Search

Found 25,374 results in 1527ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-55550 unknown 1.5 KEV 1y ago Mitel MiCollab contains a path traversal vulnerability that could allow an authenticated attacker with administrative privileges to read local files within the system due to insufficient input saniti…
CVE-2024-41713 unknown 1.5 KEV 1y ago Mitel MiCollab contains a path traversal vulnerability that could allow an attacker to gain unauthorized and unauthenticated access. This vulnerability can be chained with CVE-2024-55550, which allow…
CVE-2020-2883 unknown 2.5 KEVEXP 1y ago Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecified vulnerability exploitable by an unauthenticated attacker with network access via IIOP or T3.
CVE-2024-12970 low 3.9 3.9 1y ago Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TUBITAK BILGEM Pardus OS My Computer allows OS Command Injection. This issue affects Pardu…
CVE-2024-8447 unknown 1y ago Narayana deadlock via multiple join requests sent to LRA Coordinator
CVE-2024-3393 unknown 1.5 KEV 1y ago Palo Alto Networks PAN-OS contains a vulnerability in parsing and logging malicious DNS packets in the DNS Security feature that, when exploited, allows an unauthenticated attacker to remotely reboot…
CVE-2024-56512 unknown 2y ago Apache NiFi: Missing Complete Authorization for Parameter and Service References
CVE-2024-12744 unknown 2y ago Amazon Redshift JDBC Driver vulnerable to SQL Injection
CVE-2024-52046 unknown FIX debian debian 2y ago Apache MINA Deserialization RCE Vulnerability
CVE-2024-43441 unknown 2y ago Apache HugeGraph-Server: Fixed JWT Token (Secret)
CVE-2024-23945 unknown 2y ago Apache Hive and Spark: CookieSigner exposes the correct signature when message verification fails
CVE-2021-44207 unknown 1.5 KEV 2y ago Acclaim Systems USAHERDS contains a hard-coded credentials vulnerability that could allow an attacker to achieve remote code execution on the system that runs the application. The MachineKey must be …
CVE-2024-56334 unknown FIX debian debian 2y ago systeminformation is a System and OS information library for node.js. In affected versions SSIDs are not sanitized when before they are passed as a parameter to cmd.exe in the `getWindowsIEEE8021x` f…
CVE-2024-38819 unknown debian debian 2y ago Spring Framework Path Traversal vulnerability
CVE-2024-12801 unknown slesdebian debian 2y ago QOS.CH logback-core Server-Side Request Forgery vulnerability
CVE-2024-12798 unknown slesdebian debian google 2y ago QOS.CH logback-core Expression Language Injection vulnerability
CVE-2024-12356 unknown 2.5 KEVEXP 2y ago BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to inject commands that are run as a site use…
CVE-2024-45338 unknown FIX debian debian sles 2y ago An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.
CVE-2024-56145 unknown 2.5 KEVEXP 2y ago Craft CMS contains a code injection vulnerability. Users with affected versions are vulnerable to remote code execution if their php.ini configuration has `register_argc_argv` enabled.
CVE-2024-56128 unknown 2y ago Apache Kafka's SCRAM implementation Incorrectly Implements Authentication Algorithm
CVE-2023-37940 unknown 2y ago Liferay Portal and Liferay DXP have Cross-site Scripting vulnerability in edit Service Access Policy page
CVE-2022-23227 unknown 1.5 KEV 2y ago NUUO NVRmini2 devices contain a missing authentication vulnerability that allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users.
CVE-2021-40407 unknown 1.5 KEV 2y ago Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality.
CVE-2019-11001 unknown 1.5 KEV 2y ago Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the "TestEmail…
CVE-2018-14933 unknown 2.5 KEVEXP 2y ago NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.
CVE-2024-49194 unknown 2y ago Databricks JDBC Driver Command Injection vulnerability
CVE-2024-12539 unknown 2y ago Elasticsearch Incorrect Authorization vulnerability
CVE-2024-11993 unknown 2y ago Liferay Portal and Liferay DXP vulnerable to Cross-site Scripting
CVE-2024-54677 low 2.5 FIX slesdebian debian 2y ago Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.…
CVE-2024-55956 unknown 2.5 KEVEXP 2y ago Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload vulnerability that could allow an unauthenticated user to import and execute arbitra…
CVE-2024-35230 unknown 2y ago Welcome and About GeoServer pages communicate version and revision information
CVE-2024-35250 unknown 2.5 KEVEXP 2y ago Microsoft Windows Kernel-Mode Driver contains an untrusted pointer dereference vulnerability that allows a local attacker to escalate privileges.
