Search

Found 25,458 results in 918ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-6494 low 3.3 3.3 FIX slesdebian debian 1y ago A vulnerability was found in sparklemotion nokogiri c29c920907366cb74af13b4dc2230e9c9e23b833. It has been classified as problematic. This affects the function hashmap_get_with_hash of the file gumbo-…
CVE-2025-6490 low 3.3 3.3 FIX slesdebian debian 1y ago A vulnerability was found in sparklemotion nokogiri c29c920907366cb74af13b4dc2230e9c9e23b833 and classified as problematic. This issue affects the function hashmap_set_with_hash of the file gumbo-par…
CVE-2025-6401 low 3.5 3.5 1y ago A vulnerability was found in TOTOLINK N300RH 6.1c.1390_B20191101. It has been classified as problematic. This affects an unknown part of the file /boafrm/formFilter of the component HTTP POST Message…
CVE-2025-6384 unknown 1y ago Crafter Studio Groovy Sandbox Bypass
CVE-2025-6275 low 3.3 3.3 debian debian webassembly 1y ago A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been declared as problematic. Affected by this vulnerability is the function GetFuncOffset of the file src/interp/binary-reader-inte…
CVE-2025-6274 low 3.3 3.3 debian debian webassembly 1y ago A vulnerability was found in WebAssembly wabt up to 1.0.37. It has been classified as problematic. Affected is the function OnDataCount of the file src/interp/binary-reader-interp.cc. The manipulatio…
CVE-2025-6273 low 3.3 3.3 debian debian webassembly 1y ago A vulnerability was found in WebAssembly wabt up to 1.0.37 and classified as problematic. This issue affects the function LogOpcode of the file src/binary-reader-objdump.cc. The manipulation leads to…
CVE-2025-6272 low 3.3 3.3 wasm3_project 1y ago A vulnerability has been found in wasm3 0.5.0 and classified as problematic. This vulnerability affects the function MarkSlotAllocated of the file source/m3_compile.c. The manipulation leads to out-o…
CVE-2025-6271 low 3.3 3.3 swftools 1y ago A vulnerability, which was classified as problematic, was found in swftools up to 0.9.2. This affects the function wav_convert2mono in the library lib/wav.c of the component wav2swf. The manipulation…
CVE-2025-48059 unknown 1y ago PowSyBl Core Contains a Polynomial ReDoS in RegexCriterion
CVE-2025-48058 unknown 1y ago PowSyBl Core contains Polynomial REDoS’es
CVE-2025-47771 unknown 1y ago PowSyBl Core allows deserialization of untrusted SparseMatrix data
CVE-2025-47293 unknown 1y ago PowSyBl Core XML Reader allows XXE and SSRF
CVE-2025-32896 unknown 1y ago Apache SeaTunnel: Unauthenticated insecure access
CVE-2022-49957 unknown FIX slesdebian debian 1y ago In the Linux kernel, the following vulnerability has been resolved: kcm: fix strp_init() order and cleanup strp_init() is called just a few lines above this csk->sk_user_data check, it also initial…
CVE-2025-3248 unknown 2.5 KEVEXP 1y ago Langflow contains a missing authentication vulnerability in the /api/v1/validate/code endpoint that allows a remote, unauthenticated attacker to execute arbitrary code via crafted HTTP requests.
CVE-2025-6141 low 3.3 3.3 FIX slesdebian debian 1y ago A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipu…
CVE-2025-6140 low 3.3 3.3 FIX slesdebian debian gabime 1y ago A vulnerability, which was classified as problematic, was found in spdlog up to 1.15.1. This affects the function scoped_padder in the library include/spdlog/pattern_formatter-inl.h. The manipulation…
CVE-2025-6139 low 3.9 3.9 1y ago A vulnerability, which was classified as problematic, has been found in TOTOLINK T10 4.1.8cu.5207. Affected by this issue is some unknown functionality of the file /etc/shadow.sample. The manipulatio…
CVE-2025-6170 low 2.5 2.5 FIX arch arch slesdebian debian redhatxmlsoft 1y ago A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, …
CVE-2025-49124 unknown FIX slesdebian debian 1y ago Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects A…
CVE-2025-3594 unknown 1y ago Liferay Portal path traversal vulnerability with the downloading and installation of Xuggler
CVE-2025-3526 unknown 1y ago Liferay Portal SessionClicks does not restrict the saving of request parameters in the HTTP session
CVE-2025-3602 unknown 1y ago Liferay Portal does not limit the depth of a GraphQL queries
CVE-2025-6107 low 3.1 3.1 1y ago A vulnerability was found in comfyanonymous comfyui 0.3.40. It has been classified as problematic. Affected is the function set_attr of the file /comfy/utils.py. The manipulation leads to dynamically…
CVE-2025-43200 unknown 1.5 KEV 1y ago Apple iOS, iPadOS, macOS, watchOS, and visionOS, contain an unspecified vulnerability when processing a maliciously crafted photo or video shared via an iCloud Link.
CVE-2023-33538 unknown 1.5 KEV 1y ago TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm. The impacted products could be end-of-life (EoL) an…
CVE-2025-49585 unknown 1y ago XWiki does not require right warnings for XClass definitions
CVE-2025-49586 unknown 1y ago XWiki allows remote code execution through preview of XClass changes in AWM editor
CVE-2025-49587 unknown 1y ago XWiki does not require right warnings for notification displayer objects
CVE-2025-49584 unknown 1y ago XWiki makes title of inaccessible pages available through the class property values REST API
CVE-2025-49583 unknown 1y ago XWiki provides no warning when granting XWiki.Notifications.Code.NotificationEmailRendererClass admin right
CVE-2025-49581 unknown 1y ago XWiki allows remote code execution through default value of wiki macro wiki-type parameters
CVE-2025-49582 unknown 1y ago XWiki's required right warnings for macros are incomplete
CVE-2025-49580 unknown 1y ago XWiki allows privilege escalation through link refactoring
CVE-2025-6052 low 3.7 3.7 FIX debian debian sles gnome 1y ago A flaw was found in how GLib’s GString manages memory when adding data to strings. If a string is already very large, combining it with more input can cause a hidden overflow in the size calculation.…
CVE-2025-46096 unknown 1y ago Solon Vulnerable to Directory Traversal
CVE-2025-41234 unknown FIX debian debian 1y ago Spring Framework vulnerable to a reflected file download (RFD)
CVE-2024-56158 unknown 1y ago XWiki allows SQL injection in query endpoint of REST API with Oracle
CVE-2025-49146 unknown FIX debian debian sles 1y ago pgjdbc Client Allows Fallback to Insecure Authentication Despite channelBinding=require Configuration
CVE-2025-30220 unknown 1y ago [XBOW-025-068] XML External Entity (XXE) Processing Vulnerability in GeoServer WFS Service
CVE-2025-30145 unknown 1y ago GeoServer Infinite Loop Vulnerability in Jiffle process
CVE-2025-27505 unknown 1y ago GeoServer Missing Authorization on REST API Index
CVE-2024-40625 unknown 1y ago Coverage REST API Server Side Request Forgery
CVE-2024-38524 unknown 1y ago GWC Home Page communicate version and revision information
CVE-2024-34711 unknown 1y ago GeoServer has improper ENTITY_RESOLUTION_ALLOWLIST URI validation in XML Processing (SSRF)
CVE-2024-29198 unknown 1y ago GeoServer Vulnerable to Unauthenticated SSRF via TestWfsPost
CVE-2025-27819 unknown 1y ago Apache Kafka Deserialization of Untrusted Data vulnerability
CVE-2025-27818 unknown 1y ago Apache Kafka Deserialization of Untrusted Data vulnerability
CVE-2025-27817 unknown 1y ago Apache Kafka Client Arbitrary File Read and Server Side Request Forgery Vulnerability
CVE-2025-33053 unknown 2.5 KEVEXP 1y ago Microsoft Windows contains an external control of file name or path vulnerability that could allow an attacker to execute code from a remote WebDAV location specified by the WorkingDirectory attribut…
CVE-2025-5889 low 3.1 3.1 FIX slesdebian debian 1y ago A vulnerability was found in juliangruber brace-expansion up to 1.1.11/2.0.1/3.0.0/4.0.0. It has been rated as problematic. Affected by this issue is the function expand of the file index.js. The man…
CVE-2025-5864 low 3.7 3.7 1y ago A vulnerability was found in Tenda TDSEE App up to 1.7.12. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /app/ConfirmSmsCode of the compo…
CVE-2025-32433 unknown 2.5 KEVEXPFIX debian debian sles 1y ago Erlang Erlang/OTP SSH server contains a missing authentication for critical function vulnerability. This could allow an attacker to execute arbitrary commands without valid credentials, potentially l…
CVE-2024-42009 unknown 1.5 KEVFIX debian debian 1y ago RoundCube Webmail contains a cross-site scripting vulnerability. This vulnerability could allow a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desan…
CVE-2025-49128 unknown FIX debian debian 1y ago Jackson-core Vulnerable to Memory Disclosure via Source Snippet in JsonLocation
CVE-2025-49009 unknown 1y ago Para Inserts Sensitive Information into Log File for Facebook authentication
CVE-2025-5806 unknown 1y ago Jenkins Gatling Plugin Vulnerable to Cross-Site Scripting (XSS)
CVE-2025-27531 unknown 1y ago Apache InLong Deserialization of Untrusted Data Vulnerability
CVE-2025-48432 low 2.5 FIX arch arch slesdebian debian 1y ago An issue was discovered in Django 5.2 before 5.2.3, 5.1 before 5.1.11, and 4.2 before 4.2.23. Internal HTTP response logging does not escape request.path, which allows remote attackers to potentially…
CVE-2025-5419 unknown 1.5 KEVFIX debian debian 1y ago Out of bounds read and write in V8 in Google Chrome prior to 137.0.7151.68 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-35036 unknown debian debian 1y ago Hibernate Validator may interpolate user-supplied input in a constraint violation message with Expression Language
CVE-2025-46548 unknown 1y ago Pekko Management may not properly apply authenticator when Basic Authentication is enabled
CVE-2025-45855 unknown 1y ago Erupt Unrestricted Upload of File with Dangerous Type vulnerability
CVE-2025-48387 unknown FIX debian debianubuntu ubuntu 1y ago tar-fs vulnerabilities
CVE-2025-27038 unknown 1.5 KEV 1y ago Multiple Qualcomm chipsets contain a use-after-free vulnerability. This vulnerability allows for memory corruption while rendering graphics using Adreno GPU drivers in Chrome.
CVE-2025-21480 unknown 1.5 KEV 1y ago Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing spe…
CVE-2025-21479 unknown 1.5 KEV 1y ago Multiple Qualcomm chipsets contain an incorrect authorization vulnerability. This vulnerability allows for memory corruption due to unauthorized command execution in GPU micronode while executing spe…
CVE-2024-8008 unknown 1y ago WSO2 products vulnerable to Cross-site Scripting
CVE-2024-1440 unknown 1y ago WSO2 is vulnerable to Open Redirect through multi-option URL in its authentication endpoint
CVE-2025-3935 unknown 1.5 KEV 1y ago ConnectWise ScreenConnect contains an improper authentication vulnerability. This vulnerability could allow a ViewState code injection attack, which could allow remote code execution if machine keys …
CVE-2023-39780 unknown 1.5 KEV 1y ago ASUS RT-AX55 devices contain an OS command injection vulnerability that could allow a remote, authenticated attacker to execute arbitrary commands. As represented by CVE-2023-41346.
