Search

Found 21,050 results in 3027ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-54507 unknown 1y ago A type confusion issue was addressed with improved memory handling. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2. An attacker with user privileges may be able to read kernel me…
CVE-2025-24092 unknown 1y ago This issue was addressed with improved data protection. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to read sensitive location information.
CVE-2025-24138 unknown 1y ago This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. A malicious application may be able to leak sensitive…
CVE-2024-54550 unknown 1y ago This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2. An app may be able to view autocompleted contact inform…
CVE-2025-24118 unknown 1y ago The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3. An app may be able to cause unexpected system termination or writ…
CVE-2025-24159 unknown 1y ago A validation issue was addressed with improved logic. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. A…
CVE-2025-24122 unknown 1y ago A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An…
CVE-2025-24163 unknown 1y ago The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sequoia 15.4, macOS Sonoma 14.7.3, tv…
CVE-2025-24123 unknown 1y ago The issue was addressed with improved checks. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3, tvOS 18.3, visionOS 2.3, w…
CVE-2025-24174 unknown 1y ago The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13.7.3. An app may be able to bypass Privacy preferences.
CVE-2024-54530 unknown 1y ago The issue was addressed with improved checks. This issue is fixed in iOS 18.2 and iPadOS 18.2, macOS Sequoia 15.2, visionOS 2.2, watchOS 11.2. Password autofill may fill in passwords after failing au…
CVE-2024-54475 unknown 1y ago A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app may be able to determi…
CVE-2025-24783 unknown 1y ago Apache Cocoon vulnerable to Incorrect Usage of Seeds in Pseudo-Random Number Generator
CVE-2025-24814 unknown FIX debian debian 1y ago Apache Solr vulnerable to Execution with Unnecessary Privileges
CVE-2024-52012 unknown FIX debian debian 1y ago Apache Solr Relative Path Traversal vulnerability
CVE-2025-24363 unknown 1y ago HL7 FHIR IG Publisher potentially exposes GitHub repo user and credential information
CVE-2024-52807 unknown 1y ago XXE vulnerability in XSLT parsing in `org.hl7.fhir.publisher`
CVE-2025-23006 unknown 1.5 KEV 1y ago SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacke…
CVE-2024-53299 unknown 1y ago Apache Wicket: An attacker can intentionally trigger a memory leak
CVE-2024-56923 unknown 1y ago Cross site scripting in Silverpeas Core
CVE-2025-24403 unknown 1y ago Missing permission checks in Jenkins Azure Service Fabric Plugin
CVE-2025-24402 unknown 1y ago CSRF vulnerability in Jenkins Azure Service Fabric Plugin
CVE-2025-24401 unknown 1y ago Disabled permissions can be granted by Folder-based in Jenkins Authorization Strategy Plugin
CVE-2025-24400 unknown 1y ago Cache confusion in Jenkins Eiffel Broadcaster Plugin
CVE-2025-24399 unknown 1y ago Improper handling of case sensitivity in Jenkins OpenId Connect Authentication Plugin
CVE-2025-24398 unknown 1y ago Bitbucket Server Integration Plugin allows bypassing CSRF protection for any URL
CVE-2025-24397 unknown 1y ago Incorrect permission check in Jenkins GitLab Plugin allows enumerating credentials IDs
CVE-2024-45479 unknown 1y ago Apache Ranger UI vulnerable to Server Side Request Forgery
CVE-2024-45478 unknown 1y ago Apache Ranger has Stored Cross-site Scripting vulnerability in Edit Service Page
CVE-2025-23209 unknown 1.5 KEV 1y ago Craft CMS contains a code injection vulnerability caused by improper validation of the database backup path, ultimately enabling remote code execution.
