Search

Found 34,069 results in 3769ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-40250 unknown FIX slesdebian debianubuntu ubuntu 6mo ago Linux kernel (Xilinx) vulnerabilities
CVE-2025-14004 critical 9.8 9.8 xunruicms 6mo ago A security flaw has been discovered in dayrui XunRuiCMS up to 4.7.1. Affected is an unknown function of the file /admind45f74adbd95.php?c=email&m=add of the component Email Setting Handler. Performin…
CVE-2025-40214 unknown FIX slesdebian debian 6mo ago In the Linux kernel, the following vulnerability has been resolved: af_unix: Initialise scc_index in unix_add_edge(). Quang Le reported that the AF_UNIX GC could garbage-collect a receive queue of …
CVE-2024-3884 unknown debian debian 6mo ago Undertow OutOfMemory when parsing form data encoding with application/x-www-form-urlencoded
CVE-2025-55182 unknown 2.5 KEVEXP aws 6mo ago Meta React Server Components contains a remote code execution vulnerability that could allow unauthenticated remote code execution by exploiting a flaw in how React decodes payloads sent to React Ser…
CVE-2025-66453 unknown slesdebian debian 6mo ago Rhino has high CPU usage and potential DoS when passing specific numbers to `toFixed()` function
CVE-2025-65955 unknown FIX debian debian sles 6mo ago ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests …
CVE-2025-13472 unknown 6mo ago BlazeMeter Jenkins Plugin is Missing Authorization for Available Resources
CVE-2021-26828 unknown 1.5 KEV 6mo ago OpenPLC ScadaBR contains an unrestricted upload of file with dangerous type vulnerability that allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm.
CVE-2025-61727 unknown FIX debian debian sles 6mo ago An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certificate. For example a constraint that excludes the subdomain test.example.com doe…
CVE-2025-64460 unknown FIX slesdebian debian 6mo ago Django is vulnerable to DoS via XML serializer text extraction
CVE-2025-13372 unknown FIX slesdebian debian 6mo ago Django is vulnerable to SQL injection in column aliases
CVE-2025-10939 unknown 6mo ago Keycloak unable to restrict access to the admin console
CVE-2025-11538 unknown 6mo ago Keycloak has debug default bind address
CVE-2025-48633 unknown 1.5 KEV 6mo ago Android Framework contains an unspecified vulnerability that allows for information disclosure.
CVE-2025-48572 unknown 1.5 KEV 6mo ago Android Framework contains an unspecified vulnerability that allows for privilege escalation.
CVE-2025-55749 unknown 6mo ago XWiki Jetty Package (XJetty) allows accessing any application file through URL
CVE-2025-64775 unknown 6mo ago Apache Struts is Vulnerable to DoS via File Leak
CVE-2025-13815 critical 9.8 9.8 mogublog_project 6mo ago A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an unknown function of the file /file/pictures. This manipulation of the argument filedatas causes unrestr…
CVE-2025-13814 critical 9.8 9.8 mogublog_project 6mo ago A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the function LocalFileServiceImpl.uploadPictureByUrl of the file /file/uploadPicsByUrl. The manipulation results …
CVE-2025-13806 critical 9.8 9.8 nutzam 6mo ago NutzBoot Incorrect Privilege Assignment vulnerability
CVE-2025-13800 critical 9.8 9.8 6mo ago A vulnerability was found in ADSLR NBR1005GPEV2 250814-r037c. This issue affects the function set_mesh_disconnect of the file /send_order.cgi. The manipulation of the argument mac results in command …
CVE-2025-13799 critical 9.8 9.8 6mo ago A vulnerability has been found in ADSLR NBR1005GPEV2 250814-r037c. This vulnerability affects the function ap_macfilter_del of the file /send_order.cgi. The manipulation of the argument mac leads to …
CVE-2025-13798 critical 9.8 9.8 6mo ago A flaw has been found in ADSLR NBR1005GPEV2 250814-r037c. This affects the function ap_macfilter_add of the file /send_order.cgi. Executing manipulation of the argument mac can lead to command inject…
CVE-2025-13797 critical 9.8 9.8 6mo ago A vulnerability was detected in ADSLR B-QE2W401 250814-r037c. Affected by this issue is the function parameterdel_swifimac of the file /send_order.cgi. Performing manipulation of the argument del_swi…
CVE-2025-13788 critical 9.8 9.8 chanjet 6mo ago A vulnerability has been found in Chanjet CRM up to 20251106. The impacted element is an unknown function of the file /tools/upgradeattribute.php. The manipulation of the argument gblOrgID leads to s…
CVE-2025-13786 critical 9.8 9.8 wtcms_project 6mo ago A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Impacted is the function fetch of the file /index.php. Performing manipulation of the argument content res…
CVE-2025-13783 critical 9.8 9.8 wtcms_project 6mo ago A security flaw has been discovered in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. This affects the function check/uncheck/delete of the file application/Comment/Controller/Commentad…
CVE-2025-13782 critical 9.8 9.8 wtcms_project 6mo ago A vulnerability was identified in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Affected by this issue is the function delete of the file application/Admin/Controller/SlideController.c…
CVE-2025-12183 unknown debian debian 6mo ago LZ4 Java Compression has Out-of-bounds memory operations which can cause DoS
CVE-2025-66372 unknown 6mo ago Mustangproject allows exfiltrating files via XXE attacks
CVE-2021-26829 unknown 1.5 KEV 6mo ago OpenPLC ScadaBR contains a cross-site scripting vulnerability via system_settings.shtm.
