Search

Found 25,452 results in 933ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-7882 low 3.1 3.1 11mo ago A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been rated as problematic. This issue affects some unknown processing of the component Login. The manipulation leads…
CVE-2025-7881 low 2.7 2.7 11mo ago A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been declared as problematic. This vulnerability affects unknown code of the component Web Interface. The manipulati…
CVE-2025-53770 unknown 2.5 KEVEXP 11mo ago Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could b…
CVE-2025-54313 unknown 1.5 KEV sles 11mo ago Prettier eslint-config-prettier contains an embedded malicious code vulnerability. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.
CVE-2025-7789 low 3.7 3.7 xuxueli 11mo ago xxl-job has Inadequate Encryption Strength
CVE-2025-25257 unknown 2.5 KEVEXP 11mo ago Fortinet FortiWeb contains a SQL injection vulnerability that may allow an unauthenticated attacker to execute unauthorized SQL code or commands via crafted HTTP or HTTPs requests.
CVE-2025-54068 unknown 1.5 KEV 11mo ago Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios.
CVE-2025-7748 low 3.5 3.5 11mo ago A vulnerability classified as problematic was found in ZCMS 3.6.0. This vulnerability affects unknown code of the component Create Article Page. The manipulation of the argument Title leads to cross …
CVE-2024-9408 unknown 11mo ago Eclipse GlassFish is vulnerable to Server Side Request Forgery attacks through specific endpoints
CVE-2024-9343 unknown 11mo ago Eclipse GlassFish is vulnerable to Stored XSS attacks through its Administration Console
CVE-2024-9342 unknown 11mo ago Eclipse GlassFish is vulnerable to Login Brute Force attacks through unlimited failed login attempts
CVE-2024-10032 unknown 11mo ago Eclipse GlassFish is vulnerable to Stored XSS attacks through its Administration Console
CVE-2024-10031 unknown 11mo ago Eclipse GlassFish is vulnerable to Stored XSS attacks through configuration file modifications
CVE-2024-10029 unknown 11mo ago Eclipse GlassFish is vulnerable to Reflected XSS attacks through its Administration Console
CVE-2025-22227 unknown 11mo ago Reactor Netty HTTP is vulnerable to credential leaks during chained redirects
CVE-2025-53622 unknown 11mo ago DSpace is vulnerable to Path Traversal attacks when importing packages using Simple Archive Format
CVE-2025-53621 unknown 11mo ago DSpace is vulnerable to XML External Entity injection during archive imports
CVE-2025-48795 unknown 11mo ago Apache CXF is vulnerable to DoS attacks as entire files are read into memory and logged
CVE-2025-53836 unknown 11mo ago XWiki Rendering is vulnerable to RCE attacks when processing nested macros
CVE-2025-53835 unknown 11mo ago XWiki Rendering is vulnerable to XSS attacks through insecure XHTML syntax
CVE-2025-53643 unknown FIX slesdebian debian 11mo ago AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.12.14, the Python parser is vulnerable to a request smuggling vulnerability due to not parsing trail…
CVE-2025-53689 unknown FIX debian debian 11mo ago Apache Jackrabbit vulnerable to blind XXE attack due to insecure document build
CVE-2025-7577 low 3.7 3.7 11mo ago A vulnerability was found in Teledyne FLIR FB-Series O and FLIR FH-Series ID 1.3.2.16. It has been classified as problematic. This affects an unknown part. The manipulation leads to use of hard-coded…
CVE-2025-7569 low 3.5 3.5 11mo ago A vulnerability was found in Bigotry OneBase up to 1.3.6. It has been declared as problematic. Affected by this vulnerability is the function parse_args of the file /tpl/think_exception.tpl. The mani…
CVE-2025-7554 low 2.4 2.4 11mo ago A vulnerability classified as problematic was found in Sapido RB-1802 1.0.32. This vulnerability affects unknown code of the file urlfilter.asp of the component URL Filtering Page. The manipulation o…