CVE-2025-23184 unknown 1y ago Apache CXF: Denial of Service vulnerability with temporary files
CVE-2024-43709 unknown 1y ago Elasticsearch allocation of resources without limits or throttling leads to crash
CVE-2025-22620 unknown FIX debian debian 1y ago gitoxide is an implementation of git written in Rust. Prior to 0.17.0, gix-worktree-state specifies 0777 permissions when checking out executable files, intending that the umask will restrict them ap…
CVE-2024-5138 unknown FIX debian debian 1y ago The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did not properly parse …
CVE-2024-50603 unknown 1.5 KEV 1y ago Aviatrix Controllers contain an OS command injection vulnerability that could allow an unauthenticated attacker to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type fo…
CVE-2023-0482 unknown debian debian 1y ago Insecure Temporary File in RESTEasy
CVE-2024-56374 unknown FIX slesdebian debian 1y ago An issue was discovered in Django 5.1 before 5.1.5, 5.0 before 5.0.11, and 4.2 before 4.2.18. Lack of upper-bound limit enforcement in strings passed when performing IPv6 validation could lead to a p…
CVE-2024-45627 unknown 1y ago Apache Linkis Metadata Query Service JDBC: JDBC Datasource Module with Mysql has file read vulnerability
CVE-2025-23042 unknown 1y ago Gradio Blocked Path ACL Bypass Vulnerability
CVE-2025-23025 unknown 1y ago XWiki Realtime WYSIWYG Editor extension allows privilege escalation (PR) through realtime WYSIWYG editing
CVE-2025-21335 unknown 1.5 KEV 1y ago Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.
CVE-2025-21334 unknown 1.5 KEV 1y ago Microsoft Windows Hyper-V NT Kernel Integration VSP contains a use-after-free vulnerability that allows a local attacker to gain SYSTEM privileges.
CVE-2025-21333 unknown 2.5 KEVEXP 1y ago Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow vulnerability that allows a local attacker to gain SYSTEM privileges.
CVE-2024-55591 unknown 1.5 KEV 1y ago Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websoc…
CVE-2024-11734 unknown 1y ago Denial of Service in Keycloak Server via Security Headers
CVE-2024-11736 unknown 1y ago Keycloak allows unrestricted admin use of system and environment variables
CVE-2025-23026 unknown 1y ago jte's HTML templates containing Javascript template strings are subject to XSS
CVE-2024-12686 unknown 1.5 KEV 1y ago BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with existing administrative privileges to upload…
CVE-2023-48365 unknown 1.5 KEV 1y ago Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software.
CVE-2024-55459 unknown debian debian 1y ago keras Path Traversal vulnerability
CVE-2024-54676 unknown 1y ago Apache OpenMeetings vulnerable to Deserialization of Untrusted Data
CVE-2025-0282 unknown 2.5 KEVEXP 1y ago Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.
CVE-2024-55550 unknown 1.5 KEV 1y ago Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input saniti…
CVE-2024-41713 unknown 1.5 KEV 1y ago Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550, which allow…
CVE-2020-2883 unknown 2.5 KEVEXP 1y ago Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecified vulnerability exploitable by an unauthenticated attacker with network access via IIOP or T3.
CVE-2024-8447 unknown 1y ago Narayana deadlock via multiple join requests sent to LRA Coordinator
CVE-2024-3393 unknown 1.5 KEV 2y ago Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that, when exploited, allows an unauthenticated attacker to remotely reboot…
CVE-2024-56512 unknown 2y ago Apache NiFi: Missing Complete Authorization for Parameter and Service References
CVE-2024-12744 unknown 2y ago Amazon Redshift JDBC Driver vulnerable to SQL Injection
CVE-2024-52046 unknown FIX debian debian 2y ago Apache MINA Deserialization RCE Vulnerability
CVE-2024-43441 unknown 2y ago Apache HugeGraph-Server: Fixed JWT Token (Secret)
CVE-2024-23945 unknown 2y ago Apache Hive and Spark: CookieSigner exposes the correct signature when message verification fails
CVE-2021-44207 unknown 1.5 KEV 2y ago Acclaim Systems USAHERDS contains a hard-coded credentials vulnerability that could allow an attacker to achieve remote code execution on the system that runs the application. The MachineKey must be …
CVE-2024-56334 unknown FIX debian debian 2y ago systeminformation is a System and OS information library for node.js. In affected versions SSIDs are not sanitized when before they are passed as a parameter to cmd.exe in the `getWindowsIEEE8021x` f…
CVE-2024-38819 unknown debian debian 2y ago Spring Framework Path Traversal vulnerability
CVE-2024-12801 unknown slesdebian debian 2y ago QOS.CH logback-core Server-Side Request Forgery vulnerability
CVE-2024-12798 unknown slesdebian debian google 2y ago QOS.CH logback-core Expression Language Injection vulnerability
CVE-2024-56327 unknown ubuntu ubuntu 2y ago age vulnerability
CVE-2024-12356 unknown 2.5 KEVEXP 2y ago BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to inject commands that are run as a site use…
CVE-2024-45338 unknown FIX debian debian sles 2y ago An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.
