Search

Found 25,458 results in 6200ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-47889 unknown 1y ago Jenkins WSO2 Oauth Plugin Fails to Properly Authenticate User Credentials
CVE-2025-47888 unknown 1y ago Jenkins DingTalk Plugin Unconditionally Disables SSL/TLS Certificate and Hostname Validation
CVE-2025-47887 unknown 1y ago Jenkins Cadence vManager Plugin is Missing Permission Checks
CVE-2025-47886 unknown 1y ago Jenkins Cadence vManager Plugin Vulnerable to Cross-Site Request Forgery
CVE-2025-47885 unknown 1y ago Jenkins Health Advisor by CloudBees Plugin Vulnerable to Cross-Site Scripting
CVE-2025-47884 unknown 1y ago Jenkins OpenID Connect Provider Plugin Incorrectly Validates Crafted Build ID Tokens
CVE-2025-4641 unknown 1y ago BoniGarcia WebDriverManager Affected By Improper Restriction of XML External Entity Reference
CVE-2025-26864 unknown 1y ago Apache IoTDB Discloses Sensitive Information via Log Files
CVE-2025-26795 unknown 1y ago Apache IoTDB JDBC Driver Discloses Sensitive Information via Log Files
CVE-2024-24780 unknown 1y ago Apache IoTDB Vulnerable to Remote Code Execution
CVE-2025-32756 unknown 1.5 KEV 1y ago Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code or commands via crafted …
CVE-2025-32709 unknown 1.5 KEV 1y ago Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to escalate privileges to administrator.
CVE-2025-32706 unknown 1.5 KEV 1y ago Microsoft Windows Common Log File System (CLFS) Driver contains a heap-based buffer overflow vulnerability that allows an authorized attacker to elevate privileges locally.
CVE-2025-32701 unknown 1.5 KEV 1y ago Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
CVE-2025-30400 unknown 1.5 KEV 1y ago Microsoft Windows DWM Core Library contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
CVE-2025-30397 unknown 2.5 KEVEXP 1y ago Microsoft Windows Scripting Engine contains a type confusion vulnerability that allows an unauthorized attacker to execute code over a network via a specially crafted URL.
CVE-2024-50044 low 3.3 3.3 FIX rhel slesdebian debian 1y ago In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: FIX possible deadlock in rfcomm_sk_state_change rfcomm_sk_state_change attempts to use sock_lock so it must ne…
CVE-2023-4752 low 2.5 FIX rhel sles rocky 1y ago Use After Free in GitHub repository vim/vim prior to 9.0.1858.
CVE-2022-45063 low 2.5 FIX rhel sles rocky 1y ago Low: xterm security update
CVE-2025-47729 unknown 1.5 KEV 1y ago TeleMessage TM SGNL contains a hidden functionality vulnerability in which the archiving backend holds cleartext copies of messages from TM SGNL application users.
CVE-2025-46392 unknown FIX debian debian 1y ago Apache Commons Configuration Uncontrolled Resource Consumption
CVE-2025-47737 unknown 1y ago Unsound issue in Trailer
CVE-2025-1948 unknown FIX debian debian 1y ago Eclipse Jetty HTTP/2 client can force the server to allocate a humongous byte buffer that may lead to OoM and subsequently the JVM to exit
CVE-2024-13009 unknown FIX slesdebian debian 1y ago **UNSUPPORTED WHEN ASSIGNED** GzipHandler causes part of request body to be seen as request body of a separate request
CVE-2025-44021 unknown FIX debian debian 1y ago OpenStack Ironic before 29.0.1 can write unintended files to a target node disk during image handling (if a deployment was performed via the API). A malicious project assigned as a node owner can pro…
CVE-2025-35939 unknown 1.5 KEV 1y ago Craft CMS contains an external control of assumed-immutable web parameter vulnerability. This vulnerability could allow an unauthenticated client to introduce arbitrary values, such as PHP code, to a…
CVE-2025-46827 unknown 1y ago Graylog Allows Session Takeover via Insufficient HTML Sanitization
CVE-2025-27533 unknown 1.0 EXPFIX debian debian 1y ago Apache ActiveMQ: Unchecked buffer length can cause excessive memory allocation
CVE-2025-46551 unknown 1y ago JRuby-OpenSSL has hostname verification disabled by default
CVE-2024-6047 unknown 1.5 KEV 1y ago Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacted products could be…
CVE-2024-11120 unknown 1.5 KEV 1y ago Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacted products could be…
CVE-2025-2901 unknown 1y ago HAL Cross Site Scripting (XSS) vulnerability of user input when storing it in a data store
CVE-2025-4388 unknown 1y ago Liferay Portal Reflected XSS in marketplace-app-manager-web
CVE-2025-46762 unknown 1y ago Apache Parquet Java: Potential malicious code execution from trusted packages in the parquet-avro module when reading an Avro schema from a Parquet file metadata
CVE-2025-45616 unknown 1y ago BRCC Incorrect Access Control vulnerability
CVE-2025-29573 unknown 1y ago Mezzanine CMS Cross-Site Scripting (XSS) vulnerability
CVE-2025-2905 unknown 1y ago WSO2 API Manager XML External Entity (XXE) vulnerability
CVE-2025-34028 unknown 1.5 KEV 1y ago Commvault Command Center contains a path traversal vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code.
CVE-2024-52979 unknown 1y ago Elasticsearch Uncontrolled Resource Consumption Vulnerability
CVE-2023-44221 unknown 1.5 KEV 1y ago SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management interface that allows a remote, authenticated attacker with administrative privilege to inject arbi…
CVE-2025-3910 unknown 1y ago Keycloak vulnerable to two factor authentication bypass
CVE-2025-3501 unknown 1y ago Keycloak hostname verification
CVE-2025-46558 unknown 1y ago org.xwiki.contrib.markdown:syntax-markdown-commonmark12 vulnerable to XSS via Markdown content
CVE-2025-46557 unknown 1y ago Any user with view access to the XWiki space can change the authenticator
CVE-2025-46554 unknown 1y ago XWiki missing authorization when accessing the wiki level attachments list and metadata via REST API
CVE-2025-32974 unknown 1y ago org.xwiki.platform:xwiki-platform-security-requiredrights-default required rights analysis doesn't consider TextAreas with default content type
CVE-2025-32973 unknown 1y ago org.xwiki.platform:xwiki-platform-component-wiki provides no warning when granting XWiki.ComponentClass programming right
CVE-2025-32972 unknown 1y ago The lesscss script service allows cache clearing without programming right
CVE-2025-32971 unknown 1y ago Solr script service doesn't take dropped programming right into account
CVE-2025-32970 unknown 1y ago org.xwiki.platform:xwiki-platform-wysiwyg-api Open Redirect vulnerability
CVE-2025-31324 unknown 1.5 KEV 1y ago SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.
CVE-2025-22235 unknown 1y ago Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed
CVE-2025-42599 unknown 1.5 KEV 1y ago Qualitia Active! Mail contains a stack-based buffer overflow vulnerability that allows a remote, unauthenticated attacker to execute arbitrary or trigger a denial-of-service via a specially crafted r…
CVE-2025-3928 unknown 1.5 KEV 1y ago Commvault Web Server contains an unspecified vulnerability that allows a remote, authenticated attacker to create and execute webshells.
CVE-2025-1976 unknown 1.5 KEV 1y ago Broadcom Brocade Fabric OS contains a code injection vulnerability that allows a local user with administrative privileges to execute arbitrary code with full root privileges.
CVE-2025-3986 unknown 1y ago Apereo CAS has inefficient regular expression complexity
CVE-2025-3985 unknown 1y ago Apereo CAS has inefficient regular expression complexity
CVE-2025-3984 unknown 1y ago Apereo CAS code injection vulnerability
CVE-2025-46653 low 3.1 3.1 FIX debian debian node-formidable 1y ago Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as not "cryptographic…
CVE-2025-32432 unknown 2.5 KEVEXP 1y ago Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.
CVE-2025-27820 unknown FIX debian debian sles 1y ago Apache HttpClient disables domain checks
CVE-2025-46394 low 3.2 3.2 FIX arch archdebian debian sles busybox 1y ago In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences.
CVE-2025-32969 unknown 1y ago org.xwiki.platform:xwiki-platform-rest-server allows SQL injection in query endpoint of REST API
CVE-2025-32968 unknown 1y ago org.xwiki.platform:xwiki-platform-oldcore allows SQL injection in short form select requests through the script query API
CVE-2025-32961 unknown 1y ago XSS in the /download Endpoint of the JPA Web API
CVE-2025-32960 unknown 1y ago XSS in the /files Endpoint of the Generic REST API
CVE-2025-32959 unknown 1y ago Cuba has a DoS in the File Storage
CVE-2025-32952 unknown 1y ago io.jmix.localfs:jmix-localfs affected by DoS in the Local File Storage
CVE-2025-32951 unknown 1y ago io.jmix.rest:jmix-rest allows XSS in the /files Endpoint of the Generic REST API
CVE-2025-24016 unknown 2.5 KEVEXP 1y ago Wazuh contains a deserialization of untrusted data vulnerability that allows for remote code execution on Wazuh servers.
