Such manipulation of the argument Name leads to sql…
CVE-2025-14586 critical 9.8 9.8 6mo ago A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224. Affected by this issue is the function snprintf of the file /cgi-bin/cstecgi.cgi?action=exportOvpn&type=user. This manipulati…
CVE-2025-14585 critical 9.8 9.8 angeljudesuarez 6mo ago A vulnerability was found in itsourcecode COVID Tracking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/?page=zone. The manipulation of the argument ID resu…
CVE-2025-14584 critical 9.8 9.8 angeljudesuarez 6mo ago A vulnerability has been found in itsourcecode COVID Tracking System 1.0. Affected is an unknown function of the file /admin/login.php of the component Admin Login. The manipulation of the argument U…
CVE-2025-14583 critical 9.8 9.8 campcodes 6mo ago A flaw has been found in campcodes Online Student Enrollment System 1.0. This impacts an unknown function of the file /admin/register.php. Executing a manipulation of the argument photo can lead to u…
CVE-2025-67721 unknown 6mo ago aircompressor Snappy and LZ4 Java-based decompressor implementation can leak information from reused output buffer
CVE-2025-3586 unknown 6mo ago Liferay Portal and DXP Instance Admin can execute code using Objects Actions and Validations
CVE-2025-14578 critical 9.8 9.8 angeljudesuarez 6mo ago A weakness has been identified in itsourcecode Student Management System 1.0. The affected element is an unknown function of the file /update_account.php. This manipulation of the argument ID causes …
CVE-2025-14571 critical 9.8 9.8 projectworlds 6mo ago A vulnerability has been found in projectworlds Advanced Library Management System 1.0. Affected by this issue is some unknown functionality of the file /borrow_book.php. Such manipulation of the arg…
CVE-2025-14570 critical 9.8 9.8 projectworlds 6mo ago A flaw has been found in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_admin.php. This manipulation of the argumen…
CVE-2025-53960 unknown 6mo ago Apache StreamPark: Use the user’s password as the secret key Vulnerability
CVE-2025-40345 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: usb: storage: sddr55: Reject out-of-bound new_pba Discovered by Atuin - Automated Vulnerability Discovery Engine. new_pba comes …
CVE-2025-14566 critical 9.8 9.8 kidaze 6mo ago A security flaw has been discovered in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The impacted element is an unknown function of the file /Profilers/SProfile/reg.php…
CVE-2025-14565 critical 9.8 9.8 kidaze 6mo ago A vulnerability was identified in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The affected element is an unknown function of the file /Profilers/SProfile/login1.php. …
CVE-2025-54981 unknown 6mo ago Apache StreamPark uses a Weak Encryption Algorithm
CVE-2025-54947 unknown 6mo ago Apache StreamPark has a hard-coded encryption key
CVE-2025-26866 unknown 6mo ago Apache HugeGraph-Server: RAFT and deserialization vulnerability
CVE-2018-4063 unknown 1.5 KEV 6mo ago Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted HTTP request can upload a file, resulting in executable code being uploade…
CVE-2025-14537 critical 9.8 9.8 fabian 6mo ago A weakness has been identified in code-projects Class and Exam Timetable Management 1.0. Affected by this issue is some unknown functionality of the file /preview7.php. This manipulation of the argum…
CVE-2025-14536 critical 9.8 9.8 fabian 6mo ago A security flaw has been discovered in code-projects Class and Exam Timetable Management 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login.…
CVE-2025-14529 critical 9.8 9.8 campcodes 6mo ago A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The affected element is an unknown function of the file /admin/admin_running.php. This manipulation of the argument pid cau…
CVE-2025-14527 critical 9.8 9.8 projectworlds 6mo ago A weakness has been identified in projectworlds Advanced Library Management System 1.0. This vulnerability affects unknown code of the file /view_book.php. Executing a manipulation of the argument bo…
CVE-2025-14522 critical 9.8 9.8 baowzh 6mo ago A vulnerability was detected in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. The impacted element is an unknown function of the file /Public/Kindeditor/php/upload_json.php. Performing …
CVE-2025-14520 critical 9.1 9.1 baowzh 6mo ago A weakness has been identified in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. Impacted is an unknown function of the file /admin/index.php/datafile/delfile. This manipulation of the a…
CVE-2025-14518 critical 9.8 9.8 powerjob 6mo ago PowerJob has a server-side request forgery vulnerability in PingPongUtils.java
CVE-2025-14515 critical 9.8 9.8 campcodes 6mo ago A vulnerability has been found in Campcodes Supplier Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add_unit.php. Such manipulation of the argume…
CVE-2025-14514 critical 9.8 9.8 campcodes 6mo ago A flaw has been found in Campcodes Supplier Management System 1.0. Affected is an unknown function of the file /admin/add_distributor.php. This manipulation of the argument txtDistributorAddress caus…
CVE-2025-67505 unknown 6mo ago Race condition in the Okta Java SDK
CVE-2025-66033 unknown 6mo ago Improper Memory Cleanup in the Okta Java SDK
CVE-2025-67643 unknown 6mo ago Jenkins Redpen - Pipeline Reporter for Jira Plugin has a path traversal vulnerability
CVE-2025-67642 unknown 6mo ago Jenkins HashiCorp Vault Plugin exposes system-scoped Vault credentials
CVE-2025-67641 unknown 6mo ago Jenkins Coverage Plugin has a stored cross-site scripting (XSS) vulnerability
CVE-2025-67640 unknown 6mo ago Jenkins Git client Plugin has an OS command injection vulnerability on agents in Git client Plugin
CVE-2025-67639 unknown 6mo ago Jenkins has a CSRF vulnerability on the login form
CVE-2025-67638 unknown 6mo ago Jenkins's build authorization token is stored and displayed in plain text
CVE-2025-67637 unknown 6mo ago Jenkins's build authorization token is stored and displayed in plain text
CVE-2025-67636 unknown 6mo ago Jenkins is missing a permission check on password fields
CVE-2025-67635 unknown 6mo ago Jenkins has a Denial of service vulnerability in HTTP-based CLI
CVE-2025-67713 unknown FIX debian debian 6mo ago Miniflux 2 is an open source feed reader. Versions 2.2.14 and below treat redirect_url as safe when url.Parse(...).IsAbs() is false, enabling phishing flows after login. Protocol-relative URLs like /…
CVE-2025-66628 unknown FIX debian debian sles 6mo ago ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser contains a critical integer overflow vulnerability in…
CVE-2025-66474 unknown 6mo ago XWiki vulnerable to remote code execution through insufficient protection against {{/html}} injection
CVE-2025-66473 unknown 6mo ago XWiki's REST APIs don't enforce any limits, leading to unavailability and OOM in large wikis
CVE-2025-66472 unknown 6mo ago XWiki vulnerable to a reflected XSS via xredirect parameter in DeleteApplication
CVE-2025-8110 unknown 1.5 KEV 6mo ago Gogs contains a path traversal vulnerability affecting improper Symbolic link handling in the PutContents API that could allow for code execution.