CVE-2024-56145 unknown 2.5 KEVEXP 2y ago Craft CMS contains a code injection vulnerability. Users with affected versions are vulnerable to remote code execution if their php.ini configuration has `register_argc_argv` enabled.
CVE-2024-56128 unknown 2y ago Apache Kafka's SCRAM implementation Incorrectly Implements Authentication Algorithm
CVE-2023-37940 unknown 2y ago Liferay Portal and Liferay DXP have Cross-site Scripting vulnerability in edit Service Access Policy page
CVE-2022-23227 unknown 1.5 KEV 2y ago NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users.
CVE-2021-40407 unknown 1.5 KEV 2y ago Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality.
CVE-2019-11001 unknown 1.5 KEV 2y ago Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the "TestEmail…
CVE-2018-14933 unknown 2.5 KEVEXP 2y ago NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.
CVE-2024-49194 unknown 2y ago Databricks JDBC Driver Command Injection vulnerability
CVE-2024-12539 unknown 2y ago Elasticsearch Incorrect Authorization vulnerability
CVE-2024-11993 unknown 2y ago Liferay Portal and Liferay DXP vulnerable to Cross-site Scripting
CVE-2024-55956 unknown 2.5 KEVEXP 2y ago Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitra…
CVE-2024-35230 unknown 2y ago Welcome and About GeoServer pages communicate version and revision information
CVE-2024-35250 unknown 2.5 KEVEXP 2y ago Microsoft Windows Kernel-Mode Driver contains an untrusted pointer dereference vulnerability that allows a local attacker to escalate privileges.
CVE-2024-20767 unknown 2.5 KEVEXP 2y ago Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel.
CVE-2024-55887 unknown 2y ago Ucum-java has an XXE vulnerability in XML parsing
CVE-2024-50623 unknown 1.5 KEV 2y ago Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated priv…
CVE-2024-55662 unknown 2y ago XWiki allows remote code execution through the extension sheet
CVE-2024-55663 unknown 2y ago XWiki Platform has an SQL injection in getdocuments.vm with sort parameter
CVE-2024-55875 unknown 2y ago http4k has a potential XXE (XML External Entity Injection) vulnerability
CVE-2024-55876 unknown 2y ago XWiki's scheduler in subwiki allows scheduling operations for any main wiki user
CVE-2024-55877 unknown 2y ago XWiki allows remote code execution from account through macro descriptions and XWiki.XWikiSyntaxMacrosList
CVE-2024-55879 unknown 2y ago XWiki allows RCE from script right in configurable sections
CVE-2024-12401 unknown 2y ago cert-manager ha a potential slowdown / DoS when parsing specially crafted PEM inputs
CVE-2024-12397 unknown 2y ago io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling
CVE-2024-45337 unknown FIX debian debian sles 2y ago Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerCo…
CVE-2024-53677 unknown sles 2y ago Apache Struts file upload logic is flawed
CVE-2024-49138 unknown 2.5 KEVEXP 2y ago Microsoft Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow vulnerability that allows a local attacker to escalate privileges.
CVE-2024-6156 unknown FIX debian debian 2y ago Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.
CVE-2024-6219 unknown FIX debian debian 2y ago Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.
CVE-2024-55601 unknown FIX debian debian 2y ago Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.139.4, some HTML attributes in Markdown in the internal templates listed below not escaped in internal render hooks…