Search

Found 25,382 results in 4384ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-40890 unknown 1.5 KEV 1y ago Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP re…
CVE-2025-25193 unknown FIX slesdebian debian 1y ago Denial of Service attack on windows app using Netty
CVE-2024-27859 unknown 1y ago The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing web content may lead to ar…
CVE-2025-25188 unknown FIX debian debian 1y ago Hickory DNS is a Rust based DNS client, server, and resolver. A vulnerability present starting in version 0.8.0 and prior to versions 0.24.3 and 0.25.0-alpha.5 impacts Hickory DNS users relying on DN…
CVE-2025-24970 unknown FIX slesdebian debian 1y ago SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine
CVE-2025-25247 unknown 1y ago Apache Felix Webconsole: XSS in services console
CVE-2024-57606 unknown 1y ago SQL injection in JeecgBoot
CVE-2025-0994 unknown 1.5 KEV 1y ago Trimble Cityworks contains a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer's Microsoft Internet Information Servic…
CVE-2024-45626 unknown 1y ago Apache James vulnerable to denial of service through JMAP HTML to text conversion
CVE-2024-37358 unknown 1y ago Apache James vulnerable to denial of service through the use of IMAP literals
CVE-2024-57699 unknown FIX debian debian 1y ago Netplex Json-smart Uncontrolled Recursion vulnerability
CVE-2025-0411 unknown 1.5 KEVFIX debian debian sles 1y ago 7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user.
CVE-2024-21413 unknown 1.5 KEV 1y ago Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office…
CVE-2022-23748 unknown 1.5 KEV 1y ago Dante Discovery contains a process control vulnerability in mDNSResponder.exe that all allows for a DLL sideloading attack. A local attacker can leverage this vulnerability in the Dante Application L…
CVE-2020-29574 unknown 1.5 KEV 1y ago CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.
CVE-2020-15069 unknown 1.5 KEV 1y ago Sophos XG Firewall contains a buffer overflow vulnerability that allows for remote code execution via the "HTTP/S bookmark" feature.
CVE-2024-10973 unknown 1y ago Keycloak on Quarkus CLI option for encrypted JGroups ignored
CVE-2024-36404 unknown 1y ago GeoTools Remote Code Execution (RCE) vulnerability in evaluating XPath expressions
CVE-2025-24860 unknown 1y ago Apache Cassandra: CassandraNetworkAuthorizer and CassandraCIDRAuthorizer can be bypassed allowing access to different network regions
CVE-2025-23015 unknown 1y ago Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions
CVE-2024-27137 unknown 1y ago Apache Cassandra: unrestricted deserialization of JMX authentication credentials
CVE-2025-0148 unknown 1y ago Jenkins Zoom Plugin is Missing Password Field Masking
CVE-2024-45195 unknown 1.5 KEV 1y ago Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.
CVE-2024-29059 unknown 1.5 KEV 1y ago Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution.
CVE-2018-9276 unknown 2.5 KEVEXP 1y ago Paessler PRTG Network Monitor contains an OS command injection vulnerability that allows an attacker with administrative privileges to execute commands via the PRTG System Administrator web console.
CVE-2018-19410 unknown 1.5 KEV 1y ago Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote, unauthenticated attacker to create users with read-write privileges (including administrator).
CVE-2025-24961 unknown 1y ago S3Proxy allows insecure path traversal in filesystem and filesystem-nio2 storage backends
CVE-2025-23367 unknown 1y ago WildFly improper RBAC permission
CVE-2025-23215 unknown 1y ago PMD Designer's release key passphrase (GPG) available on Maven Central in cleartext
CVE-2025-0142 unknown 1y ago Jenkins Zoom Plugin Stores Sensitive Information in Cleartext
CVE-2025-0851 unknown 1y ago Deep Java Library path traversal issue
CVE-2025-24790 unknown 1y ago Snowflake JDBC uses insecure temporary credential cache file permissions
CVE-2025-24789 unknown 1y ago Snowflake JDBC allows an untrusted search path on Windows
CVE-2025-24374 unknown FIX debian debian 1y ago Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the operator. This vulnerability is fixed in 3.19.0.
CVE-2024-57439 unknown 1y ago RuoYi vulnerable to Denial of Service by attackers with admin privileges
CVE-2024-57438 unknown 1y ago RuoYi has insecure permissions
CVE-2024-57436 unknown 1y ago RuoYi allowed unauthorized attackers to view the session ID of the admin in the system monitoring
CVE-2024-29869 unknown 1y ago Apache Hive Incorrectly Assigns Permissions for a Critical Resource
CVE-2025-24085 unknown 2.5 KEVEXP 1y ago Apple iOS, macOS, and other Apple products contain a user-after-free vulnerability that could allow a malicious application to elevate privileges.
CVE-2024-23953 unknown 1y ago Apache Hive vulnerable to Observable Timing Discrepancy and Authentication Bypass by Spoofing
CVE-2025-24130 unknown 1y ago The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to modify protected parts of the file system.
CVE-2024-54519 unknown 1y ago The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. An app may be able to read sensitive location information.
CVE-2025-24126 unknown 1y ago An input validation issue was addressed. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3. An attacker on the lo…
CVE-2024-54523 unknown 1y ago The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, watchOS 11.2. An app may be able to corrupt coprocessor memory.
CVE-2024-54542 unknown 1y ago An authentication issue was addressed with improved state management. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, watchOS 11.2. Private Browsing tabs may be acce…
CVE-2025-24106 unknown 1y ago This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to cause unexpected system termin…
CVE-2024-54539 unknown 1y ago This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to capture keyboard events from th…
CVE-2025-24146 unknown 1y ago This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. Deleting a conversation in Messages ma…
CVE-2024-54478 unknown 1y ago An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.4, macOS Sequoia 15.2, macOS Sonoma 14.7.2, tvOS 18.2, visionOS…
CVE-2025-24102 unknown 1y ago The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to determine a user’s current loc…
CVE-2024-54507 unknown 1y ago A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2. An attacker with user privileges may be able to read kernel me…
CVE-2025-24092 unknown 1y ago This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to read sensitive location information.