CVE-2024-20767 unknown 2.5 KEVEXP 2y ago Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel.
CVE-2024-55887 unknown 2y ago Ucum-java has an XXE vulnerability in XML parsing
CVE-2022-45819 low 3.5 3.5 code-atlantic 2y ago Missing Authorization vulnerability in Popup Maker Popup Maker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup Maker: from n/a through 1.17.1.
CVE-2024-50623 unknown 1.5 KEV 2y ago Cleo Harmony, VLTrader, and LexiCom, which are managed file transfer products, contain an unrestricted file upload and download vulnerability that can lead to remote code execution with elevated priv…
CVE-2024-55662 unknown 2y ago XWiki allows remote code execution through the extension sheet
CVE-2024-55663 unknown 2y ago XWiki Platform has an SQL injection in getdocuments.vm with sort parameter
CVE-2024-55875 unknown 2y ago http4k has a potential XXE (XML External Entity Injection) vulnerability
CVE-2024-55876 unknown 2y ago XWiki's scheduler in subwiki allows scheduling operations for any main wiki user
CVE-2024-55877 unknown 2y ago XWiki allows remote code execution from account through macro descriptions and XWiki.XWikiSyntaxMacrosList
CVE-2024-55879 unknown 2y ago XWiki allows RCE from script right in configurable sections
CVE-2024-12401 unknown 2y ago cert-manager ha a potential slowdown / DoS when parsing specially crafted PEM inputs
CVE-2024-12397 unknown 2y ago io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling
CVE-2024-7592 low 2.5 FIX rhel sles rocky 2y ago There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When parsing cookies that contained backslashes for quoted characters in the cookie…
CVE-2024-45337 unknown FIX debian debian sles 2y ago Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerCo…
CVE-2024-53677 unknown sles 2y ago Apache Struts file upload logic is flawed
CVE-2024-49138 unknown 2.5 KEVEXP 2y ago Microsoft Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow vulnerability that allows a local attacker to escalate privileges.
CVE-2024-6156 unknown FIX debian debian 2y ago Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.
CVE-2024-6219 unknown FIX debian debian 2y ago Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.
CVE-2024-55601 unknown FIX debian debian 2y ago Hugo is a static site generator. Starting in version 0.123.0 and prior to version 0.139.4, some HTML attributes in Markdown in the internal templates listed below not escaped in internal render hooks…
CVE-2023-28168 low 3.7 3.7 2y ago Missing Authorization vulnerability in Jerod Santo WordPress Console allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress Console: from n/a through 0.3…
CVE-2023-24375 low 3.5 3.5 2y ago Missing Authorization vulnerability in miniOrange WordPress Social Login and Register (Discord, Google, Twitter, LinkedIn) allows Exploiting Incorrectly Configured Access Control Security Levels.This…
CVE-2023-23814 low 3.8 3.8 2y ago Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CP Multi View Event Calendar…
CVE-2024-55565 unknown FIX debian debian 2y ago nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.
CVE-2024-53908 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subje…
CVE-2024-53907 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack…
CVE-2024-54140 unknown 2y ago sigstore-java has a vulnerability with bundle verification
CVE-2022-41137 unknown 2y ago Apache Hive: Deserialization of untrusted data when fetching partitions from the Metastore
CVE-2024-38829 unknown debian debian 2y ago Spring LDAP data exposure vulnerability
CVE-2024-51378 unknown 2.5 KEVEXP 2y ago CyberPanel contains an incorrect default permissions vulnerability that allows for authentication bypass and the execution of arbitrary commands using shell metacharacters in the statusfile property.
CVE-2024-37303 unknown FIX debian debian 2y ago Synapse's unauthenticated writes to the media repository allow planting of problematic content
CVE-2024-37302 unknown FIX debian debian 2y ago Synapse denial of service through media disk space consumption
CVE-2024-45106 unknown 2y ago Apache Ozone: Improper authentication when generating S3 secrets
CVE-2024-11680 unknown 2.5 KEVEXP 2y ago ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP re…
CVE-2024-11667 unknown 1.5 KEV 2y ago Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL.