CVE-2025-3261 unknown 6mo ago ThingsBoard allows an authenticated user to upload malicious SVG images
CVE-2025-54057 unknown 6mo ago Apache SkyWalking has a stored XSS vulnerability
CVE-2025-66035 unknown FIX debian debian 6mo ago Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.16, 20.3.14, and 21.0.1, there is a XSRF tok…
CVE-2025-62728 unknown 6mo ago Hive Metastore Server is vulnerable to SQL Injection
CVE-2025-59390 unknown 6mo ago Apache Druid’s Kerberos authenticator uses a weak fallback secret
CVE-2025-66021 unknown 6mo ago OWASP Java HTML Sanitizer is vulnerable to XSS via noscript tag and improper style tag sanitization
CVE-2025-9624 unknown debian debian 6mo ago OpenSearch is vulnerable to DoS via complex query_string inputs
CVE-2025-58360 unknown 2.5 KEVEXP 6mo ago OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accepts XML input through a specific endpoint /geoserver/wms operation…
CVE-2025-21621 unknown 6mo ago GeoServer has a Reflected Cross-Site Scripting (XSS) vulnerability in its WMS GetFeatureInfo HTML format
CVE-2025-65085 critical 9.8 9.8 ashlar 6mo ago A Heap-based Buffer Overflow vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose inform…
CVE-2025-65084 critical 9.8 9.8 ashlar 6mo ago An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information …
CVE-2025-65998 unknown 7mo ago Apache Syncope's AES encryption stores hard-coded passwords in internal database
CVE-2025-13585 critical 9.8 9.8 angeljudesuarez 7mo ago A vulnerability was detected in itsourcecode COVID Tracking System 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument code results in sql injecti…
CVE-2025-13583 critical 9.8 9.8 carmelo 7mo ago A weakness has been identified in code-projects Question Paper Generator 1.0. This affects an unknown part of the file /signupscript.php of the component POST Parameter Handler. Executing manipulatio…
CVE-2025-13582 critical 9.8 9.8 anisha 7mo ago A security flaw has been discovered in code-projects Jonnys Liquor 1.0. Affected by this issue is some unknown functionality of the file /detail.php of the component GET Parameter Handler. Performing…
CVE-2025-13578 critical 9.8 9.8 code-projects 7mo ago A vulnerability has been found in code-projects Library System 1.0. This affects an unknown function of the file /index.php of the component Login. The manipulation of the argument Username leads to …
CVE-2025-13572 critical 9.8 9.8 projectworlds 7mo ago A vulnerability was identified in projectworlds Advanced Library Management System 1.0. This affects an unknown part of the file /delete_admin.php. The manipulation of the argument admin_id leads to …
CVE-2025-13562 critical 9.8 9.8 7mo ago A vulnerability was identified in D-Link DIR-852 1.00. This issue affects some unknown processing of the file /gena.cgi. Such manipulation of the argument service leads to command injection. The atta…
CVE-2025-13561 critical 9.8 9.8 torrahclef 7mo ago A vulnerability was determined in SourceCodester Company Website CMS 1.0. This vulnerability affects unknown code of the file /admin/index.php. This manipulation of the argument Username causes sql i…
CVE-2025-13560 critical 9.8 9.8 torrahclef 7mo ago A vulnerability was found in SourceCodester Company Website CMS 1.0. This affects an unknown part of the file /admin/reset-password.php. The manipulation of the argument email results in sql injectio…
CVE-2025-13557 critical 9.8 9.8 campcodes 7mo ago A vulnerability has been found in Campcodes Online Polling System 1.0. Affected by this issue is some unknown functionality of the file /registeracc.php. The manipulation of the argument email leads …
CVE-2025-13556 critical 9.8 9.8 campcodes 7mo ago A flaw has been found in Campcodes Online Polling System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/checklogin.php. Executing a manipulation of the argument my…
CVE-2025-13555 critical 9.8 9.8 campcodes 7mo ago A vulnerability was detected in Campcodes School File Management System 1.0. Affected is an unknown function of the file /index.php of the component Login. Performing a manipulation of the argument s…
