Search

Found 25,458 results in 1077ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-39954 unknown 10mo ago Apache EventMesh Vulnerable to Server-Side Request Forgery in WebhookUtil.java
CVE-2025-9193 low 3.5 3.5 10mo ago A flaw has been found in TOTVS Portal Meu RH up to 12.1.17. Impacted is an unknown function of the component Password Reset Handler. Executing manipulation of the argument redirectUrl can lead to ope…
CVE-2025-43744 unknown 10mo ago Liferay Portal Vulnerable to Cross-Site Scripting via DDM Structure Field Labels
CVE-2025-43743 unknown 10mo ago Liferay Portal Enumeration Discrepancy in Calendars
CVE-2025-43745 unknown 10mo ago Liferay Portal CSRF Vulnerability via Endpoint Parameter
CVE-2025-43737 unknown 10mo ago Liferay Portal Vulnerable to Cross-Site Scripting via backURL Paramter
CVE-2025-9165 low 2.5 2.5 FIX slesdebian debian libtiff 10mo ago A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipul…
CVE-2025-43738 unknown 10mo ago Liferay Portal Reflected Cross-Site Scripting Vulnerability in displayType Parameter
CVE-2025-43739 unknown 10mo ago Liferay Portal Email Modification Vulnerability via Calendar Portlet
CVE-2025-43731 unknown 10mo ago Liferay Portal Vulnerable to Cross-Site Scripting
CVE-2025-9119 low 2.4 2.4 10mo ago A vulnerability was determined in Netis WF2419 1.2.29433. This vulnerability affects unknown code of the file /index.htm of the component Wireless Settings Page. This manipulation of the argument SSI…
CVE-2025-3639 unknown 10mo ago Liferay Portal Login Bypass Vulnerability
CVE-2025-43733 unknown 10mo ago Liferay Portal Vulnerable to Cross-Site Scripting
CVE-2025-43732 unknown 10mo ago Liferay Portal Vulnerable to Insecure Direct Object Reference
CVE-2025-41242 unknown debian debian 10mo ago Spring Framework MVC Applications Path Traversal Vulnerability
CVE-2025-9109 low 3.7 3.7 portabilis 10mo ago A security flaw has been discovered in Portabilis i-Diario up to 1.5.0. Affected by this vulnerability is an unknown functionality of the file /password/email of the component Password Recovery Endpo…
CVE-2025-9103 low 2.4 2.4 10mo ago A vulnerability was detected in ZenCart 2.1.0. Affected by this vulnerability is an unknown functionality of the component CKEditor. The manipulation leads to cross site scripting. The attack can be …
CVE-2025-9096 low 3.5 3.5 10mo ago ExpressGateway Cross-Site Scripting Vulnerability in lib/rest/routes/apps.js
CVE-2025-54948 unknown 1.5 KEV 10mo ago Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attacker to upload malicious code and execute commands …
CVE-2025-9095 low 3.5 3.5 10mo ago ExpressGateway Cross-Site Scripting Vulnerability in lib/rest/routes/users.js
CVE-2025-9092 unknown 10mo ago Bouncy Castle for Java Uncontrolled Resource Consumption Vulnerability
CVE-2025-9005 low 3.7 3.7 mtons 10mo ago A vulnerability was determined in mtons mblog up to 3.5.0. Affected is an unknown function of the file /register. The manipulation leads to information exposure through error message. It is possible …
CVE-2025-8961 low 3.3 3.3 FIX slesdebian debian libtiff 10mo ago A weakness has been identified in LibTIFF 4.7.0. This affects the function main of the file tiffcrop.c of the component tiffcrop. Executing manipulation can lead to memory corruption. The attack can …
CVE-2025-8927 low 3.7 3.7 mtons 10mo ago A vulnerability was determined in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality of the file /email/send_code of the component Verification Code Handler. The manipulati…
CVE-2025-55163 unknown FIX slesdebian debian 10mo ago Netty affected by MadeYouReset HTTP/2 DDoS vulnerability
CVE-2025-8876 unknown 1.5 KEV 10mo ago N-able N-Central contains a command injection vulnerability via improper sanitization of user input.
CVE-2025-8875 unknown 1.5 KEV 10mo ago N-able N-Central contains an insecure deserialization vulnerability that could lead to command execution.
CVE-2025-43734 unknown 10mo ago Liferay Portal 7.4.0 and Liferay DXP have a reflected cross-site scripting (XSS) vulnerability
CVE-2025-8747 unknown FIX debian debian 10mo ago Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality
CVE-2025-21096 low 1.9 1.9 10mo ago Improper buffer restrictions in the firmware for some Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.
CVE-2025-8885 unknown FIX debian debian sles 10mo ago Bouncy Castle for Java on All (API modules) allows Excessive Allocation
CVE-2025-43736 unknown 10mo ago Liferay Portal and Liferay DXP have a Denial Of Service via File Upload (DOS) vulnerability
CVE-2025-8088 unknown 1.5 KEV 10mo ago RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.
CVE-2025-55159 unknown FIX slesdebian debian 10mo ago slab is a pre-allocated storage for a uniform data type. In version 0.4.10, the get_disjoint_mut method incorrectly checked if indices were within the slab's capacity instead of its length, allowing …
CVE-2013-3893 unknown 2.5 KEVEXP 10mo ago Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code execution. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users shoul…
CVE-2007-0671 unknown 1.5 KEV 10mo ago Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachmen…
CVE-2025-8836 low 3.3 3.3 sles jasper_project 10mo ago A vulnerability was determined in JasPer up to 4.2.5. Affected by this issue is the function jpc_floorlog2 of the file src/libjasper/jpc/jpc_enc.c of the component JPEG2000 Encoder. The manipulation …
CVE-2025-8834 low 2.4 2.4 10mo ago A vulnerability has been found in JCG Link-net LW-N915R 17s.20.001.908. Affected is an unknown function of the file /wireless/basic.asp of the component Wireless Basic Settings Page. The manipulation…
CVE-2025-8765 low 3.5 3.5 10mo ago A vulnerability classified as problematic was found in Datacom DM955 5GT 1200 825.8010.00. Affected by this vulnerability is an unknown functionality of the component Wireless Basic Settings. The man…
CVE-2025-4581 unknown 10mo ago Liferay Portal and Liferay DXP vulnerable to Server-Side Request Forgery
CVE-2025-8737 low 3.5 3.5 10mo ago A vulnerability, which was classified as problematic, was found in zlt2000 microservices-platform up to 6.0.0. This affects the function onLogoutSuccess of the file src/main/java/com/central/oauth/ha…
CVE-2025-8735 low 3.3 3.3 debian debian 10mo ago A vulnerability classified as problematic was found in GNU cflow up to 1.8. Affected by this vulnerability is the function yylex of the file c.c of the component Lexer. The manipulation leads to null…
CVE-2025-4576 unknown 10mo ago Liferay Portal Reflected XSS in blogs-web
CVE-2025-8732 low 3.3 3.3 debian debian sles 10mo ago A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads…
CVE-2025-53606 unknown 10mo ago Apache Seata: Deserialization of untrusted Data in Apache Seata Server
CVE-2025-48913 unknown google 10mo ago Apache CXF: Untrusted JMS configuration can lead to RCE
CVE-2025-8698 low 3.3 3.3 open5gs 10mo ago A vulnerability was found in Open5GS up to 2.7.5. It has been classified as problematic. Affected is the function amf_nsmf_pdusession_handle_release_sm_context of the file src/amf/nsmf-handler.c of t…
CVE-2025-54368 unknown FIX slesdebian debian 10mo ago uv is a Python package and project manager written in Rust. In versions 0.8.5 and earlier, remote ZIP archives were handled in a streamwise fashion, and file entries were not reconciled against the a…
CVE-2025-54799 unknown FIX debian debian 10mo ago Let's Encrypt client and ACME library written in Go (Lego). In versions 4.25.1 and below, the github.com/go-acme/lego/v4/acme/api package (thus the lego library and the lego cli as well) don't enforc…
CVE-2012-10024 unknown 1.0 EXP 10mo ago XBMC version 11.0 contains a path traversal vulnerability in its embedded HTTP server. When accessed via HTTP Basic Authentication, the server fails to properly sanitize URI input, allowing authentic…
CVE-2012-10026 unknown 1.0 EXP 10mo ago The WordPress plugin Asset-Manager version 2.0 and below contains an unauthenticated arbitrary file upload vulnerability in upload.php. The endpoint fails to properly validate and restrict uploaded f…
CVE-2025-8586 low 3.3 3.3 libav 10mo ago A vulnerability, which was classified as problematic, was found in libav up to 12.3. This affects the function ff_seek_frame_binary of the file /libavformat/utils.c of the component MPEG File Parser.…
CVE-2025-8584 low 3.3 3.3 libav 10mo ago A vulnerability classified as problematic was found in libav up to 12.3. Affected by this vulnerability is the function av_buffer_unref of the file libavutil/buffer.c of the component AVI File Parser…
CVE-2025-54125 unknown 10mo ago XWiki exposes passwords and emails stored in fields not named password/email in xml.vm
CVE-2025-54124 unknown 10mo ago XWiki leaks password hashes and other accessible password properties
CVE-2025-32430 unknown 10mo ago XWiki allows Reflected XSS in two templates
CVE-2025-8549 low 3.7 3.7 pybbs_project 10mo ago A vulnerability was found in atjiu pybbs up to 6.0.0. It has been classified as critical. Affected is the function update of the file src/main/java/co/yiiu/pybbs/controller/admin/UserAdminController.…
CVE-2025-8548 low 3.7 3.7 pybbs_project 10mo ago A vulnerability was found in atjiu pybbs up to 6.0.0 and classified as problematic. This issue affects the function sendEmailCode of the file src/main/java/co/yiiu/pybbs/controller/api/SettingsApiCon…
CVE-2025-4604 unknown 10mo ago Liferay Portal CAPTCHA Bypass for Gogo Shell
CVE-2025-8534 low 2.5 2.5 FIX slesdebian debian libtiff 10mo ago A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads …
CVE-2022-40799 unknown 1.5 KEV 10mo ago D-Link DNR-322L contains a download of code without integrity check vulnerability that could allow an authenticated attacker to execute OS level commands on the device. The impacted products could be…
CVE-2022-29458 low 2.5 FIX rhel sles rocky 10mo ago ncurses 6.3 before patch 20220416 has an out-of-bounds read and segmentation violation in convert_strings in tinfo/read_entry.c in the terminfo library.
CVE-2020-25079 unknown 1.5 KEV 10mo ago D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users shou…
CVE-2020-25078 unknown 1.5 KEV 10mo ago D-Link DCS-2530L and DCS-2670L devices contains an unspecified vulnerability that could allow for remote administrator password disclosure. The impacted products could be end-of-life (EoL) and/or end…
CVE-2025-8519 low 2.7 2.7 vvveb 10mo ago A vulnerability classified as problematic has been found in givanz Vvveb up to 1.0.5. This affects an unknown part of the file /vadmin123/index.php?module=editor/editor of the component Drag-and-Drop…
CVE-2025-8515 low 3.7 3.7 intelbras 10mo ago A weakness has been identified in Intelbras InControl 2.21.60.9. This vulnerability affects unknown code of the file /v1/operador/ of the component JSON Endpoint. Executing manipulation can lead to i…
CVE-2024-52279 unknown 10mo ago Apache Zeppelin: Arbitrary file read by adding malicious JDBC connection string
CVE-2024-51775 unknown 10mo ago Apache Zeppelin: Missing Origin Validation in WebSockets vulnerability
CVE-2024-41177 unknown 10mo ago Apache Zeppelin: XSS in the Helium module
CVE-2025-8506 low 3.5 3.5 10mo ago A vulnerability was found in 495300897 wx-shop up to de1b66331368695779cfc6e4d11a64caddf8716e and classified as problematic. This issue affects some unknown processing of the file /user/editUI. The m…
CVE-2025-24854 unknown 10mo ago Apache JSPWiki Cross-Site Scripting (XSS) Vulnerability in the Image Plugin
CVE-2025-24853 unknown 10mo ago Apache JSPWiki Cross-Site Scripting (XSS) Vulnerability via Header Link Rendering
CVE-2025-54656 unknown sles 10mo ago Apache Struts Extras Before 2 has an Improper Output Neutralization for Logs Vulnerability
CVE-2025-52490 unknown 10mo ago Couchbase Sync Gateway shows cleartext passwords in redacted and unredacted output
CVE-2025-54410 unknown debian debian sles 10mo ago Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. A firewalld vulne…
CVE-2025-54388 unknown FIX debian debian sles 10mo ago Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. In versions 28.2.…
CVE-2025-8283 low 3.7 3.7 FIX slesdebian debian rhel redhat 10mo ago Netavark Has Possible DNS Resolve Confusion
CVE-2025-20337 unknown 1.5 KEV 11mo ago Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to explo…
CVE-2025-20281 unknown 1.5 KEV 11mo ago Cisco Identity Services Engine contains an injection vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC due to insufficient validation of user-supplied input allowing an attacker to explo…
CVE-2023-2533 unknown 1.5 KEV 11mo ago PaperCut NG/MF contains a cross-site request forgery (CSRF) vulnerability, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code.
CVE-2025-8225 low 3.3 3.3 FIX debian debian sles gnu 11mo ago A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component DWARF Section Handler. T…
CVE-2025-8205 low 3.7 3.7 comodo 11mo ago A vulnerability, which was classified as problematic, has been found in Comodo Dragon up to 134.0.6998.179. Affected by this issue is some unknown functionality of the component IP DNS Leakage Detect…
CVE-2025-8204 low 3.7 3.7 comodo 11mo ago A vulnerability classified as problematic was found in Comodo Dragon up to 134.0.6998.179. Affected by this vulnerability is an unknown functionality of the component HSTS Handler. The manipulation l…
CVE-2025-54380 unknown 11mo ago Opencast still publishes global system account credentials
CVE-2025-54385 unknown 11mo ago XWiki Platform vulnerable to SQL injection through XWiki#searchDocuments API
CVE-2025-32429 unknown 1.0 EXP 11mo ago XWiki Platform vulnerable to SQL injection through getdeleteddocuments.vm template sort parameter
CVE-2025-53015 unknown FIX debian debian sles 11mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0, infinite lines occur when writing during a specific XMP file conversion co…
CVE-2025-50481 unknown 1.0 EXP 11mo ago Mezzanine CMS vulnerable to Cross-site Scripting
CVE-2025-51471 unknown 11mo ago Ollama vulnerable to Cross-Domain Token Exposure
CVE-2025-51481 unknown 11mo ago Dagster Local File Inclusion vulnerability
CVE-2025-54309 unknown 1.5 KEV 11mo ago CrushFTP contains an unprotected alternate channel vulnerability. When the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via…
CVE-2025-49706 unknown 2.5 KEVEXP 11mo ago Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view…
CVE-2025-49704 unknown 2.5 KEVEXP 11mo ago Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-…
CVE-2025-2776 unknown 1.5 KEV 11mo ago SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Server URL processing functionality, allowing for administrator account takeover and file read pr…
CVE-2025-2775 unknown 1.5 KEV 11mo ago SysAid On-Prem contains an improper restriction of XML external entity reference vulnerability in the Checkin processing functionality, allowing for administrator account takeover and file read primi…
CVE-2025-54121 unknown FIX slesdebian debian 11mo ago Starlette is a lightweight ASGI (Asynchronous Server Gateway Interface) framework/toolkit, designed for building async web services in Python. In versions 0.47.1 and below, when parsing a multi-part …
CVE-2025-7962 unknown debian debian sles 11mo ago Jakarta Mail vulnerable to SMTP Injection
CVE-2025-50151 unknown debian debian 11mo ago Apache Jena doesn't validate file access paths in configuration files uploaded by users with administrator access
CVE-2025-49656 unknown debian debian 11mo ago Apache Jena allows users with administrator access to create databases files outside the files area of the Fuseki server
CVE-2025-49087 low 3.7 3.7 FIX debian debian trustedfirmware 11mo ago In Mbed TLS 3.6.1 through 3.6.3 before 3.6.4, a timing discrepancy in block cipher padding removal allows an attacker to recover the plaintext when PKCS#7 padding mode is used.