Search

Found 21,050 results in 2464ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-27624 unknown 1y ago Jenkins cross-site request forgery (CSRF) vulnerability
CVE-2025-27623 unknown 1y ago Jenkins reveals encrypted values of secrets stored in agent configuration to users with Agent/Extended Read permission
CVE-2025-27622 unknown 1y ago Jenkins reveals encrypted values of secrets stored in agent configuration to users with Agent/Extended Read permission
CVE-2025-4432 unknown FIX debian debian 1y ago Ring: some aes functions may panic when overflow checking is enabled in ring in github.com/briansmith/ring
CVE-2025-27508 unknown 1y ago Emissary May Use a Broken or Risky Cryptographic Algorithm
CVE-2025-27497 unknown 1y ago OpenDJ Denial of Service (DoS) using alias loop
CVE-2023-38693 unknown 1y ago Lucee RCE/XXE Vulnerability
CVE-2025-27426 unknown FIX debian debian 1y ago Malicious websites utilizing a server-side redirect to an internal error page could result in a spoofed website URL. This vulnerability was fixed in Firefox for iOS 136.
CVE-2025-1942 unknown FIX debian debian 1y ago When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into the result string. This vulnerability was fixed in Firefox 136 and Thunderbird…
CVE-2025-1941 unknown FIX debian debian 1y ago Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability was fixed in Firef…
CVE-2025-1940 unknown FIX debian debian 1y ago A select option could partially obscure the confirmation prompt shown before launching external apps. This could be used to trick a user in to launching an external app unexpectedly. *This issue onl…
CVE-2025-22226 unknown 1.5 KEV 1y ago VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. Successful exploitation allows an attacker with administrative privileges to…
CVE-2025-22225 unknown 1.5 KEV 1y ago VMware ESXi contains an arbitrary write vulnerability. Successful exploitation allows an attacker with privileges within the VMX process to trigger an arbitrary kernel write leading to an escape of t…
CVE-2025-22224 unknown 1.5 KEV 1y ago VMware ESXi and Workstation contain a time-of-check time-of-use (TOCTOU) race condition vulnerability that leads to an out-of-bounds write. Successful exploitation enables an attacker with local admi…
CVE-2024-55532 unknown 1y ago Apache Ranger Improper Neutralization of Formula Elements vulnerability
CVE-2024-24778 unknown 1y ago Apache StreamPipes has improper privilege management in a REST interface
CVE-2024-4885 unknown 1.5 KEV 1y ago Progress WhatsUp Gold contains a path traversal vulnerability that allows an unauthenticated attacker to achieve remote code execution.
CVE-2023-20118 unknown 1.5 KEV 1y ago Multiple Cisco Small Business RV Series Routers contains a command injection vulnerability in the web-based management interface. Successful exploitation could allow an authenticated, remote attacker…
CVE-2022-43939 unknown 2.5 KEVEXP 1y ago Hitachi Vantara Pentaho BA Server contains a use of non-canonical URL paths for authorization decisions vulnerability that enables an attacker to bypass authorization.
CVE-2022-43769 unknown 2.5 KEVEXP 1y ago Hitachi Vantara Pentaho BA Server contains a special element injection vulnerability that allows an attacker to inject Spring templates into properties files, allowing for arbitrary command execution.
CVE-2018-8639 unknown 1.5 KEV 1y ago Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnera…
CVE-2024-2321 unknown 1y ago WSO2 incorrect authorization vulnerability
CVE-2025-1634 unknown 1y ago io.quarkus:quarkus-resteasy: Memory Leak in Quarkus RESTEasy Classic When Client Requests Timeout
CVE-2023-25574 unknown 1y ago LTI JupyterHub Authenticator does not properly validate JWT Signature
CVE-2024-49035 unknown 1.5 KEV 1y ago Microsoft Partner Center contains an improper access control vulnerability that allows an attacker to escalate privileges.
CVE-2023-34192 unknown 1.5 KEV 1y ago Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability that allows a remote authenticated attacker to execute arbitrary code via a crafted script to the /h/autoS…
CVE-2024-20953 unknown 1.5 KEV 1y ago Oracle Agile Product Lifecycle Management (PLM) contains a deserialization vulnerability that allows a low-privileged attacker with network access via HTTP to compromise the system.
CVE-2017-3066 unknown 2.5 KEVEXP 1y ago Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution.
CVE-2025-1584 unknown 1y ago Solon Path Traversal
CVE-2025-24989 unknown 1.5 KEV 1y ago Microsoft Power Pages contains an improper access control vulnerability that allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control.
CVE-2025-24893 unknown 2.5 KEVEXP 1y ago XWiki Platform contains an eval injection vulnerability that could allow any guest to perform arbitrary remote code execution through a request to SolrSearch.
