Search

Found 33,996 results in 1142ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-64458 unknown FIX debian debian 7mo ago Django has a denial-of-service vulnerability in HttpResponseRedirect and HttpResponsePermanentRedirect on Windows
CVE-2025-48703 unknown 1.5 KEV 7mo ago CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in…
CVE-2025-11371 unknown 2.5 KEVEXP 7mo ago Gladinet CentreStack and Triofox contains a files or directories accessible to external parties vulnerability that allows unintended disclosure of system files.
CVE-2025-11953 unknown 1.5 KEV 7mo ago React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server and run arbitrary e…
CVE-2025-0987 critical 9.9 9.9 7mo ago Authorization Bypass Through User-Controlled Key vulnerability in CB Project Ltd. Co. CVLand allows Parameter Injection. This issue affects CVLand: from 2.1.0 through 20251103. NOTE: The vendor was …
CVE-2025-12617 critical 9.8 9.8 angeljudesuarez 7mo ago A flaw has been found in itsourcecode Billing System 1.0. This affects an unknown function of the file /admin/app/login_crud.php. Executing a manipulation of the argument Password can lead to sql inj…
CVE-2025-12614 critical 9.8 9.8 mayurik 7mo ago A weakness has been identified in SourceCodester Best House Rental Management System 1.0. Impacted is the function delete_payment of the file /admin_class.php. This manipulation of the argument ID ca…
CVE-2025-12612 critical 9.8 9.8 campcodes 7mo ago A security flaw has been discovered in Campcodes School Fees Payment Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=delete_course. The manipulation of …
CVE-2025-12608 critical 9.8 9.8 angeljudesuarez 7mo ago A security flaw has been discovered in itsourcecode Online Loan Management System 1.0. The affected element is an unknown function of the file /manage_user.php. Performing manipulation of the argumen…
CVE-2025-12607 critical 9.8 9.8 angeljudesuarez 7mo ago A vulnerability was identified in itsourcecode Online Loan Management System 1.0. Impacted is an unknown function of the file /manage_payment.php. Such manipulation of the argument ID leads to sql in…
CVE-2025-12606 critical 9.8 9.8 angeljudesuarez 7mo ago A vulnerability was determined in itsourcecode Online Loan Management System 1.0. This issue affects some unknown processing of the file /manage_borrower.php. This manipulation of the argument ID cau…
CVE-2025-12605 critical 9.8 9.8 angeljudesuarez 7mo ago A vulnerability was found in itsourcecode Online Loan Management System 1.0. This vulnerability affects unknown code of the file /manage_loan.php. The manipulation of the argument ID results in sql i…
CVE-2025-12604 critical 9.8 9.8 angeljudesuarez 7mo ago A vulnerability has been found in itsourcecode Online Loan Management System 1.0. This affects an unknown part of the file /load_fields.php. The manipulation of the argument loan_id leads to sql inje…
CVE-2025-12598 critical 9.8 9.8 mayurik 7mo ago A flaw has been found in SourceCodester Best House Rental Management System 1.0. Affected by this issue is the function save_tenant of the file /admin_class.php. Executing manipulation of the argumen…
CVE-2025-12597 critical 9.8 9.8 mayurik 7mo ago A vulnerability was detected in SourceCodester Best House Rental Management System 1.0. Affected by this vulnerability is the function save_category of the file /admin_class.php. Performing manipulat…
CVE-2025-62275 unknown 7mo ago Liferay Portal and DXP do not check permissions of images in a blog entry
CVE-2025-62276 unknown 7mo ago Liferay Portal and DXP use an incorrect cache-control header
CVE-2025-62267 unknown 7mo ago Liferay Portal and DXP affected by multiple cross-site scripting (XSS) vulnerabilities in web content template’s select structure page
CVE-2025-62264 unknown 7mo ago Liferay Portal Vulnerable to Reflected XSS via the selectedLanguageId Parameter
CVE-2025-57108 unknown debian debian 7mo ago Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader. The vulnerability manifests during mesh object copy operations where vector me…
CVE-2025-57107 unknown debian debian 7mo ago Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap buffer overflow vulnerability in vtkGLTFDocumentLoader. When processing specially crafted GLTF files, the copy constructor of Accesso…
CVE-2025-57106 unknown debian debian 7mo ago Kitware VTK (Visualization Toolkit) up to 9.5.0 is vulnerable to Buffer Overflow in vtkGLTFDocumentLoader. The vulnerability occurs in the BufferDataExtractionWorker template function when processing…
CVE-2025-6520 critical 9.8 9.8 7mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Abis Technology BAPSIS allows Blind SQL Injection. This issue affects BAPSIS: before 20251027160…
CVE-2025-62265 unknown 7mo ago Liferay Portal is vulnerable to XSS in the Blogs widget
CVE-2025-62266 unknown 7mo ago Liferay Portal is vulnerable to DNS rebinding attacks
CVE-2025-62257 unknown 7mo ago Liferay Portal vulnerable to password enumeration
CVE-2025-13327 unknown FIX slesdebian debian 7mo ago A flaw was found in uv. This vulnerability allows an attacker to execute malicious code during package resolution or installation via specially crafted ZIP (Zipped Information Package) archives that …
CVE-2025-61724 unknown FIX debian debian sles 7mo ago The Reader.ReadResponse function constructs a response string through repeated string concatenation of lines. When the number of lines in a response is large, this can cause excessive CPU consumption.
CVE-2025-58188 unknown FIX debian debian sles google 7mo ago Validating certificate chains which contain DSA public keys can cause programs to panic, due to a interface cast that assumes they implement the Equal method. This affects programs which validate arb…
CVE-2025-58186 unknown FIX debian debian sles 7mo ago Despite HTTP headers having a default limit of 1MB, the number of cookies that can be parsed does not have a limit. By sending a lot of very small cookies such as "a=;", an attacker can make an HTTP …
CVE-2025-58185 unknown FIX debian debian sles 7mo ago Parsing a maliciously crafted DER payload could allocate large amounts of memory, causing memory exhaustion.
CVE-2025-47912 unknown FIX debian debian sles 7mo ago The Parse function permits values other than IPv6 addresses to be included in square brackets within the host component of a URL. RFC 3986 permits IPv6 addresses to be included within the host compon…
CVE-2025-61723 unknown FIX debian debian sles google 7mo ago The processing time for parsing some invalid inputs scales non-linearly with respect to the size of the input. This affects programs which parse untrusted PEM inputs.
CVE-2025-58189 unknown FIX debian debian sles 7mo ago When Conn.Handshake fails during ALPN negotiation the error contains attacker controlled information (the ALPN protocols sent by the client) which is not escaped.
CVE-2025-58187 unknown FIX debian debian sles google 7mo ago Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate. This affects programs which validate ar…
CVE-2025-61725 unknown FIX debian debian sles 7mo ago The ParseAddress function constructs domain-literal address components through repeated string concatenation. When parsing large domain-literal components, this can cause excessive CPU consumption.
CVE-2025-64150 unknown 7mo ago Jenkins Publish to Bitbucket Plugin is missing a permissions check
CVE-2025-64149 unknown 7mo ago Jenkins Publish to Bitbucket Plugin vulnerable to CSRF and missing permissions check
CVE-2025-64148 unknown 7mo ago Jenkins Publish to Bitbucket Plugin is missing a permissions check
CVE-2025-64147 unknown 7mo ago Jenkins Curseforge Publisher Plugin does not mask API Keys displayed on the job configuration form
CVE-2025-64145 unknown 7mo ago Jenkins ByteGuard Build Actions Plugin does not mask API tokens displayed on the job configuration form
CVE-2025-64144 unknown 7mo ago Jenkins ByteGuard Build Actions Plugin stores API tokens unencrypted in job config.xml files
CVE-2025-64143 unknown 7mo ago Jenkins OpenShift Pipeline Plugin stores authorization tokens unencrypted in job config.xml files
CVE-2025-64142 unknown 7mo ago Jenkins Nexus Task Runner Plugin is missing a permission check
CVE-2025-64141 unknown 7mo ago Jenkins Nexus Task Runner Plugin vulnerable to cross-site request forgery
CVE-2025-64140 unknown 7mo ago Jenkins Azure CLI Plugin does not restrict the commands it executes
CVE-2025-64139 unknown 7mo ago Jenkins Start Windocks Containers Plugin is missing a permission check
CVE-2025-64138 unknown 7mo ago Jenkins Start Windocks Containers Plugin vulnerable to cross-site request forgery
CVE-2025-64137 unknown 7mo ago Jenkins Themis Plugin is missing a permission check
CVE-2025-64136 unknown 7mo ago Jenkins Themis Plugin vulnerable to cross-site request forgery
CVE-2025-64135 unknown 7mo ago Jenkins Eggplant Runner Plugin protection mechanism disabled
CVE-2025-64134 unknown 7mo ago Jenkins JDepend Plugin vulnerable to XML external entity attacks
CVE-2025-64133 unknown 7mo ago Jenkins Extensible Choice Parameter Plugin vulnerable to cross-site request forgery
CVE-2025-64132 unknown 7mo ago Jenkins MCP Server Plugin does not perform permission checks in multiple MCP tools
CVE-2025-64131 unknown 7mo ago Jenkins SAML Plugin does not implement a replay cache
CVE-2025-62727 unknown FIX slesdebian debian 7mo ago Starlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthenticated attacker can send a crafted HTTP Range header that triggers quadratic-ti…
CVE-2025-62784 unknown 7mo ago InventoryGui allows item duplication in GUIs which use GuiStorageElement
CVE-2025-12390 unknown 7mo ago Keycloak vulnerable to session takeovers due to reuse of session identifiers
