Search

Found 25,391 results in 889ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-52316 unknown FIX slesdebian debian 2y ago Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception dur…
CVE-2024-38828 unknown debian debian 2y ago Spring MVC controller vulnerable to a DoS attack
CVE-2024-9474 unknown 2.5 KEVEXP 2y ago Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls …
CVE-2024-1212 unknown 2.5 KEVEXP 2y ago Progress Kemp LoadMaster contains an OS command injection vulnerability that allows an unauthenticated, remote attacker to access the system through the LoadMaster management interface, enabling arbi…
CVE-2024-0012 unknown 2.5 KEVEXP 2y ago Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators.
CVE-2023-4639 unknown FIX debian debian 2y ago Undertow incorrectly parses cookies
CVE-2023-1419 unknown 2y ago Debezium database connector has a script injection vulnerability
CVE-2024-42499 unknown 2y ago FitNesse Path Traversal
CVE-2024-39610 unknown 2y ago FitNesse Cross-site scripting
CVE-2024-7787 unknown 2y ago Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in ITG Computer Technology vSRM Supplier Relationship Management System allows Reflected XSS,…
CVE-2024-9465 unknown 1.5 KEV 2y ago Palo Alto Networks Expedition contains a SQL injection vulnerability that allows an unauthenticated attacker to reveal Expedition database contents, such as password hashes, usernames, device configu…
CVE-2024-9463 unknown 1.5 KEV 2y ago Palo Alto Networks Expedition contains an OS command injection vulnerability that allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of use…
CVE-2018-12699 low 2.5 FIX debian debian sles rocky 2y ago RHSA-2024:9689: binutils security update (Low)
CVE-2024-52554 unknown 2y ago Script security bypass vulnerability in Jenkins Shared Library Version Override Plugin
CVE-2024-52553 unknown 2y ago Session fixation vulnerability in Jenkins OpenId Connect Authentication Plugin
CVE-2024-52552 unknown 2y ago Stored XSS vulnerability in Jenkins Authorize Project Plugin
CVE-2024-52551 unknown 2y ago Restarting a run with revoked script approval allowed by Jenkins Pipeline: Declarative Plugin
CVE-2024-52550 unknown 2y ago Rebuilding a run with revoked script approval allowed by Jenkins Pipeline: Groovy Plugin
CVE-2024-52549 unknown 2y ago Missing permission check in Jenkins Script Security Plugin
CVE-2024-51996 unknown FIX debian debian 2y ago Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. When consuming a persisted remember-me cookie, Symfony does not check if the username persisted i…
CVE-2024-47535 unknown FIX slesdebian debian 2y ago Denial of Service attack on windows app using netty
CVE-2024-8074 unknown 2y ago Missing Authentication for Critical Function, Missing Authorization vulnerability in Nomysoft Informatics Nomysem allows Collect Data as Provided by Users. This issue affects Nomysem: before 13.10.2…
CVE-2024-6501 low 2.5 FIX rhel slesdebian debian 2y ago Low: NetworkManager security update
CVE-2024-6126 low 2.5 FIX rheldebian debian sles 2y ago A flaw was found in the cockpit package. This flaw allows an authenticated user to kill any process when enabling the pam_env's user_readenv option, which leads to a denial of service (DoS) attack.
CVE-2024-5742 low 2.5 FIX rhel rocky sles 2y ago RHSA-2024:6986: nano security update (Low)
CVE-2024-49039 unknown 1.5 KEV 2y ago Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access pr…
CVE-2024-4741 low 2.5 FIX rhel sles rocky 2y ago Low: openssl security update
CVE-2024-4603 low 2.5 FIX rhel sles rocky 2y ago Low: openssl security update
CVE-2024-43451 unknown 1.5 KEV 2y ago Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a file open operation. The attacker could then leverage this h…
CVE-2024-29039 low 2.5 FIX rhel sles rocky 2y ago Low: tpm2-tools security update
CVE-2024-29038 low 2.5 FIX rhel sles rocky 2y ago Low: tpm2-tools security update
CVE-2024-26461 low 2.5 rhel sles rocky 2y ago RHSA-2024:3268: krb5 security update (Low)
CVE-2024-26458 low 2.5 rhel rocky sles 2y ago RHSA-2024:3268: krb5 security update (Low)
CVE-2024-2314 low 2.5 FIX rheldebian debian rocky 2y ago RHSA-2024:8831: bcc security update (Low)
CVE-2024-2313 low 2.5 FIX rheldebian debian rocky 2y ago RHSA-2024:8830: bpftrace security update (Low)
CVE-2021-41277 unknown 1.5 KEV 2y ago Metabase contains a local file inclusion vulnerability in the custom map support in the API to read GeoJSON formatted data.
