Search

Found 25,374 results in 1148ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-10553 unknown 1y ago H2O Deserialization of Untrusted Data Vulnerability
CVE-2024-10550 unknown 1y ago H2O Vulnerable to Denial of Service (DoS) via `/3/ParseSetup` Endpoint
CVE-2024-10549 unknown 1y ago H2O Vulnerable to Denial of Service (DoS) via `/3/Parse` Endpoint
CVE-2024-8063 unknown 1y ago Ollama Divide by Zero Vulnerability
CVE-2024-54016 unknown 1y ago Apache Seata Vulnerable to Data Amplification
CVE-2024-47552 unknown 1y ago Apache Seata Vulnerable to Deserialization of Untrusted Data
CVE-2025-22228 unknown 1y ago Spring Security Does Not Enforce Password Length
CVE-2025-2536 unknown 1y ago Liferay Portal and Liferay DXP Vulnerable to Cross-Site Scripting (XSS)
CVE-2025-29926 unknown 1y ago The WikiManager REST API allows any user to create wikis
CVE-2025-29924 unknown 1y ago XWiki uses the wrong wiki reference in AuthorizationManager
CVE-2025-30197 unknown 1y ago Jenkins Zoho QEngine Plugin Displays Unmasked API Keys
CVE-2025-30196 unknown 1y ago Jenkins AnchorChain Plugin Has a Cross-Site Scripting (XSS) Vulnerability
CVE-2025-1316 unknown 1.5 KEV 1y ago Edimax IC-7100 IP camera contains an OS command injection vulnerability due to improper input sanitization that allows an attacker to achieve remote code execution via specially crafted requests. The…
CVE-2024-48248 unknown 1.5 KEV 1y ago NAKIVO Backup and Replication contains an absolute path traversal vulnerability that enables an attacker to read arbitrary files.
CVE-2017-12637 unknown 1.5 KEV 1y ago SAP NetWeaver Application Server (AS) Java contains a directory traversal vulnerability in scheduler/ui/js/ffffffffbca41eb4/UIUtilJavaScriptJS that allows a remote attacker to read arbitrary files vi…
CVE-2025-30066 unknown 1.5 KEV 1y ago tj-actions/changed-files GitHub Action contains an embedded malicious code vulnerability that allows a remote attacker to discover secrets by reading Github Actions Workflow Logs. These secrets may i…
CVE-2025-24472 unknown 1.5 KEV 1y ago Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests.
CVE-2024-58103 unknown 1y ago Wire has Uncontrolled Recursion on Nested Groups
CVE-2025-27496 unknown 1y ago Snowflake JDBC Driver client-side encryption key in DEBUG logs
CVE-2020-36843 unknown FIX slesdebian debian 1y ago Ed25519 Signature Malleability in ed25519-java Due to Missing Scalar Range Check
CVE-2025-21590 unknown 1.5 KEV 1y ago Juniper Junos OS contains an improper isolation or compartmentalization vulnerability. This vulnerability could allows a local attacker with high privileges to inject arbitrary code.
CVE-2025-27867 unknown 1y ago Apache Felix HTTP Webconsole Plugin: XSS in HTTP Webconsole Plugin
CVE-2025-27017 unknown 1y ago Apache NiFi: Potential Insertion of MongoDB Password in Provenance Record
CVE-2025-29891 unknown 1y ago Apache Camel Message Header Injection through request parameters
CVE-2025-2240 unknown 1y ago SmallRye Fault Tolerance out-of-memory (OOM) issue
CVE-2025-1550 unknown 1.0 EXPFIX debian debian 1y ago Arbitrary Code Execution via Crafted Keras Config for Model Loading
CVE-2025-23384 low 3.7 3.7 1y ago A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2.1), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.2.1), SCALANCE M8…
CVE-2025-26633 unknown 2.5 KEVEXP 1y ago Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.
CVE-2025-24993 unknown 1.5 KEV 1y ago Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally.
CVE-2025-24991 unknown 1.5 KEV 1y ago Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally.
CVE-2025-24985 unknown 1.5 KEV 1y ago Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally.