CVE-2025-62171 unknown FIX debian debian sles 7mo ago ImageMagick is an open source software suite for displaying, converting, and editing raster image files. In ImageMagick versions prior to 7.1.2-7 and 6.9.13-32, an integer overflow vulnerability exis…
CVE-2025-40039 unknown FIX slesdebian debian 7mo ago In the Linux kernel, the following vulnerability has been resolved: ksmbd: Fix race condition in RPC handle list access The 'sess->rpc_handle_list' XArray manages RPC handles within a ksmbd session…
CVE-2025-12378 critical 9.8 9.8 fabian 7mo ago A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This issue affects some unknown processing of the file /addproduct.php. Performing manipulation of the argument p…
CVE-2025-12339 critical 9.8 9.8 campcodes 7mo ago A security vulnerability has been detected in Campcodes Retro Basketball Shoes Online Store 1.0. This issue affects some unknown processing of the file /admin/admin_football.php. The manipulation of …
CVE-2025-12338 critical 9.8 9.8 campcodes 7mo ago A weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1.0. This vulnerability affects unknown code of the file /admin/admin_product.ph. Executing a manipulation of the argum…
CVE-2025-12337 critical 9.8 9.8 campcodes 7mo ago A security flaw has been discovered in Campcodes Retro Basketball Shoes Online Store 1.0. This affects an unknown part of the file /admin/admin_feature.php. Performing a manipulation of the argument …
CVE-2025-12336 critical 9.8 9.8 campcodes 7mo ago A vulnerability was identified in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unknown functionality of the file /admin/admin_index.php. Such manipulation of the …
CVE-2025-62260 unknown 7mo ago Liferay Portal Vulnerable to DoS via Crafted Headless API Request
CVE-2025-62259 unknown 7mo ago Liferay Portal Does Not Limit Access to APIs Before Email Verification
CVE-2025-62258 unknown 7mo ago Liferay Portal Vulnerable to CSRF in Headless APIs
CVE-2025-62261 unknown 7mo ago Liferay Portal Stores Password Reset Tokens in Plain Text
CVE-2025-6205 unknown 1.5 KEV 7mo ago Dassault Systèmes DELMIA Apriso contains a missing authorization vulnerability that could allow an attacker to gain privileged access to the application.
CVE-2025-6204 unknown 1.5 KEV 7mo ago Dassault Systèmes DELMIA Apriso contains a code injection vulnerability that could allow an attacker to execute arbitrary code.
CVE-2025-62594 unknown FIX debian debian sles 7mo ago ImageMagick is a software suite to create, edit, compose, or convert bitmap images. ImageMagick versions prior to 7.1.2-8 are vulnerable to denial-of-service due to unsigned integer underflow and div…
CVE-2025-62262 unknown 7mo ago Liferay Portal Vulnerable to Information Exposure Through a Log File Vulnerability in LDAP Import Feature
CVE-2025-62263 unknown 7mo ago Liferay Portal Vulnerable to Cross-Site Scripting
CVE-2025-62253 unknown 7mo ago Liferay Portal Vulnerable to Open Redirect via the _com_liferay_layout_admin_web_portlet_GroupPagesPortlet_redirect parameter
CVE-2025-12325 critical 9.8 9.8 mayurik 7mo ago A vulnerability has been found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the file /panel/forgot-password.php. The manipulation of the argument email leads to…
CVE-2025-12316 critical 9.8 9.8 carmelogarcia 7mo ago A vulnerability was identified in code-projects Courier Management System 1.0. This impacts an unknown function of the file /courier/edit-courier.php. The manipulation of the argument OfficeName lead…
CVE-2025-11419 unknown 7mo ago Keycloak TLS Client-Initiated Renegotiation Denial of Service
CVE-2025-12315 critical 9.8 9.8 code-projects 7mo ago A vulnerability was determined in code-projects Food Ordering System 1.0. This affects an unknown function of the file /admin/menu.php. Executing a manipulation of the argument itemPrice can lead to …
CVE-2025-12314 critical 9.8 9.8 code-projects 7mo ago A vulnerability was found in code-projects Food Ordering System 1.0. The impacted element is an unknown function of the file /admin/deleteitem.php. Performing a manipulation of the argument itemID re…
CVE-2025-12313 critical 9.8 9.8 7mo ago A vulnerability has been found in D-Link DI-7001 MINI 19.09.19A1/24.04.18B1. The affected element is an unknown function of the file /msp_info.htm. Such manipulation of the argument cmd leads to comm…
CVE-2025-62782 unknown 7mo ago InventoryGui allows item duplication with experimental "Bundle" item in GUIs which use GuiStorageElement