CVE-2025-13554 critical 9.8 9.8 campcodes 7mo ago A security vulnerability has been detected in Campcodes Supplier Management System 1.0. This impacts an unknown function of the file /index.php of the component Login. Such manipulation of the argume…
CVE-2025-13546 critical 9.8 9.8 ashraf-kabir 7mo ago A vulnerability was detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected by this issue is some unknown functionality of the file /results.php of the compone…
CVE-2025-13544 critical 9.8 9.8 ashraf-kabir 7mo ago A weakness has been identified in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected is an unknown function of the file /customer_register.php. Executing manipulation…
CVE-2025-62609 unknown 7mo ago MLX has Wild Pointer Dereference in load_gguf()
CVE-2025-62608 unknown 7mo ago MLX has heap-buffer-overflow in load()
CVE-2025-13485 critical 9.8 9.8 admerc 7mo ago A security flaw has been discovered in itsourcecode Online File Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=login. The manipulation of the argument …
CVE-2025-61757 unknown 1.5 KEV 7mo ago Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager.
CVE-2025-13451 critical 9.8 9.8 oretnom23 7mo ago A vulnerability was identified in SourceCodester Online Shop Project 1.0. The affected element is an unknown function of the file /action.php. Such manipulation of the argument Search leads to sql in…
CVE-2025-13449 critical 9.8 9.8 oretnom23 7mo ago A vulnerability was found in code-projects Online Shop Project 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument Password results in sql injecti…
CVE-2025-13442 critical 9.8 9.8 7mo ago A security vulnerability has been detected in UTT 进取 750W up to 3.2.2-191225. Affected by this vulnerability is the function system of the file /goform/formPdbUpConfig. Such manipulation of the argum…
CVE-2025-13424 critical 9.8 9.8 campcodes 7mo ago A vulnerability has been found in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /admin/add_product.php. The manipulation of the argument txtProductName leads …
CVE-2025-13422 critical 9.8 9.8 darkseid 7mo ago A vulnerability was detected in freeprojectscodes Sports Club Management System 1.0. The affected element is an unknown function of the file /dashboard/admin/change_s_pwd.php. Performing manipulation…
CVE-2025-47914 unknown FIX debian debian sles 7mo ago SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.
CVE-2025-13421 critical 9.8 9.8 angeljudesuarez 7mo ago A security vulnerability has been detected in itsourcecode Human Resource Management System 1.0. Impacted is an unknown function of the file /src/store/NoticeStore.php. Such manipulation of the argum…
CVE-2025-13420 critical 9.8 9.8 angeljudesuarez 7mo ago A weakness has been identified in itsourcecode Human Resource Management System 1.0. This issue affects some unknown processing of the file /src/store/EventStore.php. This manipulation of the argumen…
CVE-2025-58181 unknown FIX debian debian sles 7mo ago SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.
CVE-2025-13411 critical 9.8 9.8 campcodes 7mo ago A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/admin_football.php. Performing a manipula…
CVE-2025-13410 critical 9.8 9.8 campcodes 7mo ago A vulnerability has been found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected is an unknown function of the file /admin/receipt.php. Such manipulation of the argument tid leads to sql…
CVE-2025-13396 critical 9.8 9.8 carmelogarcia 7mo ago A weakness has been identified in code-projects Courier Management System 1.0. This affects an unknown function of the file /add-office.php. This manipulation of the argument OfficeName causes sql in…
CVE-2025-64408 unknown 7mo ago Apache Causeway vulnerable to deserialization in Java
CVE-2025-10437 critical 9.8 9.8 7mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eksagate Electronic Engineering and Computer Industry Trade Inc. Webpack Management System allows…
CVE-2025-12119 unknown FIX debian debian 7mo ago A mongoc_bulk_operation_t may read invalid memory if large options are passed.