CVE-2025-47812 unknown 2.5 KEVEXP 11mo ago Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injection of arbitrary Lua code into user session files. This can be used to execute arb…
CVE-2024-41169 unknown 11mo ago Apache Zeppelin exposes server resources to unauthenticated attackers
CVE-2025-7453 low 3.7 3.7 11mo ago A vulnerability was found in saltbo zpan up to 1.6.5/1.7.0-beta2. It has been rated as problematic. This issue affects the function NewToken of the file zpan/internal/app/service/token.go of the comp…
CVE-2025-48924 unknown FIX debian debian slesubuntu ubuntu 11mo ago Apache Commons Lang vulnerability
CVE-2025-53864 unknown 11mo ago Nimbus JOSE + JWT is vulnerable to DoS attacks when processing deeply nested JSON
CVE-2025-7435 low 3.5 3.5 11mo ago A vulnerability was found in LiveHelperChat lhc-php-resque Extension up to ee1270b35625f552425e32a6a3061cd54b5085c4. It has been classified as problematic. This affects an unknown part of the file /s…
CVE-2025-5777 unknown 2.5 KEVEXP 11mo ago Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread when the NetScaler is configured as a…
CVE-2025-53743 unknown 11mo ago Jenkins Applitools Eyes Plugin vulnerability does not mask API keys on its job configuration form
CVE-2025-53742 unknown 11mo ago Jenkins Applitools Eyes Plugin vulnerability exposes unencrypted keys to certain authenticated users
CVE-2025-53678 unknown 11mo ago Jenkins User1st uTester Plugin vulnerability exposes unencrypted token to authenticated users
CVE-2025-53676 unknown 11mo ago Jenkins Xooa Plugin vulnerability exposes unencrypted tokens to authenticated users
CVE-2025-53675 unknown 11mo ago Jenkins Warrior Framework Plugin vulnerability exposes unencrypted passwords to certain authenticated users
CVE-2025-53669 unknown 11mo ago Jenkins VAddy Plugin vulnerability exposes plaintext keys on its job configuration form
CVE-2025-53674 unknown 11mo ago Jenkins Sensedia API Platform Plugin vulnerability exposes unencrypted tokens
CVE-2025-53673 unknown 11mo ago Jenkins Sensedia API Platform Plugin vulnerability exposes unencrypted tokens in its global configuration file
CVE-2025-53672 unknown 11mo ago Jenkins Kryptowire Plugin vulnerability stores unencrypted Kryptowire API key
CVE-2025-53671 unknown 11mo ago Jenkins Nouvola DiveCloud Plugin vulnerability does not mask keys on its job configuration form
CVE-2025-53670 unknown 11mo ago Jenkins Nouvola DiveCloud Plugin vulnerability stores unencrypted credentials
CVE-2025-53668 unknown 11mo ago Jenkins VAddy Plugin vulnerability exposes unencrypted keys to certain authenticated users
CVE-2025-53667 unknown 11mo ago Jenkins Dead Man's Snitch Plugin vulnerability does not mask tokens
CVE-2025-53666 unknown 11mo ago Jenkins Dead Man's Snitch Plugin vulnerability stores tokens in plain text
CVE-2025-53665 unknown 11mo ago Jenkins Apica Loadtest Plugin vulnerability exposes authentication tokens
CVE-2025-53664 unknown 11mo ago Jenkins Apica Loadtest Plugin vulnerability exposes authentication tokens
CVE-2025-53663 unknown 11mo ago Jenkins IBM Cloud DevOps Plugin vulnerability exposes SonarQube authentication tokens
CVE-2025-53662 unknown 11mo ago Jenkins IFTTT Build Notifier Plugin vulnerability exposes IFTTT Maker Channel Keys
CVE-2025-53661 unknown 11mo ago Jenkins Testsigma Test Plan vulnerability exposes API keys via job configuration form
CVE-2025-53660 unknown 11mo ago Jenkins QMetry Test Management Plugin vulnerability exposes API keys
CVE-2025-53659 unknown 11mo ago Jenkins QMetry Test Management Plugin stores unencrypted API keys
CVE-2025-53658 unknown 11mo ago Jenkins Applitools Eyes Plugin vulnerable to XSS through its Build page
CVE-2025-53657 unknown 11mo ago Jenkins ReadyAPI Functional Testing Plugin vulnerability exposes secrets
CVE-2025-53656 unknown 11mo ago Jenkins ReadyAPI Functional Testing Plugin vulnerability stores unencrypted authentication credentials
CVE-2025-53655 unknown 11mo ago Jenkins Statistics Gatherer Plugin does not mask AWS Secret Key