CVE-2025-24138 unknown 1y ago This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A malicious application may be able to leak sensitive…
CVE-2024-54550 unknown 1y ago This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2. An app may be able to view autocompleted contact inform…
CVE-2025-24118 unknown 1y ago The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to cause unexpected system termination or writ…
CVE-2025-24159 unknown 1y ago A validation issue was addressed with improved logic. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. A…
CVE-2025-24122 unknown 1y ago A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An…
CVE-2025-24163 unknown 1y ago The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sequoia 15.4, macOS Sonoma 14.7.3, tv…
CVE-2025-24123 unknown 1y ago The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.3, visionOS 2.3, w…
CVE-2025-24174 unknown 1y ago The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to bypass Privacy preferences.
CVE-2024-54530 unknown 1y ago The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, visionOS 2.2, watchOS 11.2. Password autofill may fill in passwords after failing au…
CVE-2024-54475 unknown 1y ago A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to determi…
CVE-2025-24783 unknown 1y ago Apache Cocoon vulnerable to Incorrect Usage of Seeds in Pseudo-Random Number Generator
CVE-2025-24814 unknown FIX debian debian 1y ago Apache Solr vulnerable to Execution with Unnecessary Privileges
CVE-2024-52012 unknown FIX debian debian 1y ago Apache Solr Relative Path Traversal vulnerability
CVE-2025-24363 unknown 1y ago HL7 FHIR IG Publisher potentially exposes GitHub repo user and credential information
CVE-2024-52807 unknown 1y ago XXE vulnerability in XSLT parsing in `org.hl7.fhir.publisher`
CVE-2025-23006 unknown 1.5 KEV 1y ago SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacke…
CVE-2024-53299 unknown 1y ago Apache Wicket: An attacker can intentionally trigger a memory leak
CVE-2024-56923 unknown 1y ago Cross site scripting in Silverpeas Core
CVE-2025-24403 unknown 1y ago Missing permission checks in Jenkins Azure Service Fabric Plugin
CVE-2025-24402 unknown 1y ago CSRF vulnerability in Jenkins Azure Service Fabric Plugin
CVE-2025-24401 unknown 1y ago Disabled permissions can be granted by Folder-based in Jenkins Authorization Strategy Plugin
CVE-2025-24400 unknown 1y ago Cache confusion in Jenkins Eiffel Broadcaster Plugin
CVE-2025-24399 unknown 1y ago Improper handling of case sensitivity in Jenkins OpenId Connect Authentication Plugin
CVE-2025-24398 unknown 1y ago Bitbucket Server Integration Plugin allows bypassing CSRF protection for any URL
CVE-2025-24397 unknown 1y ago Incorrect permission check in Jenkins GitLab Plugin allows enumerating credentials IDs
CVE-2024-45479 unknown 1y ago Apache Ranger UI vulnerable to Server Side Request Forgery
CVE-2024-45478 unknown 1y ago Apache Ranger has Stored Cross-site Scripting vulnerability in Edit Service Page
CVE-2025-23209 unknown 1.5 KEV 1y ago Craft CMS contains a code injection vulnerability caused by improper validation of the database backup path, ultimately enabling remote code execution.
CVE-2025-23184 unknown 1y ago Apache CXF: Denial of Service vulnerability with temporary files
CVE-2024-43709 unknown 1y ago Elasticsearch allocation of resources without limits or throttling leads to crash
CVE-2025-22620 unknown FIX debian debian 1y ago gitoxide is an implementation of git written in Rust. Prior to 0.17.0, gix-worktree-state specifies 0777 permissions when checking out executable files, intending that the umask will restrict them ap…
CVE-2024-5138 unknown FIX debian debian 1y ago The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did not properly parse …
CVE-2024-50603 unknown 1.5 KEV 1y ago Aviatrix Controllers contain an OS command injection vulnerability that could allow an unauthenticated attacker to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type fo…
CVE-2023-0482 unknown debian debian 1y ago Insecure Temporary File in RESTEasy
CVE-2024-56374 unknown FIX slesdebian debian 1y ago An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a p…
CVE-2024-45627 unknown 1y ago Apache Linkis Metadata Query Service JDBC: JDBC Datasource Module with Mysql has file read vulnerability
CVE-2025-23042 unknown 1y ago Gradio Blocked Path ACL Bypass Vulnerability
CVE-2025-23025 unknown 1y ago XWiki Realtime WYSIWYG Editor extension allows privilege escalation (PR) through realtime WYSIWYG editing
CVE-2025-21335 unknown 1.5 KEV 1y ago Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.
CVE-2025-21334 unknown 1.5 KEV 1y ago Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.
CVE-2025-21333 unknown 2.5 KEVEXP 1y ago Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges.
CVE-2024-55591 unknown 1.5 KEV 1y ago Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websoc…
CVE-2024-11734 unknown 1y ago Denial of Service in Keycloak Server via Security Headers
CVE-2024-11736 unknown 1y ago Keycloak allows unrestricted admin use of system and environment variables
CVE-2025-23026 unknown 1y ago jte's HTML templates containing Javascript template strings are subject to XSS
CVE-2024-12686 unknown 1.5 KEV 1y ago BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with existing administrative privileges to upload…
CVE-2023-48365 unknown 1.5 KEV 1y ago Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.
CVE-2024-55459 unknown debian debian 1y ago keras Path Traversal vulnerability