CVE-2025-66675 unknown 6mo ago Apache Struts has a Denial of Service vulnerability
CVE-2025-14082 unknown 6mo ago Keycloak Admin REST (Representational State Transfer) API does not properly enforce permissions
CVE-2025-13955 unknown 6mo ago Predictable default Wi-Fi Password in Access Point functionality in EZCast Pro II before version 1.17478.177 allows attackers in Wi-Fi range to gain access to the dongle by calculating the default pa…
CVE-2025-13954 unknown 6mo ago Hard-coded cryptographic keys in Admin UI of EZCast Pro II before version 1.17478.177 allows attackers to bypass authorization checks and gain full access to the admin UI
CVE-2025-14337 critical 9.8 9.8 angeljudesuarez 6mo ago A vulnerability was determined in itsourcecode Student Management System 1.0. This affects an unknown part of the file /new_grade.php. This manipulation of the argument grade causes sql injection. Th…
CVE-2025-14336 critical 9.8 9.8 angeljudesuarez 6mo ago A vulnerability was found in itsourcecode Student Management System 1.0. Affected by this issue is some unknown functionality of the file /promote.php. The manipulation of the argument sy results in …
CVE-2025-14335 critical 9.8 9.8 angeljudesuarez 6mo ago A vulnerability has been found in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /new_school_year.php. The manipulation of the argu…
CVE-2025-14334 critical 9.8 9.8 angeljudesuarez 6mo ago A flaw has been found in itsourcecode Student Management System 1.0. Affected is an unknown function of the file /new_adviser.php. Executing manipulation of the argument Name can lead to sql injectio…
CVE-2025-14307 unknown debian debian 6mo ago An insecure temporary file creation vulnerability exists in the AutoExtract component of Robocode version 1.9.3.6. The createTempFile method fails to securely create temporary files, allowing attacke…
CVE-2025-14306 unknown debian debian 6mo ago A directory traversal vulnerability exists in the CacheCleaner component of Robocode version 1.9.3.6. The recursivelyDelete method fails to properly sanitize file paths, allowing attackers to travers…
CVE-2025-12504 critical 9.8 9.8 6mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talent Software UNIS allows SQL Injection. This issue affects UNIS: before 42321.
CVE-2025-11022 critical 9.6 9.6 6mo ago Cross-Site Request Forgery (CSRF) vulnerability in Personal Project Panilux allows Cross Site Request Forgery.  This CSRF vulnerability resulting in Command Injection has been identified. Thi…
CVE-2025-14285 critical 9.8 9.8 code-projects 6mo ago A vulnerability was found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of the file edit_personnel.php. The manipulation of the argument per_id results in s…
CVE-2025-62221 unknown 1.5 KEV 6mo ago Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally.
CVE-2025-6218 unknown 1.5 KEVFIX debian debian 6mo ago RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user.
CVE-2025-14258 critical 9.8 9.8 angeljudesuarez 6mo ago A vulnerability has been found in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /newsubject.php. The manipulation of the argument …
CVE-2025-14257 critical 9.8 9.8 angeljudesuarez 6mo ago A flaw has been found in itsourcecode Student Management System 1.0. Affected is an unknown function of the file /newrecord.php. Executing manipulation of the argument ID can lead to sql injection. T…
CVE-2025-14256 critical 9.8 9.8 angeljudesuarez 6mo ago A vulnerability was detected in itsourcecode Student Management System 1.0. This impacts an unknown function of the file /newcurriculm.php. Performing manipulation of the argument ID results in sql i…
CVE-2025-14251 critical 9.8 9.8 fabian 6mo ago A security vulnerability has been detected in code-projects Online Ordering System 1.0. This affects an unknown function of the file /admin/ of the component Admin Login. Such manipulation of the arg…
CVE-2025-14250 critical 9.8 9.8 fabian 6mo ago A weakness has been identified in code-projects Online Ordering System 1.0. The impacted element is an unknown function of the file /user_contact.php. This manipulation of the argument Name causes sq…
CVE-2025-14249 critical 9.8 9.8 fabian 6mo ago A security flaw has been discovered in code-projects Online Ordering System 1.0. The affected element is an unknown function of the file /user_school.php. The manipulation of the argument product_id …