CVE-2021-32030 unknown 1.5 KEV 1y ago ASUS Lyra Mini and ASUS GT-AC2900 devices contain an improper authentication vulnerability that allows an attacker to gain unauthorized access to the administrative interface. The impacted products c…
CVE-2025-48955 unknown 1y ago Para Server Logs Sensitive Information
CVE-2024-7096 unknown 1y ago WSO2 products vulnerable to privilege escalation due to business logic flaw in SOAP admin services
CVE-2025-41235 unknown 1y ago Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies
CVE-2025-48889 unknown 1y ago Gradio Allows Unauthorized File Copy via Path Manipulation
CVE-2025-48881 unknown 1y ago Valtimo backend libraries allows objects in the object-api to be accessed and modified by unauthorized users
CVE-2025-27528 unknown 1y ago Apache InLong: JDBC Vulnerability for Invisible Character Bypass Leading to Arbitrary File Read
CVE-2025-27526 unknown 1y ago Apache InLong: JDBC Vulnerability For URLEncode and backspace bypass
CVE-2025-27522 unknown 1y ago Apache InLong: JDBC Vulnerability during verification processing
CVE-2025-48382 unknown 1y ago Fess has Insecure Temporary File Permissions
CVE-2025-48370 low 2.5 1y ago auth-js Vulnerable to Insecure Path Routing from Malformed User Input
CVE-2025-5138 low 3.5 3.5 1y ago A vulnerability was found in Bitwarden up to 2.25.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component PDF File Handler. The manipulatio…
CVE-2025-4632 unknown 1.5 KEV 1y ago Samsung MagicINFO 9 Server contains a path traversal vulnerability that allows an attacker to write arbitrary file as system authority.
CVE-2025-4949 unknown debian debian sles 1y ago Eclipse JGit XML External Entity (XXE) Vulnerability
CVE-2025-48063 unknown 1y ago XWiki Platform Security Authorization Bridge allows users with just edit right can enforce required rights with programming right
CVE-2025-41232 unknown 1y ago Spring Security authorization bypass for method security annotations on private methods
CVE-2025-4428 unknown 2.5 KEVEXP 1y ago Ivanti Endpoint Manager Mobile (EPMM) contains a code injection vulnerability in the API component that allows an authenticated attacker to remotely execute arbitrary code via crafted API requests. T…
CVE-2025-4427 unknown 2.5 KEVEXP 1y ago Ivanti Endpoint Manager Mobile (EPMM) contains an authentication bypass vulnerability in the API component that allows an attacker to access protected resources without proper credentials via crafted…
CVE-2025-27920 unknown 1.5 KEV 1y ago Srimax Output Messenger contains a directory traversal vulnerability that allows an attacker to access sensitive files outside the intended directory, potentially leading to configuration leakage or …
CVE-2024-27443 unknown 1.5 KEV 1y ago Zimbra Collaboration contains a cross-site scripting (XSS) vulnerability in the CalendarInvite feature of the Zimbra webmail classic user interface. An attacker can exploit this vulnerability via an …
CVE-2024-11182 unknown 1.5 KEV 1y ago MDaemon Email Server contains a cross-site scripting (XSS) vulnerability that allows a remote attacker to load arbitrary JavaScript code via an HTML e-mail message.
CVE-2023-38950 unknown 1.5 KEV 1y ago ZKTeco BioTime contains a path traversal vulnerability in the iclock API that allows an unauthenticated attacker to read arbitrary files via supplying a crafted payload.
CVE-2025-22233 unknown debian debian 1y ago Spring Framework DataBinder Case Sensitive Match Exception
CVE-2025-1975 unknown sles 1y ago Ollama Server Vulnerable to Denial of Service (DoS) Attack
CVE-2025-47783 unknown 1y ago label-studio vulnerable to Cross-Site Scripting (Reflected) via the label_config parameter.
CVE-2025-47279 unknown FIX debian debian 1y ago Undici is an HTTP/1.1 client for Node.js. Prior to versions 5.29.0, 6.21.2, and 7.5.0, applications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server …
CVE-2025-42999 unknown 1.5 KEV 1y ago SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host s…
CVE-2024-12987 unknown 1.5 KEV 1y ago DrayTek Vigor2960, Vigor300B, and Vigor3900 routers contain an OS command injection vulnerability due to an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component web ma…