CVE-2025-53654 unknown 11mo ago Jenkins Statistics Gatherer Plugin vulnerability exposes AWS Secret Key
CVE-2025-53653 unknown 11mo ago Jenkins Aqua Security Scanner Plugin vulnerability exposes scanner tokens
CVE-2025-53652 unknown 11mo ago Jenkins Git Parameter Plugin vulnerable to code injection due to inexhaustive parameter check
CVE-2025-53651 unknown 11mo ago Jenkins HTML Publisher Plugin vulnerability displays controller file system information in its logs
CVE-2025-53650 unknown 11mo ago Jenkins Credentials Binding Plugin vulnerability can expose sensitive information in logger messages
CVE-2025-7215 low 1.6 1.6 11mo ago A vulnerability, which was classified as problematic, has been found in FNKvision FNK-GU2 up to 40.1.7. Affected by this issue is some unknown functionality of the file /rom/wpa_supplicant.conf. The …
CVE-2025-7214 low 1.6 1.6 11mo ago A vulnerability classified as problematic was found in FNKvision FNK-GU2 up to 40.1.7. Affected by this vulnerability is an unknown functionality of the file /etc/shadow of the component MD5. The man…
CVE-2019-9621 unknown 2.5 KEVEXP 11mo ago Synacor Zimbra Collaboration Suite (ZCS) contains a server-side request forgery (SSRF) vulnerability via the ProxyServlet component.
CVE-2014-3931 unknown 1.5 KEV 11mo ago Multi-Router Looking Glass (MRLG) contains a buffer overflow vulnerability that could allow remote attackers to cause an arbitrary memory write and memory corruption.
CVE-2025-7080 low 3.7 3.7 11mo ago A vulnerability, which was classified as problematic, was found in Done-0 Jank up to 322caebbad10568460364b9667aa62c3080bfc17. Affected is an unknown function of the file internal/utils/jwt_utils.go …
CVE-2025-53602 unknown 11mo ago Zipkin Server vulnerable to Insecure Resource Initialization through its /heapdump endpoint
CVE-2025-7061 low 2.7 2.7 intelbras 11mo ago A vulnerability was found in Intelbras InControl up to 2.21.60.9. It has been declared as problematic. This vulnerability affects unknown code of the file /v1/operador/. The manipulation leads to csv…
CVE-2025-6554 unknown 1.5 KEVFIX debian debian 11mo ago Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
CVE-2025-53103 unknown FIX debian debian sles 11mo ago junit-platform-reporting can leak Git credentials through its OpenTestReportGeneratingListener
CVE-2025-48928 unknown 1.5 KEV 11mo ago TeleMessage TM SGNL contains an exposure of core dump file to an unauthorized control sphere Vulnerability. This vulnerability is based on a JSP application in which the heap content is roughly equiv…
CVE-2025-48927 unknown 1.5 KEV 11mo ago TeleMessage TM SGNL contains an initialization of a resource with an insecure default vulnerability. This vulnerability relies on how the Spring Boot Actuator is configured with an exposed heap dump …
CVE-2025-6932 low 3.7 3.7 11mo ago A vulnerability, which was classified as problematic, was found in D-Link DCS-7517 up to 2.02.0. This affects the function g_F_n_GenPassForQlync of the file /bin/httpd of the component Qlync Password…
CVE-2025-53106 unknown 11mo ago Graylog vulnerable to privilege escalation through API tokens
CVE-2025-26074 unknown 11mo ago Conductor vulnerable to OS command injection through unrestricted access to Java classes
CVE-2025-53003 unknown 11mo ago Janssen Config API returns results without scope verification
CVE-2025-6543 unknown 1.5 KEV 11mo ago Citrix NetScaler ADC and Gateway contain a buffer overflow vulnerability leading to unintended control flow and Denial of Service. NetScaler must be configured as Gateway (VPN virtual server, ICA Pro…
CVE-2025-53393 unknown 11mo ago akka-cluster-metrics uses Java serialization for cluster metrics
CVE-2025-32897 unknown 11mo ago Apache Seata Vulnerable to Deserialization of Untrusted Data
CVE-2025-6817 low 3.3 3.3 debian debian hdfgroup 11mo ago A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. This issue affects the function H5C__load_entry of the file /src/H5Centry.c. The manipulation leads to resource co…