CVE-2025-32950 unknown 1y ago io.jmix.localfs:jmix-localfs has a Path Traversal in Local File Storage
CVE-2025-29287 unknown 1y ago MCMS allows arbitrary file uploads in the ueditor component
CVE-2024-42699 unknown 1y ago OpenCMS Cross-Site Scripting vulnerability
CVE-2024-41446 unknown 1y ago OpenCMS cross-site scripting (XSS) vulnerability
CVE-2025-43973 unknown FIX debian debian 1y ago An issue was discovered in GoBGP before 3.35.0. pkg/packet/rtr/rtr.go does not verify that the input length corresponds to a situation in which all bytes are available for an RTR message.
CVE-2025-43972 unknown FIX debian debian 1y ago An issue was discovered in GoBGP before 3.35.0. An attacker can cause a crash in the pkg/packet/bgp/bgp.go flowspec parser by sending fewer than 20 bytes in a certain context.
CVE-2025-43971 unknown FIX debian debian 1y ago An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value for softwareVersionLen.
CVE-2025-43970 unknown FIX debian debian 1y ago An issue was discovered in GoBGP before 3.35.0. pkg/packet/mrt/mrt.go does not properly check the input length, e.g., by ensuring that there are 12 bytes or 36 bytes (depending on the address family).
CVE-2024-41447 unknown 1y ago Alkacon OpenCMS stored cross-site scripting (XSS) vulnerability
CVE-2025-32434 unknown FIX debian debian 1y ago PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built on a tape-based autograd system. In version 2.5.1 and prior, a Remote Command …
CVE-2024-55238 unknown 1y ago OpenMetadata SQL Injection
CVE-2025-3760 unknown 1y ago Liferay Cross-site Scripting vulnerability
CVE-2025-31201 unknown 1.5 KEV 1y ago Apple iOS, iPadOS, macOS, and other Apple products contain an arbitrary read and write vulnerability that allows an attacker to bypass Pointer Authentication.
CVE-2025-31200 unknown 1.5 KEV 1y ago Apple iOS, iPadOS, macOS, and other Apple products contain a memory corruption vulnerability that allows for code execution when processing an audio stream in a maliciously crafted media file.
CVE-2025-24054 unknown 2.5 KEVEXP 1y ago Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-3730 unknown FIX debian debian 1y ago A vulnerability, which was classified as problematic, was found in PyTorch 2.6.0. Affected is the function torch.nn.functional.ctc_loss of the file aten/src/ATen/native/LossCTC.cpp. The manipulation …
CVE-2025-22872 unknown FIX debian debian sles 1y ago The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly…
CVE-2025-32783 unknown 1y ago Unregistered users can see "public" messages from a closed wiki via notifications from a different wiki
CVE-2021-20035 unknown 1.5 KEV 1y ago SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user, whic…
CVE-2025-30215 unknown FIX debian debian 1y ago NATS Server may fail to authorize certain Jetstream admin APIs
CVE-2025-3573 unknown FIX debian debian 1y ago Versions of the package jquery-validation before 1.20.0 are vulnerable to Cross-site Scripting (XSS) in the showLabel() function, which may take input from a user-controlled placeholder value. This v…
CVE-2025-3588 unknown 1y ago jsonschema2pojo has Improper Restriction of Operations within the Bounds of a Memory Buffer
CVE-2025-3549 low 3.3 3.3 FIX debian debian sles assimp 1y ago A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD3Importer::ValidateSurfaceHeaderOffsets of the file code/Ass…
CVE-2025-3548 low 3.3 3.3 FIX debian debian sles assimp 1y ago A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp up to 5.4.3. This issue affects the function aiString::Set in the library include/assimp/types.h …
CVE-2025-32205 low 2.7 2.7 1y ago Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in piotnetdotcom Piotnet Forms piotnetforms.This issue affects Piotnet Forms: from n/a through <= 1.0.30.
CVE-2024-58136 unknown 1.5 KEV 1y ago Yii Framework contains an improper protection of alternate path vulnerability that may allow a remote attacker to execute arbitrary code. This vulnerability could affect other products that implement…
CVE-2025-27391 unknown 1y ago Apache ActiveMQ Artemis Vulnerable to Insertion of Sensitive Information into Log File
CVE-2025-31672 unknown debian debian 1y ago Apache POI OOXML Vulnerable to Improper Input Validation in OOXML File Parsing
CVE-2025-30677 unknown 1y ago Apache Pulsar Kafka Connector Logs Sensitive Information in Application Logs
CVE-2024-52981 unknown 1y ago Elasticsearch Vulnerable to Stack Overflow due to a Large Recursion