CVE-2025-23020 unknown 1y ago Kwik hash collision vulnerability
CVE-2025-0111 unknown 1.5 KEV 1y ago Palo Alto Networks PAN-OS contains an external control of file name or path vulnerability. Successful exploitation enables an authenticated attacker with network access to the management web interfac…
CVE-2024-4028 unknown 1y ago Keycloak allows cross-site scripting (XSS)
CVE-2025-0108 unknown 1.5 KEV 1y ago Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in its management web interface. This vulnerability allows an unauthenticated attacker with network access to the management …
CVE-2024-53704 unknown 1.5 KEV 1y ago SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication.
CVE-2024-56180 unknown 1y ago Apache EventMesh: raft Hessian Deserialization Vulnerability allowing remote code execution
CVE-2024-52577 unknown 1y ago Apache Ignite: Possible RCE when deserializing incoming messages by the server node
CVE-2025-26791 unknown FIX slesdebian debian 1y ago DOMPurify before 3.2.4 has an incorrect template literal regular expression, sometimes leading to mutation cross-site scripting (mXSS).
CVE-2025-26511 unknown 1y ago Instaclustr Cassandra-Lucene-Index allows bypass of Cassandra RBAC
CVE-2025-1247 unknown 1y ago Quarkus REST Endpoint Request Parameter Leakage Due to Shared Instance
CVE-2024-46910 unknown 1y ago Apache Atlas: An authenticated user can perform XSS and potentially impersonate another user
CVE-2024-57727 unknown 2.5 KEVEXP 1y ago SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP r…
CVE-2025-24200 unknown 1.5 KEV 1y ago Apple iOS and iPadOS contains an incorrect authorization vulnerability that allows a physical attacker to disable USB Restricted Mode on a locked device.
CVE-2024-41710 unknown 1.5 KEV 1y ago Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones, including the 6970 Conference Unit, contain an argument injection vulnerability due to insufficient parameter sanitization during the boot…
CVE-2024-32037 unknown 1y ago GeoNetwork search end-point information disclosure in response headers
CVE-2024-52067 unknown 1y ago Apache NiFi: Potential Insertion of Sensitive Parameter Values in Debug Log
CVE-2025-21418 unknown 1.5 KEV 1y ago Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.
CVE-2025-21391 unknown 1.5 KEV 1y ago Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in t…
CVE-2024-40891 unknown 1.5 KEV 1y ago Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the management commands that could allow an authenticated attacker to execute OS commands via Telnet.
CVE-2024-40890 unknown 1.5 KEV 1y ago Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP re…
CVE-2025-25193 unknown FIX slesdebian debian 1y ago Denial of Service attack on windows app using Netty
CVE-2024-27859 unknown 1y ago The issue was addressed with improved memory handling. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing web content may lead to ar…
CVE-2025-25188 unknown FIX debian debian 1y ago Hickory DNS is a Rust based DNS client, server, and resolver. A vulnerability present starting in version 0.8.0 and prior to versions 0.24.3 and 0.25.0-alpha.5 impacts Hickory DNS users relying on DN…
CVE-2025-24970 unknown FIX slesdebian debian 1y ago SslHandler doesn't correctly validate packets which can lead to native crash when using native SSLEngine
CVE-2025-25247 unknown 1y ago Apache Felix Webconsole: XSS in services console
CVE-2024-57606 unknown 1y ago SQL injection in JeecgBoot
CVE-2025-0994 unknown 1.5 KEV 1y ago Trimble Cityworks contains a deserialization vulnerability. This could allow an authenticated user to perform a remote code execution attack against a customer's Microsoft Internet Information Servic…
CVE-2024-45626 unknown 1y ago Apache James vulnerable to denial of service through JMAP HTML to text conversion
CVE-2024-37358 unknown 1y ago Apache James vulnerable to denial of service through the use of IMAP literals
CVE-2024-57699 unknown FIX debian debian 1y ago Netplex Json-smart Uncontrolled Recursion vulnerability
CVE-2025-0411 unknown 1.5 KEVFIX debian debian sles 1y ago 7-Zip contains a protection mechanism failure vulnerability that allows remote attackers to bypass the Mark-of-the-Web security feature to execute arbitrary code in the context of the current user.
CVE-2024-21413 unknown 1.5 KEV 1y ago Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office…
CVE-2022-23748 unknown 1.5 KEV 1y ago Dante Discovery contains a process control vulnerability in mDNSResponder.exe that all allows for a DLL sideloading attack. A local attacker can leverage this vulnerability in the Dante Application L…
CVE-2020-29574 unknown 1.5 KEV 1y ago CyberoamOS (CROS) contains a SQL injection vulnerability in the WebAdmin that allows an unauthenticated attacker to execute arbitrary SQL statements remotely.