CVE-2025-62783 unknown 7mo ago InventoryGui affected by item duplication in GUIs which use GuiStorageElement
CVE-2025-12309 critical 9.8 9.8 fabian 7mo ago A weakness has been identified in code-projects Nero Social Networking Site 1.0. This affects an unknown part of the file /friendprofile.php. Executing manipulation of the argument ID can lead to sql…
CVE-2025-12308 critical 9.8 9.8 fabian 7mo ago A security flaw has been discovered in code-projects Nero Social Networking Site 1.0. Affected by this issue is some unknown functionality of the file /deletemessage.php. Performing manipulation of t…
CVE-2025-12307 critical 9.8 9.8 fabian 7mo ago A vulnerability was identified in code-projects Nero Social Networking Site 1.0. Affected by this vulnerability is an unknown functionality of the file /addfriend.php. Such manipulation of the argume…
CVE-2025-12306 critical 9.8 9.8 fabian 7mo ago A vulnerability was determined in code-projects Nero Social Networking Site 1.0. Affected is an unknown function of the file /acceptoffres.php. This manipulation of the argument ID causes sql injecti…
CVE-2025-12305 critical 9.8 9.8 quequnlong 7mo ago A vulnerability was found in quequnlong shiyi-blog up to 1.2.1. This impacts an unknown function of the file src/main/java/com/mojian/controller/SysJobController.java of the component Job Handler. Th…
CVE-2025-12301 critical 9.8 9.8 fabian 7mo ago A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Impacted is an unknown function of the file /editproduct.php. Such manipulation of the argument photo lead…
CVE-2025-12296 critical 9.8 9.8 7mo ago A security vulnerability has been detected in D-Link DAP-2695 2.00RC13. The impacted element is the function sub_4174B0 of the component Firmware Update Handler. The manipulation leads to os command …
CVE-2025-12294 critical 9.8 9.8 janobe 7mo ago A security flaw has been discovered in SourceCodester Point of Sales 1.0. Impacted is an unknown function of the file /delete_category.php. Performing manipulation of the argument ID results in sql i…
CVE-2025-12293 critical 9.8 9.8 janobe 7mo ago A vulnerability was identified in SourceCodester Point of Sales 1.0. This issue affects some unknown processing of the file /category.php. Such manipulation of the argument Category leads to sql inje…
CVE-2025-12292 critical 9.8 9.8 janobe 7mo ago A vulnerability was determined in SourceCodester Point of Sales 1.0. This vulnerability affects unknown code of the file /index.php. This manipulation of the argument Username causes sql injection. I…
CVE-2025-12268 critical 9.8 9.8 learnhouse 7mo ago A vulnerability has been found in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Impacted is an unknown function of the file /api/v1/courses/ of the component Course Thumbnail Handler. Th…
CVE-2025-12257 critical 9.8 9.8 oretnom23 7mo ago A security vulnerability has been detected in SourceCodester Online Student Result System 1.0. This issue affects some unknown processing of the file /view_result.php. The manipulation of the argumen…
CVE-2025-12253 critical 9.8 9.8 amttgroup 7mo ago A vulnerability was determined in AMTT Hotel Broadband Operation System 1.0. Affected by this vulnerability is an unknown functionality of the file /user/portal/get_expiredtime.php. This manipulation…
CVE-2025-12237 critical 9.8 9.8 projectworlds 7mo ago A vulnerability was identified in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function of the file /index.php. Such manipulation of the argument keywords leads to sql…
CVE-2025-12226 critical 9.8 9.8 mayurik 7mo ago A vulnerability was found in SourceCodester Best House Rental Management System 1.0. Impacted is the function save_house of the file /admin_class.php. Performing manipulation of the argument house_no…
CVE-2025-12215 critical 9.8 9.8 projectworlds 7mo ago A flaw has been found in projectworlds Online Shopping System 1.0. Impacted is an unknown function of the file /login_submit.php. Executing a manipulation of the argument keywords can lead to sql inj…
CVE-2025-12208 critical 9.8 9.8 mayurik 7mo ago A vulnerability was found in SourceCodester Best House Rental Management System 1.0. This impacts the function login2 of the file /admin_class.php. Performing manipulation of the argument Username re…