CVE-2025-6816 low 3.3 3.3 debian debian sles hdfgroup 11mo ago A vulnerability classified as problematic was found in HDF5 1.14.6. This vulnerability affects the function H5O__fsinfo_encode of the file /src/H5Ofsinfo.c. The manipulation leads to heap-based buffe…
CVE-2025-6750 low 3.3 3.3 debian debian sles hdfgroup 1y ago A vulnerability, which was classified as problematic, has been found in HDF5 1.14.6. Affected by this issue is the function H5O__mtime_new_encode of the file src/H5Omtime.c. The manipulation leads to…
CVE-2025-6748 low 2.1 2.1 1y ago A vulnerability classified as problematic has been found in Bharti Airtel Thanks App 4.105.4 on Android. Affected is an unknown function of the file /Android/data/com.myairtelapp/files/. The manipula…
CVE-2025-5731 unknown 1y ago Infinispan CLI vulnerable to Generation of Error Message Containing Sensitive Information
CVE-2025-52890 unknown FIX debian debian 1y ago Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus versions 6.12 and 6.13generates nftables rules that partially bypass security optio…
CVE-2025-52889 unknown FIX debian debian 1y ago Incus is a system container and virtual machine manager. When using an ACL on a device connected to a bridge, Incus version 6.12 and 6.13 generates nftables rules for local services (DHCP, DNS...) th…
CVE-2025-6669 low 3.7 3.7 1y ago A vulnerability was found in gooaclok819 sublinkX up to 1.8. It has been declared as problematic. This vulnerability affects unknown code of the file middlewares/jwt.go. The manipulation with the inp…
CVE-2025-52888 unknown 1y ago Allure Report allows Improper XXE Restriction via DocumentBuilderFactory
CVE-2024-54085 unknown 1.5 KEV 1y ago AMI MegaRAC SPx contains an authentication bypass by spoofing vulnerability in the Redfish Host Interface. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integ…
CVE-2024-0769 unknown 1.5 KEV 1y ago D-Link DIR-859 routers contain a path traversal vulnerability in the file /hedwig.cgi of the component HTTP POST Request Handler. Manipulation of the argument service with the input ../../../../htdoc…
CVE-2019-6693 unknown 1.5 KEV 1y ago Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key.
CVE-2025-6536 low 3.3 3.3 debian debian 1y ago A vulnerability has been found in Tarantool up to 3.3.1 and classified as problematic. Affected by this vulnerability is the function tm_to_datetime in the library src/lib/core/datetime.c. The manipu…
CVE-2025-6527 low 3.1 3.1 1y ago A vulnerability, which was classified as problematic, was found in 70mai M300 up to 20250611. Affected is an unknown function of the component Web Server. The manipulation leads to improper access co…
CVE-2025-6524 low 3.1 3.1 1y ago A vulnerability classified as problematic has been found in 70mai 1S up to 20250611. This affects an unknown part of the component Video Services. The manipulation leads to improper authentication. A…
CVE-2025-49574 unknown 1y ago Quarkus potentially leaks data when duplicating a duplicated context
CVE-2025-4563 low 2.5 FIX arch archdebian debian sles 1y ago A vulnerability exists in the NodeRestriction admission controller where nodes can bypass dynamic resource allocation authorization checks. When the DynamicResourceAllocation feature gate is enabled,…
CVE-2025-6509 low 3.5 3.5 1y ago A vulnerability was found in seaswalker spring-analysis up to 4379cce848af96997a9d7ef91d594aa129be8d71. It has been declared as problematic. Affected by this vulnerability is the function echo of the…
CVE-2025-6497 low 3.3 3.3 debian debian 1y ago A vulnerability was found in HTACG tidy-html5 5.8.0. It has been rated as problematic. This issue affects the function prvTidyParseNamespace of the file src/parser.c. The manipulation leads to reacha…
CVE-2025-6496 low 3.3 3.3 debian debian 1y ago A vulnerability was found in HTACG tidy-html5 5.8.0. It has been declared as problematic. This vulnerability affects the function InsertNodeAsParent of the file src/parser.c. The manipulation leads t…