CVE-2025-13223 unknown 1.5 KEVFIX debian debian 7mo ago Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2025-65089 unknown 7mo ago XWiki view file macro: User can view content of office file without view rights on the attachment
CVE-2025-12383 unknown 7mo ago Eclipse Jersey has a Race Condition
CVE-2025-65015 unknown FIX debian debian 7mo ago joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions from 1.3.3 to before 1.3.5 and from 1.4.0 to before 1.4.2, the …
CVE-2025-54990 unknown 7mo ago XWiki AdminTools application doesn't set permissions on the AdminTools space
CVE-2025-13344 critical 9.8 9.8 oretnom23 7mo ago A weakness has been identified in SourceCodester Train Station Ticketing System 1.0. Affected by this vulnerability is an unknown functionality of the file /ajax.php?action=login. This manipulation o…
CVE-2025-13323 critical 9.8 9.8 carmelo 7mo ago A security flaw has been discovered in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown function of the file /listorder.php. Performing manipulation of the argument ID results i…
CVE-2025-58034 unknown 2.5 KEVEXP 7mo ago Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI comman…
CVE-2025-13303 critical 9.8 9.8 carmelogarcia 7mo ago A vulnerability was determined in code-projects Courier Management System 1.0. Affected by this issue is some unknown functionality of the file /search-edit.php. This manipulation of the argument Con…
CVE-2025-13302 critical 9.8 9.8 carmelogarcia 7mo ago A vulnerability was identified in code-projects Courier Management System 1.0. This affects an unknown part of the file /add-new-officer.php. Such manipulation of the argument ManagerName leads to sq…
CVE-2025-13301 critical 9.8 9.8 itsourcecode 7mo ago A vulnerability was found in itsourcecode Web-Based Internet Laboratory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /subject/controller.php. The mani…
CVE-2025-13300 critical 9.8 9.8 itsourcecode 7mo ago A vulnerability has been found in itsourcecode Web-Based Internet Laboratory Management System 1.0. Affected is an unknown function of the file /settings/controller.php. The manipulation leads to sql…
CVE-2025-13299 critical 9.8 9.8 itsourcecode 7mo ago A flaw has been found in itsourcecode Web-Based Internet Laboratory Management System 1.0. This impacts an unknown function of the file /user/controller.php. Executing a manipulation can lead to sql …
CVE-2025-13298 critical 9.8 9.8 itsourcecode 7mo ago A vulnerability was detected in itsourcecode Web-Based Internet Laboratory Management System 1.0. This affects an unknown function of the file /enrollment/controller.php. Performing a manipulation re…
CVE-2025-13297 critical 9.8 9.8 itsourcecode 7mo ago A security vulnerability has been detected in itsourcecode Web-Based Internet Laboratory Management System 1.0. The impacted element is an unknown function of the file /course/controller.php. Such ma…
CVE-2025-13291 critical 9.8 9.8 campcodes 7mo ago A vulnerability was found in Campcodes Supplier Management System 1.0. This affects an unknown part of the file /manufacturer/confirm_order.php. Performing a manipulation of the argument ID results i…
CVE-2025-13285 critical 9.8 9.8 angeljudesuarez 7mo ago A vulnerability was identified in itsourcecode Online Voting System 1.0. The affected element is an unknown function of the file /login.php. Such manipulation of the argument Username leads to sql in…
CVE-2025-13280 critical 9.8 9.8 codeastro 7mo ago A vulnerability was determined in CodeAstro Simple Inventory System 1.0. The impacted element is an unknown function of the file /index.php of the component Login. Executing a manipulation of the arg…
CVE-2025-13277 critical 9.8 9.8 fabian 7mo ago A flaw has been found in code-projects Nero Social Networking Site 1.0. This issue affects some unknown processing of the file /friendsphoto.php. This manipulation of the argument ID causes sql injec…
CVE-2025-65073 unknown FIX debian debian 7mo ago OpenStack Keystone before 26.0.1, 27.0.0, and 28.0.0 allows a /v3/ec2tokens or /v3/s3tokens request with a valid AWS Signature to provide Keystone authorization.
CVE-2025-13272 critical 9.8 9.8 campcodes 7mo ago A vulnerability was identified in Campcodes School Fees Payment Management System 1.0. Affected is an unknown function of the file /manage_course.php. Such manipulation of the argument ID leads to sq…
CVE-2025-13271 critical 9.8 9.8 campcodes 7mo ago A vulnerability was determined in Campcodes School Fees Payment Management System 1.0. This impacts an unknown function of the file /ajax.php?action=login. This manipulation of the argument Username …
CVE-2025-13267 critical 9.8 9.8 jkev 7mo ago A vulnerability was detected in SourceCodester Dental Clinic Appointment Reservation System 1.0. Impacted is an unknown function of the file /success.php. Performing manipulation of the argument user…