CVE-2025-24984 unknown 1.5 KEV 1y ago Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a phys…
CVE-2025-24983 unknown 1.5 KEV 1y ago Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
CVE-2025-0604 unknown 1y ago Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak
CVE-2025-27136 unknown 1y ago LocalS3 CreateBucketConfiguration Endpoint XML External Entity (XXE) Injection
CVE-2025-2149 unknown debian debian 1y ago A vulnerability was found in PyTorch 2.6.0+cu124. It has been rated as problematic. Affected by this issue is the function nnq_Sigmoid of the component Quantized Sigmoid Module. The manipulation of t…
CVE-2025-2148 unknown debian debian 1y ago A vulnerability was found in PyTorch 2.6.0+cu124. It has been declared as critical. Affected by this vulnerability is the function torch.ops.profiler._call_end_callbacks_on_jit_fut of the component T…
CVE-2025-25181 unknown 1.5 KEV 1y ago Advantive VeraCore contains a SQL injection vulnerability in timeoutWarning.asp that allows a remote attacker to execute arbitrary SQL commands via the PmSess1 parameter.
CVE-2024-57968 unknown 1.5 KEV 1y ago Advantive VeraCore contains an unrestricted file upload vulnerability that allows a remote unauthenticated attacker to upload files to unintended folders via upload.apsx.
CVE-2024-13161 unknown 1.5 KEV 1y ago Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.
CVE-2024-13160 unknown 1.5 KEV 1y ago Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.
CVE-2024-13159 unknown 1.5 KEV 1y ago Ivanti Endpoint Manager (EPM) contains an absolute path traversal vulnerability that allows a remote unauthenticated attacker to leak sensitive information.
CVE-2025-27636 unknown 1y ago Apache Camel: Camel Message Header Injection via Improper Filtering
CVE-2025-27604 unknown 1y ago com.xwiki.confluencepro:application-confluence-migrator-pro-ui's application homepage is public
CVE-2025-27603 unknown 1y ago com.xwiki.confluencepro:application-confluence-migrator-pro-ui Remote Code Execution via unescaped translations
CVE-2025-26699 unknown FIX slesdebian debian 1y ago An issue was discovered in Django 5.1 before 5.1.7, 5.0 before 5.0.13, and 4.2 before 4.2.20. The django.utils.text.wrap() method and wordwrap template filter are subject to a potential denial-of-ser…
CVE-2025-27625 unknown 1y ago Jenkins Open Redirect vulnerability
CVE-2025-27624 unknown 1y ago Jenkins cross-site request forgery (CSRF) vulnerability
CVE-2025-27623 unknown 1y ago Jenkins reveals encrypted values of secrets stored in agent configuration to users with Agent/Extended Read permission
CVE-2025-27622 unknown 1y ago Jenkins reveals encrypted values of secrets stored in agent configuration to users with Agent/Extended Read permission
CVE-2025-4432 unknown FIX debian debian 1y ago Ring: some aes functions may panic when overflow checking is enabled in ring in github.com/briansmith/ring
CVE-2025-27508 unknown 1y ago Emissary May Use a Broken or Risky Cryptographic Algorithm
CVE-2025-27497 unknown 1y ago OpenDJ Denial of Service (DoS) using alias loop
CVE-2023-38693 unknown 1y ago Lucee RCE/XXE Vulnerability
CVE-2025-27426 unknown FIX debian debian 1y ago Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. This vulnerability was fixed in Firefox for iOS 136.
CVE-2025-1942 unknown FIX debian debian 1y ago When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability was fixed in Firefox 136 and Thunderbird…
CVE-2025-1941 unknown FIX debian debian 1y ago Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability was fixed in Firef…
CVE-2025-1940 unknown FIX debian debian 1y ago A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly. *This issue onl…
CVE-2025-22226 unknown 1.5 KEV 1y ago VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. Successful exploitation allows an attacker with administrative privileges to…
CVE-2025-22225 unknown 1.5 KEV 1y ago VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of t…
CVE-2025-22224 unknown 1.5 KEV 1y ago VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. Successful exploitation enables an attacker with local admi…
CVE-2024-55532 unknown 1y ago Apache Ranger Improper Neutralization of Formula Elements vulnerability
CVE-2024-24778 unknown 1y ago Apache StreamPipes has improper privilege management in a REST interface
CVE-2024-4885 unknown 1.5 KEV 1y ago Progress WhatsUp Gold contains a path traversal vulnerability that allows an unauthenticated attacker to achieve remote code execution.
CVE-2023-20118 unknown 1.5 KEV 1y ago Multiple Cisco Small Business RV Series Routers contains a command injection vulnerability in the web-based management interface. Successful exploitation could allow an authenticated, remote attacker…
CVE-2022-43939 unknown 2.5 KEVEXP 1y ago Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL paths for authorization decisions vulnerability that enables an attacker to bypass authorization.