CVE-2020-15069 unknown 1.5 KEV 1y ago Sophos XG Firewall contains a buffer overflow vulnerability that allows for remote code execution via the "HTTP/S bookmark" feature.
CVE-2024-10973 unknown 1y ago Keycloak on Quarkus CLI option for encrypted JGroups ignored
CVE-2024-36404 unknown 1y ago GeoTools Remote Code Execution (RCE) vulnerability in evaluating XPath expressions
CVE-2025-24860 unknown 1y ago Apache Cassandra: CassandraNetworkAuthorizer and CassandraCIDRAuthorizer can be bypassed allowing access to different network regions
CVE-2025-23015 unknown 1y ago Apache Cassandra: User with MODIFY permission on ALL KEYSPACES can escalate privileges to superuser via unsafe actions
CVE-2024-27137 unknown 1y ago Apache Cassandra: unrestricted deserialization of JMX authentication credentials
CVE-2025-0148 unknown 1y ago Jenkins Zoom Plugin is Missing Password Field Masking
CVE-2024-45195 unknown 1.5 KEV 1y ago Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.
CVE-2024-29059 unknown 1.5 KEV 1y ago Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution.
CVE-2018-9276 unknown 2.5 KEVEXP 1y ago Paessler PRTG Network Monitor contains an OS command injection vulnerability that allows an attacker with administrative privileges to execute commands via the PRTG System Administrator web console.
CVE-2018-19410 unknown 1.5 KEV 1y ago Paessler PRTG Network Monitor contains a local file inclusion vulnerability that allows a remote, unauthenticated attacker to create users with read-write privileges (including administrator).
CVE-2025-24961 unknown 1y ago S3Proxy allows insecure path traversal in filesystem and filesystem-nio2 storage backends
CVE-2025-23367 unknown 1y ago WildFly improper RBAC permission
CVE-2025-23215 unknown 1y ago PMD Designer's release key passphrase (GPG) available on Maven Central in cleartext
CVE-2025-0142 unknown 1y ago Jenkins Zoom Plugin Stores Sensitive Information in Cleartext
CVE-2025-0851 unknown 1y ago Deep Java Library path traversal issue
CVE-2025-24790 unknown 1y ago Snowflake JDBC uses insecure temporary credential cache file permissions
CVE-2025-24789 unknown 1y ago Snowflake JDBC allows an untrusted search path on Windows
CVE-2025-24374 unknown FIX debian debian 1y ago Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the operator. This vulnerability is fixed in 3.19.0.
CVE-2024-57439 unknown 1y ago RuoYi vulnerable to Denial of Service by attackers with admin privileges
CVE-2024-57438 unknown 1y ago RuoYi has insecure permissions
CVE-2024-57436 unknown 1y ago RuoYi allowed unauthorized attackers to view the session ID of the admin in the system monitoring
CVE-2024-29869 unknown 1y ago Apache Hive Incorrectly Assigns Permissions for a Critical Resource
CVE-2025-24085 unknown 2.5 KEVEXP 1y ago Apple iOS, macOS, and other Apple products contain a user-after-free vulnerability that could allow a malicious application to elevate privileges.
CVE-2024-23953 unknown 1y ago Apache Hive vulnerable to Observable Timing Discrepancy and Authentication Bypass by Spoofing
CVE-2025-24130 unknown 1y ago The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to modify protected parts of the file system.
CVE-2024-54519 unknown 1y ago The issue was resolved by sanitizing logging. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. An app may be able to read sensitive location information.
CVE-2025-24126 unknown 1y ago An input validation issue was addressed. This issue is fixed in iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.3, visionOS 2.3. An attacker on the lo…
CVE-2024-54523 unknown 1y ago The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, tvOS 18.2, watchOS 11.2. An app may be able to corrupt coprocessor memory.
CVE-2024-54542 unknown 1y ago An authentication issue was addressed with improved state management. This issue is fixed in Safari 18.2, iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, watchOS 11.2. Private Browsing tabs may be acce…
CVE-2025-24106 unknown 1y ago This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to cause unexpected system termin…
CVE-2024-54539 unknown 1y ago This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to capture keyboard events from th…
CVE-2025-24146 unknown 1y ago This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. Deleting a conversation in Messages ma…
CVE-2024-54478 unknown 1y ago An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.4, macOS Sequoia 15.2, macOS Sonoma 14.7.2, tvOS 18.2, visionOS…
CVE-2025-24102 unknown 1y ago The issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to determine a user’s current loc…