CVE-2021-3903 low 2.5 FIX rhelarch arch sles 2y ago vim is vulnerable to Heap-based Buffer Overflow
CVE-2021-26086 unknown 2.5 KEVEXP 2y ago Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint.
CVE-2014-2120 unknown 1.5 KEV 2y ago Cisco Adaptive Security Appliance (ASA) contains a cross-site scripting (XSS) vulnerability in the WebVPN login page. This vulnerability allows remote attackers to inject arbitrary web script or HTML…
CVE-2024-51135 unknown 2y ago powertac-server XML External Entity vulnerability
CVE-2024-52007 unknown 2y ago XXE vulnerability in XSLT parsing in `org.hl7.fhir.core`
CVE-2024-47072 unknown FIX slesdebian debian 2y ago XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream
CVE-2024-51504 unknown FIX debian debian 2y ago Apache ZooKeeper: Authentication bypass with IP-based authentication in Admin Server
CVE-2023-1973 unknown FIX debian debian 2y ago Undertow Denial of Service vulnerability
CVE-2023-1932 unknown debian debian 2y ago hibernate-validator Cross-site Scripting vulnerability
CVE-2024-5910 unknown 2.5 KEVEXP 2y ago Palo Alto Networks Expedition contains a missing authentication vulnerability that allows an attacker with network access to takeover an Expedition admin account and potentially access configuration …
CVE-2024-51567 unknown 2.5 KEVEXP 2y ago CyberPanel contains an incorrect default permissions vulnerability that allows a remote, unauthenticated attacker to execute commands as root.
CVE-2024-43093 unknown 1.5 KEV 2y ago Android Framework contains an unspecified vulnerability that allows for privilege escalation.
CVE-2019-16278 unknown 2.5 KEVEXP 2y ago Nostromo nhttpd contains a directory traversal vulnerability in the http_verify() function in a non-chrooted nhttpd server allowing for remote code execution.
CVE-2024-51755 unknown FIX debian debian 2y ago Twig is a template language for PHP. In a sandbox, an attacker can access attributes of Array-like objects as they were not checked by the security policy. They are now checked via the property polic…
CVE-2024-51754 unknown FIX debian debian 2y ago Twig is a template language for PHP. In a sandbox, an attacker can call `__toString()` on an object even if the `__toString()` method is not allowed by the security policy when the object is part of …
CVE-2024-51751 unknown 2y ago Gradio vulnerable to arbitrary file read with File and UploadButton components
CVE-2024-51736 unknown FIX debian debian 2y ago Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.exe` is located in the current working directory i…
CVE-2024-50345 unknown FIX debian debian 2y ago symfony/http-foundation is a module for the Symphony PHP framework which defines an object-oriented layer for the HTTP specification. The `Request` class, does not parse URI with special characters t…
CVE-2024-50343 unknown FIX debian debian 2y ago symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to trick a `Validator` configured with a regular expression using the `$` metachar…
CVE-2024-50342 unknown FIX debian debian 2y ago symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the `NoPrivateNetworkHttpClient`, so…
CVE-2024-50341 unknown FIX debian debian 2y ago symfony/security-bundle is a module for the Symphony PHP framework which provides a tight integration of the Security component into the Symfony full-stack framework. The custom `user_checker` define…
CVE-2024-50340 unknown FIX debian debian 2y ago symfony/runtime is a module for the Symphony PHP framework which enables decoupling PHP applications from global state. When the `register_argv_argc` php directive is set to `on` , and users call any…
CVE-2024-51132 unknown 2y ago HAPI FHIR XML External Entity (XXE) vulnerability
CVE-2024-51746 unknown FIX debian debian 2y ago Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. gitsign may select the wrong Rekor entry to use during online verification when multiple entries are …
CVE-2024-36117 unknown 2y ago Reposilite vulnerable to path traversal while serving javadoc expanded files (arbitrary file read) (`GHSL-2024-074`)
CVE-2024-51127 unknown 2y ago hornetq vulnerable to file overwrite, sensitive information disclosure
CVE-2024-23590 unknown 2y ago Apache Kylin Session Fixation vulnerability
CVE-2024-8957 unknown 1.5 KEV 2y ago PTZOptics PT30X-SDI/NDI cameras contain an OS command injection vulnerability that allows a remote, authenticated attacker to escalate privileges to root via a crafted payload with the ntp_addr param…
CVE-2024-8956 unknown 1.5 KEV 2y ago PTZOptics PT30X-SDI/NDI cameras contain an insecure direct object reference (IDOR) vulnerability that allows a remote, attacker to bypass authentication for the /cgi-bin/param.cgi CGI script. If comb…
CVE-2024-42835 unknown 2y ago langflow has vulnerability in PythonCodeTool component
CVE-2024-48910 unknown FIX debian debian 2y ago DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify was vulnerable to prototype pollution. This vulnerability is fixed in 2.4.2.