CVE-2022-43769 unknown 2.5 KEVEXP 1y ago Hitachi Vantara Pentaho BA Server contains a special element injection vulnerability that allows an attacker to inject Spring templates into properties files, allowing for arbitrary command execution.
CVE-2018-8639 unknown 1.5 KEV 1y ago Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnera…
CVE-2024-2321 unknown 1y ago WSO2 incorrect authorization vulnerability
CVE-2025-1634 unknown 1y ago io.quarkus:quarkus-resteasy: Memory Leak in Quarkus RESTEasy Classic When Client Requests Timeout
CVE-2023-25574 unknown 1y ago LTI JupyterHub Authenticator does not properly validate JWT Signature
CVE-2024-49035 unknown 1.5 KEV 1y ago Microsoft Partner Center contains an improper access control vulnerability that allows an attacker to escalate privileges.
CVE-2023-34192 unknown 1.5 KEV 1y ago Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability that allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoS…
CVE-2024-20953 unknown 1.5 KEV 1y ago Oracle Agile Product Lifecycle Management (PLM) contains a deserialization vulnerability that allows a low-privileged attacker with network access via HTTP to compromise the system.
CVE-2017-3066 unknown 2.5 KEVEXP 1y ago Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution.
CVE-2025-1584 unknown 1y ago Solon Path Traversal
CVE-2025-24989 unknown 1.5 KEV 1y ago Microsoft Power Pages contains an improper access control vulnerability that allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control.
CVE-2025-24893 unknown 2.5 KEVEXP 1y ago XWiki Platform contains an eval injection vulnerability that could allow any guest to perform arbitrary remote code execution through a request to SolrSearch.
CVE-2025-23020 unknown 1y ago Kwik hash collision vulnerability
CVE-2025-0111 unknown 1.5 KEV 1y ago Palo Alto Networks PAN-OS contains an external control of file name or path vulnerability. Successful exploitation enables an authenticated attacker with network access to the management web interfac…
CVE-2024-4028 unknown 1y ago Keycloak allows cross-site scripting (XSS)
CVE-2025-0108 unknown 1.5 KEV 1y ago Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in its management web interface. This vulnerability allows an unauthenticated attacker with network access to the management …
CVE-2024-53704 unknown 1.5 KEV 1y ago SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication.
CVE-2025-1376 low 2.5 2.5 debian debian sles elfutils_project 1y ago A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipu…
CVE-2024-56180 unknown 1y ago Apache EventMesh: raft Hessian Deserialization Vulnerability allowing remote code execution
CVE-2024-52577 unknown 1y ago Apache Ignite: Possible RCE when deserializing incoming messages by the server node
CVE-2025-26791 unknown FIX slesdebian debian 1y ago DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).
CVE-2025-26511 unknown 1y ago Instaclustr Cassandra-Lucene-Index allows bypass of Cassandra RBAC
CVE-2025-1247 unknown 1y ago Quarkus REST Endpoint Request Parameter Leakage Due to Shared Instance
CVE-2024-46910 unknown 1y ago Apache Atlas: An authenticated user can perform XSS and potentially impersonate another user
CVE-2024-57727 unknown 2.5 KEVEXP 1y ago SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP r…
CVE-2025-24200 unknown 1.5 KEV 1y ago Apple iOS and iPadOS contains an incorrect authorization vulnerability that allows a physical attacker to disable USB Restricted Mode on a locked device.
CVE-2024-41710 unknown 1.5 KEV 1y ago Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, contain an argument injection vulnerability due to insufficient parameter sanitization during the boot…
CVE-2024-32037 unknown 1y ago GeoNetwork search end-point information disclosure in response headers
CVE-2024-52067 unknown 1y ago Apache NiFi: Potential Insertion of Sensitive Parameter Values in Debug Log
CVE-2025-21418 unknown 1.5 KEV 1y ago Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.
CVE-2025-21391 unknown 1.5 KEV 1y ago Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in t…
CVE-2024-40891 unknown 1.5 KEV 1y ago Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the management commands that could allow an authenticated attacker to execute OS commands via Telnet.
CVE-2024-40890 unknown 1.5 KEV 1y ago Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP re…
CVE-2025-25193 unknown FIX slesdebian debian 1y ago Denial of Service attack on windows app using Netty