CVE-2023-45727 unknown 1.5 KEV 2y ago North Grid Proself Enterprise/Standard, Gateway, and Mail Sanitize contain an improper restriction of XML External Entity (XXE) reference vulnerability, which could allow a remote, unauthenticated at…
CVE-2024-53981 unknown FIX slesdebian debian 2y ago python-multipart is a streaming multipart parser for Python. When parsing form data, python-multipart skips line breaks (CR \r or LF \n) in front of the first boundary and any tailing bytes after the…
CVE-2024-53990 unknown debian debian 2y ago AsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`s
CVE-2024-52800 low 2.5 2y ago veraPDF CLI has potential XXE (XML External Entity Injection) vulnerability
CVE-2024-38827 unknown 2y ago Spring Framework has Authorization Bypass for Case Sensitive Comparisons
CVE-2024-35371 unknown 2y ago Ant-Media-Server vulnerable to Improper Output Neutralization for Logs
CVE-2024-36623 unknown FIX debian debian sles 2y ago moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application cr…
CVE-2024-36621 unknown FIX debian debian sles 2y ago moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function result…
CVE-2024-36620 unknown FIX debian debian 2y ago moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.
CVE-2024-49203 unknown 2y ago Querydsl vulnerable to HQL injection through orderBy
CVE-2024-54004 unknown 2y ago Jenkins Filesystem List Parameter Plugin has Path Traversal vulnerability
CVE-2024-54003 unknown 2y ago Jenkins Simple Queue Plugin has stored cross-site scripting (XSS) vulnerability
CVE-2024-53267 unknown 2y ago sigstore-java has vulnerability with bundle verification
CVE-2024-27043 low 2.5 FIX rocky slesdebian debian 2y ago In the Linux kernel, the following vulnerability has been resolved: media: edia: dvbdev: fix a use-after-free In dvb_register_device, *pdvbdev is set equal to dvbdev, which is freed in several erro…
CVE-2024-10039 unknown 2y ago Keycloak mTLS Authentication Bypass via Reverse Proxy TLS Termination
CVE-2024-9666 unknown 2y ago Keycloak proxy header handling Denial-of-Service (DoS) vulnerability
CVE-2024-10451 unknown 2y ago Keycloak Build Process Exposes Sensitive Data
CVE-2024-10492 low 2.7 2.7 2y ago Keycloak Path Traversal Vulnerability Due to External Control of File Name or Path
CVE-2024-53916 unknown FIX debian debian 2y ago In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. It does not apply the proper policy check for changing network tags. An unprivileg…
CVE-2023-28461 unknown 1.5 KEV 2y ago Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway.
CVE-2024-44308 unknown 1.5 KEVFIX slesdebian debian 2y ago The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing malici…
CVE-2024-21287 unknown 1.5 KEV 2y ago Oracle Agile Product Lifecycle Management (PLM) contains an incorrect authorization vulnerability in the Process Extension component of the Software Development Kit. Successful exploitation of this v…
CVE-2024-52797 unknown 2y ago Searching Opencast may cause a denial of service
CVE-2024-38813 unknown 1.5 KEV 2y ago VMware vCenter contains an improper check for dropped privileges vulnerability. This vulnerability could allow an attacker with network access to the vCenter Server to escalate privileges to root by …
CVE-2024-38812 unknown 1.5 KEV 2y ago VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter S…
CVE-2024-31141 unknown 2y ago Apache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProvider
CVE-2024-52304 unknown FIX slesdebian debian 2y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.10.11, the Python parser parses newlines in chunk extensions incorrectly which can lead to request s…
CVE-2024-52303 unknown FIX slesdebian debian 2y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions starting with 3.10.6 and prior to 3.10.11, a memory leak can occur when a request produces a MatchInfoError…
CVE-2024-52506 unknown 2y ago Graylog concurrent PDF report rendering can leak other users' reports
CVE-2024-52318 unknown FIX slesdebian debian 2y ago Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97…
CVE-2024-8781 unknown 2y ago Execution with Unnecessary Privileges, : Improper Protection of Alternate Path vulnerability in TR7 Application Security Platform (ASP) allows Privilege Escalation, -Privilege Abuse. This issue affe…
CVE-2024-52317 unknown FIX slesdebian debian 2y ago Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between us…
CVE-2024-52316 unknown FIX slesdebian debian 2y ago Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception dur…
CVE-2024-38828 unknown debian debian 2y ago Spring MVC controller vulnerable to a DoS attack