CVE-2024-48307 unknown 2y ago JeecgBoot SQL Injection vulnerability
CVE-2024-36387 low 2.5 FIX debian debian rhel sles 2y ago Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance.
CVE-2024-43382 unknown 2y ago Snowflake JDBC Security Advisory
CVE-2024-48063 unknown debian debian 2y ago In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.
CVE-2024-45477 unknown 2y ago Apache NiFi Cross-site Scripting vulnerability
CVE-2024-38821 unknown 2y ago Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications
CVE-2024-49771 unknown 2y ago MPXJ has a Potential Path Traversal Vulnerability
CVE-2024-49760 unknown FIX debian debian 2y ago OpenRefine has a path traversal in LoadLanguageCommand
CVE-2024-47883 unknown FIX debian debian 2y ago Butterfly has path/URL confusion in resource handling leading to multiple weaknesses
CVE-2024-47882 unknown FIX debian debian 2y ago OpenRefine's error page lacks escaping, leading to potential Cross-site Scripting on import of malicious project
CVE-2024-47881 unknown FIX debian debian 2y ago OpenRefine's SQLite integration allows filesystem access, remote code execution (RCE)
CVE-2024-47880 unknown FIX debian debian 2y ago OpenRefine has a reflected cross-site scripting vulnerability (XSS) from POST request in ExportRowsCommand
CVE-2024-47879 unknown FIX debian debian 2y ago OpenRefine's PreviewExpressionCommand, which is eval, lacks protection against cross-site request forgery (CSRF)
CVE-2024-47878 unknown FIX debian debian 2y ago OpenRefine has a reflected cross-site scripting vulnerability (XSS) in GData extension (authorized.vt)
CVE-2024-45031 unknown 2y ago Apache Syncope: Stored XSS in Console and Enduser
CVE-2024-37383 unknown 2.5 KEVEXPFIX debian debian 2y ago RoundCube Webmail contains a cross-site scripting (XSS) vulnerability in the handling of SVG animate attributes that allows a remote attacker to run malicious JavaScript code.
CVE-2024-20481 unknown 1.5 KEV 2y ago Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain a missing release of resource after effective lifetime vulnerability that could allow an unauthenticated, remote att…
CVE-2024-47575 unknown 2.5 KEVEXP 2y ago Fortinet FortiManager contains a missing authentication vulnerability in the fgfmd daemon that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted re…
CVE-2024-8980 unknown 2y ago Liferay Portal and Liferay DXP Vulnerable to CSRF in the Script Console
CVE-2024-38002 unknown 2y ago Liferay Portal and Liferay DXP Workflow Component Does Not Check User Permissions
CVE-2024-26273 unknown 2y ago Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the Content Page Editor
CVE-2024-26272 unknown 2y ago Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the Content Page Editor
CVE-2024-26271 unknown 2y ago Liferay Portal and Liferay DXP Vulnerable to Cross-Site Request Forgery (CSRF) via the My Account Widget
CVE-2024-38094 unknown 1.5 KEV 2y ago Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution.
CVE-2024-9537 unknown 1.5 KEV 2y ago ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component.
CVE-2024-38820 unknown debian debian 2y ago Spring Framework DataBinder Case Sensitive Match Exception
CVE-2024-49580 unknown 2y ago JetBrains Ktor information disclosure
CVE-2024-40711 unknown 1.5 KEV 2y ago Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthenticated user to perform remote code execution.
CVE-2024-45217 unknown FIX debian debian 2y ago Insecure Default Initialization of Resource vulnerability in Apache Solr
CVE-2024-45216 unknown FIX debian debian 2y ago Improper Authentication vulnerability in Apache Solr
CVE-2024-47874 unknown FIX slesdebian debian 2y ago Starlette is an Asynchronous Server Gateway Interface (ASGI) framework/toolkit. Prior to version 0.40.0, Starlette treats `multipart/form-data` parts without a `filename` as text form fields and buff…
CVE-2024-47876 unknown 2y ago SAK-50571 Sakai Kernel users created with type roleview can login as a normal user
CVE-2024-30088 unknown 1.5 KEV 2y ago Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation.