Search

Found 21,056 results in 3958ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-55565 unknown FIX debian debian 2y ago nanoid (aka Nano ID) before 5.0.9 mishandles non-integer values. 3.3.8 is also a fixed version.
CVE-2024-53908 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. Direct usage of the django.db.models.fields.json.HasKey lookup, when an Oracle database is used, is subje…
CVE-2024-53907 unknown FIX slesdebian debian 2y ago An issue was discovered in Django 5.1 before 5.1.4, 5.0 before 5.0.10, and 4.2 before 4.2.17. The strip_tags() method and striptags template filter are subject to a potential denial-of-service attack…
CVE-2024-54140 unknown 2y ago sigstore-java has a vulnerability with bundle verification
CVE-2022-41137 unknown 2y ago Apache Hive: Deserialization of untrusted data when fetching partitions from the Metastore
CVE-2024-38829 unknown debian debian 2y ago Spring LDAP data exposure vulnerability
CVE-2024-51378 unknown 2.5 KEVEXP 2y ago CyberPanel contains an incorrect default permissions vulnerability that allows for authentication bypass and the execution of arbitrary commands using shell metacharacters in the statusfile property.
CVE-2024-37303 unknown FIX debian debian 2y ago Synapse's unauthenticated writes to the media repository allow planting of problematic content
CVE-2024-37302 unknown FIX debian debian 2y ago Synapse denial of service through media disk space consumption
CVE-2024-45106 unknown 2y ago Apache Ozone: Improper authentication when generating S3 secrets
CVE-2024-11680 unknown 2.5 KEVEXP 2y ago ProjectSend contains an improper authentication vulnerability that allows a remote, unauthenticated attacker to enable unauthorized modification of the application's configuration via crafted HTTP re…
CVE-2024-11667 unknown 1.5 KEV 2y ago Multiple Zyxel firewalls contain a path traversal vulnerability in the web management interface that could allow an attacker to download or upload files via a crafted URL.
CVE-2023-45727 unknown 1.5 KEV 2y ago North Grid Proself Enterprise/Standard, Gateway, and Mail Sanitize contain an improper restriction of XML External Entity (XXE) reference vulnerability, which could allow a remote, unauthenticated at…
CVE-2024-53981 unknown FIX slesdebian debian 2y ago python-multipart is a streaming multipart parser for Python. When parsing form data, python-multipart skips line breaks (CR \r or LF \n) in front of the first boundary and any tailing bytes after the…
CVE-2024-53990 unknown debian debian 2y ago AsyncHttpClient (AHC) library's `CookieStore` replaces explicitly defined `Cookie`s
CVE-2024-38827 unknown 2y ago Spring Framework has Authorization Bypass for Case Sensitive Comparisons
CVE-2024-35371 unknown 2y ago Ant-Media-Server vulnerable to Improper Output Neutralization for Logs
CVE-2024-36623 unknown FIX debian debian sles 2y ago moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application cr…
CVE-2024-36621 unknown FIX debian debian sles 2y ago moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function result…
CVE-2024-36620 unknown FIX debian debian 2y ago moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.
CVE-2024-49203 unknown 2y ago Querydsl vulnerable to HQL injection through orderBy
CVE-2024-54004 unknown 2y ago Jenkins Filesystem List Parameter Plugin has Path Traversal vulnerability
CVE-2024-54003 unknown 2y ago Jenkins Simple Queue Plugin has stored cross-site scripting (XSS) vulnerability
CVE-2024-53267 unknown 2y ago sigstore-java has vulnerability with bundle verification
CVE-2024-10039 unknown 2y ago Keycloak mTLS Authentication Bypass via Reverse Proxy TLS Termination
CVE-2024-9666 unknown 2y ago Keycloak proxy header handling Denial-of-Service (DoS) vulnerability
CVE-2024-10451 unknown 2y ago Keycloak Build Process Exposes Sensitive Data
CVE-2024-53916 unknown FIX debian debian 2y ago In OpenStack Neutron before 25.0.1, neutron/extensions/tagging.py can use an incorrect ID during policy enforcement. It does not apply the proper policy check for changing network tags. An unprivileg…
CVE-2023-28461 unknown 1.5 KEV 2y ago Array Networks AG and vxAG ArrayOS contain a missing authentication for critical function vulnerability that allows an attacker to read local files and execute code on the SSL VPN gateway.
CVE-2024-44308 unknown 1.5 KEVFIX slesdebian debian 2y ago The issue was addressed with improved checks. This issue is fixed in Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, iOS 18.1.1 and iPadOS 18.1.1, macOS Sequoia 15.1.1, visionOS 2.1.1. Processing malici…
CVE-2024-21287 unknown 1.5 KEV 2y ago Oracle Agile Product Lifecycle Management (PLM) contains an incorrect authorization vulnerability in the Process Extension component of the Software Development Kit. Successful exploitation of this v…
CVE-2024-52797 unknown 2y ago Searching Opencast may cause a denial of service
CVE-2024-38813 unknown 1.5 KEV 2y ago VMware vCenter contains an improper check for dropped privileges vulnerability. This vulnerability could allow an attacker with network access to the vCenter Server to escalate privileges to root by …
CVE-2024-38812 unknown 1.5 KEV 2y ago VMware vCenter Server contains a heap-based buffer overflow vulnerability in the implementation of the DCERPC protocol. This vulnerability could allow an attacker with network access to the vCenter S…
CVE-2024-31141 unknown 2y ago Apache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProvider
CVE-2024-52304 unknown FIX slesdebian debian 2y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.10.11, the Python parser parses newlines in chunk extensions incorrectly which can lead to request s…
CVE-2024-52303 unknown FIX slesdebian debian 2y ago aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In versions starting with 3.10.6 and prior to 3.10.11, a memory leak can occur when a request produces a MatchInfoError…
CVE-2024-52506 unknown 2y ago Graylog concurrent PDF report rendering can leak other users' reports
CVE-2024-52318 unknown FIX slesdebian debian 2y ago Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97…
CVE-2024-8781 unknown 2y ago Execution with Unnecessary Privileges, : Improper Protection of Alternate Path vulnerability in TR7 Application Security Platform (ASP) allows Privilege Escalation, -Privilege Abuse. This issue affe…
CVE-2024-52317 unknown FIX slesdebian debian 2y ago Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between us…
CVE-2024-52316 unknown FIX slesdebian debian 2y ago Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception dur…
CVE-2024-38828 unknown debian debian 2y ago Spring MVC controller vulnerable to a DoS attack
CVE-2024-9474 unknown 2.5 KEVEXP 2y ago Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls …
CVE-2024-1212 unknown 2.5 KEVEXP 2y ago Progress Kemp LoadMaster contains an OS command injection vulnerability that allows an unauthenticated, remote attacker to access the system through the LoadMaster management interface, enabling arbi…
CVE-2024-0012 unknown 2.5 KEVEXP 2y ago Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators.
CVE-2023-4639 unknown FIX debian debian 2y ago Undertow incorrectly parses cookies
CVE-2023-1419 unknown 2y ago Debezium database connector has a script injection vulnerability
CVE-2024-42499 unknown 2y ago FitNesse Path Traversal
CVE-2024-39610 unknown 2y ago FitNesse Cross-site scripting
CVE-2024-7787 unknown 2y ago Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ITG Computer Technology vSRM Supplier Relationship Management System allows Reflected XSS,…
CVE-2024-9465 unknown 1.5 KEV 2y ago Palo Alto Networks Expedition contains a SQL injection vulnerability that allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configu…
CVE-2024-9463 unknown 1.5 KEV 2y ago Palo Alto Networks Expedition contains an OS command injection vulnerability that allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of use…
CVE-2024-52554 unknown 2y ago Script security bypass vulnerability in Jenkins Shared Library Version Override Plugin
CVE-2024-52553 unknown 2y ago Session fixation vulnerability in Jenkins OpenId Connect Authentication Plugin
CVE-2024-52552 unknown 2y ago Stored XSS vulnerability in Jenkins Authorize Project Plugin
CVE-2024-52551 unknown 2y ago Restarting a run with revoked script approval allowed by Jenkins Pipeline: Declarative Plugin
CVE-2024-52550 unknown 2y ago Rebuilding a run with revoked script approval allowed by Jenkins Pipeline: Groovy Plugin
CVE-2024-52549 unknown 2y ago Missing permission check in Jenkins Script Security Plugin
CVE-2024-51996 unknown FIX debian debian 2y ago Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me cookie, Symfony does not check if the username persisted i…
CVE-2024-47535 unknown FIX slesdebian debian 2y ago Denial of Service attack on windows app using netty
CVE-2024-8074 unknown 2y ago Missing Authentication for Critical Function, Missing Authorization vulnerability in Nomysoft Informatics Nomysem allows Collect Data as Provided by Users. This issue affects Nomysem: before 13.10.2…
CVE-2024-49039 unknown 1.5 KEV 2y ago Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access pr…
CVE-2024-43451 unknown 1.5 KEV 2y ago Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a file open operation. The attacker could then leverage this h…
CVE-2021-41277 unknown 1.5 KEV 2y ago Metabase contains a local file inclusion vulnerability in the custom map support in the API to read GeoJSON formatted data.
CVE-2021-26086 unknown 2.5 KEVEXP 2y ago Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint.
CVE-2014-2120 unknown 1.5 KEV 2y ago Cisco Adaptive Security Appliance (ASA) contains a cross-site scripting (XSS) vulnerability in the WebVPN login page. This vulnerability allows remote attackers to inject arbitrary web script or HTML…
CVE-2024-51135 unknown 2y ago powertac-server XML External Entity vulnerability
CVE-2024-52007 unknown 2y ago XXE vulnerability in XSLT parsing in `org.hl7.fhir.core`
CVE-2024-47072 unknown FIX slesdebian debian 2y ago XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
CVE-2024-51504 unknown FIX debian debian 2y ago Apache ZooKeeper: Authentication bypass with IP-based authentication in Admin Server
CVE-2023-1973 unknown FIX debian debian 2y ago Undertow Denial of Service vulnerability
CVE-2023-1932 unknown debian debian 2y ago hibernate-validator Cross-site Scripting vulnerability
CVE-2024-5910 unknown 2.5 KEVEXP 2y ago Palo Alto Networks Expedition contains a missing authentication vulnerability that allows an attacker with network access to takeover an Expedition admin account and potentially access configuration …
CVE-2024-51567 unknown 2.5 KEVEXP 2y ago CyberPanel contains an incorrect default permissions vulnerability that allows a remote, unauthenticated attacker to execute commands as root.
CVE-2024-43093 unknown 1.5 KEV 2y ago Android Framework contains an unspecified vulnerability that allows for privilege escalation.
CVE-2019-16278 unknown 2.5 KEVEXP 2y ago Nostromo nhttpd contains a directory traversal vulnerability in the http_verify() function in a non-chrooted nhttpd server allowing for remote code execution.
CVE-2024-51755 unknown FIX debian debian 2y ago Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the security policy. They are now checked via the property polic…
CVE-2024-51754 unknown FIX debian debian 2y ago Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toString()` method is not allowed by the security policy when the object is part of …
CVE-2024-51751 unknown 2y ago Gradio vulnerable to arbitrary file read with File and UploadButton components
CVE-2024-51736 unknown FIX debian debian 2y ago Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.exe` is located in the current working directory i…
CVE-2024-50345 unknown FIX debian debian 2y ago symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` class, does not parse URI with special characters t…
CVE-2024-50343 unknown FIX debian debian 2y ago symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to trick a `Validator` configured with a regular expression using the `$` metachar…
CVE-2024-50342 unknown FIX debian debian 2y ago symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the `NoPrivateNetworkHttpClient`, so…
CVE-2024-50341 unknown FIX debian debian 2y ago symfony/security-bundle is a module for the Symphony PHP framework which provides a tight integration of the Security component into the Symfony full-stack framework. The custom `user_checker` define…
CVE-2024-50340 unknown FIX debian debian 2y ago symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. When the `register_argv_argc` php directive is set to `on` , and users call any…
CVE-2024-51132 unknown 2y ago HAPI FHIR XML External Entity (XXE) vulnerability
CVE-2024-51746 unknown FIX debian debian 2y ago Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. gitsign may select the wrong Rekor entry to use during online verification when multiple entries are …
CVE-2024-36117 unknown 2y ago Reposilite vulnerable to path traversal while serving javadoc expanded files (arbitrary file read) (`GHSL-2024-074`)
CVE-2024-51127 unknown 2y ago hornetq vulnerable to file overwrite, sensitive information disclosure
CVE-2024-23590 unknown 2y ago Apache Kylin Session Fixation vulnerability
CVE-2024-8957 unknown 1.5 KEV 2y ago PTZOptics PT30X-SDI/NDI cameras contain an OS command injection vulnerability that allows a remote, authenticated attacker to escalate privileges to root via a crafted payload with the ntp_addr param…
CVE-2024-8956 unknown 1.5 KEV 2y ago PTZOptics PT30X-SDI/NDI cameras contain an insecure direct object reference (IDOR) vulnerability that allows a remote, attacker to bypass authentication for the /cgi-bin/param.cgi CGI script. If comb…
CVE-2024-42835 unknown 2y ago langflow has vulnerability in PythonCodeTool component
CVE-2024-48910 unknown FIX debian debian 2y ago DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2.
CVE-2024-48307 unknown 2y ago JeecgBoot SQL Injection vulnerability
CVE-2024-43382 unknown 2y ago Snowflake JDBC Security Advisory
CVE-2024-48063 unknown debian debian 2y ago In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.
CVE-2024-45477 unknown 2y ago Apache NiFi Cross-site Scripting vulnerability
CVE-2024-38821 unknown 2y ago Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications