Search

Found 4,380 results in 206ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2026-22409 low 3.8 3.8 4mo ago Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Justicia justicia allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Justicia: …
CVE-2026-22407 low 3.8 3.8 4mo ago Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Roam roam allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Roam: from n/a thr…
CVE-2026-22406 low 3.8 3.8 4mo ago Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Overton overton allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Overton: fro…
CVE-2026-22404 low 3.8 3.8 4mo ago Authorization Bypass Through User-Controlled Key vulnerability in Mikado-Themes Innovio innovio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Innovio: fro…
CVE-2026-21947 low 3.1 3.1 FIX slesdebian debian oracle 4mo ago Vulnerability in Oracle Java SE (component: JavaFX). Supported versions that are affected are Oracle Java SE: 8u471-b50. Difficult to exploit vulnerability allows unauthenticated attacker with netwo…
CVE-2026-1197 low 3.1 3.1 mineadmin 5mo ago A vulnerability was detected in MineAdmin 1.x/2.x. Affected by this vulnerability is an unknown functionality of the file /system/downloadById. Performing a manipulation of the argument ID results in…
CVE-2026-1161 low 3.5 3.5 5mo ago A vulnerability was detected in pbrong hrms 1.0.1. The affected element is the function UpdateRecruitmentById of the file /handler/recruitment.go. The manipulation results in cross site scripting. Th…
CVE-2026-1136 low 3.5 3.5 5mo ago A weakness has been identified in lcg0124 BootDo up to e93dd428ef6f5c881aa74d49a2099ab0cf1e0fcb. Affected is the function Save of the file /blog/bContent/save of the component ContentController. This…
CVE-2025-15535 low 3.3 3.3 5mo ago A security flaw has been discovered in nicbarker clay up to 0.14. This affects the function Clay__MeasureTextCached in the library clay.h. The manipulation results in null pointer dereference. The at…
CVE-2025-15506 low 3.3 3.3 debian debian 5mo ago AcademySoftwareFoundation OpenColorIO has an out-of-bounds vulnerability
CVE-2025-15505 low 2.4 2.4 5mo ago A vulnerability was found in Luxul XWR-600 up to 4.0.1. The affected element is an unknown function of the component Web Administration Interface. The manipulation of the argument Guest Network/Wirel…
CVE-2026-0824 low 3.5 3.5 5mo ago QuestDB UI's Web Console is Vulnerable to Cross-Site Scripting
CVE-2026-22597 low 2.7 2.7 ghost 5mo ago Ghost has SSRF via External Media Inliner
CVE-2025-15454 low 3.1 3.1 5mo ago A vulnerability was detected in zhanglun lettura up to 0.1.22. This issue affects some unknown processing of the file src/components/ArticleView/ContentRender.tsx of the component RSS Handler. The ma…
CVE-2025-15248 low 3.5 3.5 5mo ago A security flaw has been discovered in sunhailin12315 product-review 商品评价系统 up to 91ead6890b4065bb45b7602d0d73348e75cb4639. This affects an unknown part of the component Write a Review. Performing ma…
CVE-2025-69015 low 3.8 3.8 5mo ago Missing Authorization vulnerability in Automattic Crowdsignal Forms crowdsignal-forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Crowdsignal Forms: fro…
CVE-2025-15245 low 3.3 3.3 5mo ago A vulnerability was found in D-Link DCS-850L 1.02.09. Affected is the function uploadfirmware of the component Firmware Update Service. The manipulation of the argument DownloadFile results in path t…
CVE-2025-15244 low 3.7 3.7 phpems 5mo ago A vulnerability has been found in PHPEMS up to 11.0. This impacts an unknown function of the component Purchase Request Handler. The manipulation leads to race condition. The attack may be initiated …
CVE-2025-15242 low 3.1 3.1 phpems 5mo ago A vulnerability was detected in PHPEMS up to 11.0. The impacted element is an unknown function of the component Coupon Handler. Performing a manipulation results in race condition. The attack can be …
CVE-2025-15241 low 3.5 3.5 5mo ago A security vulnerability has been detected in CloudPanel Community Edition up to 2.5.1. The affected element is an unknown function of the file /admin/users of the component HTTP Header Handler. Such…
CVE-2025-15151 low 3.7 3.7 5mo ago A vulnerability was determined in TaleLin Lin-CMS up to 0.6.0. This affects an unknown part of the file /tests/config.py of the component Tests Folder. This manipulation of the argument username/pass…
CVE-2025-15149 low 2.4 2.4 5mo ago A vulnerability has been found in rawchen ecms up to b59d7feaa9094234e8aa6c8c6b290621ca575ded. Affected by this vulnerability is the function updateProductServlet of the file src/servlet/product/upda…
CVE-2025-15141 low 3.1 3.1 halo 5mo ago A vulnerability was determined in Halo up to 2.21.10. This issue affects some unknown processing of the file /actuator of the component Configuration Handler. Executing a manipulation can lead to inf…
CVE-2025-15134 low 3.5 3.5 5mo ago A security flaw has been discovered in yourmaileyes MOOC up to 1.17. This affects the function subreview of the file mooc/controller/MainController.java of the component Submission Handler. Performin…
CVE-2025-15125 low 3.1 3.1 jeecg 5mo ago A security flaw has been discovered in JeecgBoot up to 3.9.0. Affected is the function queryDepartPermission of the file /sys/permission/queryDepartPermission. The manipulation of the argument depart…
CVE-2025-15124 low 3.1 3.1 jeecg 5mo ago A vulnerability was identified in JeecgBoot up to 3.9.0. This impacts the function getParameterMap of the file /sys/sysDepartPermission/list. The manipulation of the argument departId leads to improp…
CVE-2025-15123 low 3.1 3.1 jeecg 5mo ago A vulnerability was determined in JeecgBoot up to 3.9.0. This affects an unknown function of the file /sys/sysDepartPermission/datarule/. Executing manipulation can lead to improper authorization. It…
CVE-2025-15122 low 3.1 3.1 jeecg 5mo ago A vulnerability was found in JeecgBoot up to 3.9.0. The impacted element is the function loadDatarule of the file /sys/sysDepartRole/datarule/. Performing manipulation of the argument departId/roleId…
CVE-2025-15120 low 3.1 3.1 jeecg 5mo ago A flaw has been found in JeecgBoot up to 3.9.0. Impacted is the function getDeptRoleList of the file /sys/sysDepartRole/getDeptRoleList. This manipulation of the argument departId causes improper aut…
CVE-2025-15119 low 3.1 3.1 jeecg 5mo ago A vulnerability was detected in JeecgBoot up to 3.9.0. This issue affects the function queryPageList of the file /sys/sysDepartRole/list. The manipulation of the argument deptId results in improper a…
CVE-2025-15108 low 3.7 3.7 5mo ago A vulnerability was detected in PandaXGO PandaX up to fb8ff40f7ce5dfebdf66306c6d85625061faf7e5. This affects an unknown function of the file config.yml of the component JWT Secret Handler. The manipu…
CVE-2025-15095 low 3.5 3.5 sles 5mo ago A security vulnerability has been detected in postmanlabs httpbin up to 0.6.1. This affects an unknown function of the file httpbin-master/httpbin/core.py. The manipulation leads to cross site script…
CVE-2025-15084 low 3.1 3.1 youlai 5mo ago A vulnerability was identified in youlaitech youlai-mall 1.0.0/2.0.0. The impacted element is the function orderService.payOrder of the file mall-oms/oms-boot/src/main/java/com/youlai/mall/oms/contro…
CVE-2025-15005 low 3.7 3.7 couchcms 5mo ago A security flaw has been discovered in CouchCMS up to 2.4. Affected is an unknown function of the file couch/config.example.php of the component reCAPTCHA Handler. The manipulation of the argument K_…
CVE-2025-14955 low 3.7 3.7 open5gs 6mo ago A vulnerability was found in Open5GS up to 2.7.5. Affected by this vulnerability is the function ogs_pfcp_handle_create_pdr in the library lib/pfcp/handler.c of the component PFCP. The manipulation r…
CVE-2025-14841 low 3.3 3.3 FIX debian debian 6mo ago A flaw has been found in OFFIS DCMTK up to 3.6.9. The impacted element is the function DcmQueryRetrieveIndexDatabaseHandle::startFindRequest/DcmQueryRetrieveIndexDatabaseHandle::startMoveRequest in t…
CVE-2025-14836 low 2.7 2.7 zzcms 6mo ago A flaw has been found in ZZCMS 2025. Affected by this vulnerability is an unknown functionality of the file /reg/user_save.php of the component User Data Storage Module. This manipulation causes clea…
CVE-2025-14722 low 2.4 2.4 6mo ago A vulnerability was determined in vion707 DMadmin up to 3403cafdb42537a648c30bf8cbc8148ec60437d1. This impacts the function Add of the file Admin/Controller/AddonsController.class.php of the componen…
CVE-2025-14697 low 3.7 3.7 6mo ago A security flaw has been discovered in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 4.10.24.3. Affected by this issue is some unknown functionality of the file /ExportFiles…
CVE-2025-14651 low 3.7 3.7 6mo ago A vulnerability has been found in MartialBE one-hub up to 0.14.27. This vulnerability affects unknown code of the file docker-compose.yml. The manipulation of the argument SESSION_SECRET leads to use…
CVE-2025-14636 low 3.7 3.7 6mo ago A security flaw has been discovered in Tenda AX9 22.03.01.46. This affects the function image_check of the component httpd. The manipulation results in use of weak hash. It is possible to launch the …
CVE-2025-14538 low 3.5 3.5 6mo ago A security vulnerability has been detected in yangshare warehouseManager 仓库管理系统 1.1.0. This affects the function addCustomer of the file CustomerManageHandler.java. Such manipulation of the argument …
CVE-2025-13127 low 3.5 3.5 6mo ago Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in TAC Information Services Internal and External Trade Inc. GoldenHorn allows Cross-Site Scr…
CVE-2025-64787 low 3.3 3.3 macos macos adobe 6mo ago Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could r…
CVE-2025-64786 low 3.3 3.3 macos macos adobe 6mo ago Acrobat Reader versions 24.001.30264, 20.005.30793, 25.001.20982, 24.001.30273, 20.005.30803 and earlier are affected by an Improper Verification of Cryptographic Signature vulnerability that could r…
CVE-2025-64254 low 2.7 2.7 6mo ago Missing Authorization vulnerability in Ronald Huereca Photo Block photo-block allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Photo Block: from n/a through …
CVE-2025-14228 low 3.5 3.5 6mo ago A weakness has been identified in Yealink SIP-T21P E2 52.84.0.15. Impacted is an unknown function of the component Local Directory Page. This manipulation causes cross site scripting. It is possible …
CVE-2025-14186 low 3.5 3.5 6mo ago A security flaw has been discovered in Grandstream GXP1625 1.0.7.4. The impacted element is an unknown function of the file /cgi-bin/api.values.post of the component Network Status Page. Performing m…
CVE-2025-13805 low 3.7 3.7 6mo ago NutzBoot vulnerable to deserialization
CVE-2025-13795 low 2.4 2.4 6mo ago A weakness has been identified in codingWithElias School Management System up to f1ac334bfd89ae9067cc14dea12ec6ff3f078c01. Affected is an unknown function of the file /student-view.php of the compone…
CVE-2025-6666 low 2.0 2.0 6mo ago A vulnerability was determined in motogadget mo.lock Ignition Lock up to 20251125. Affected by this vulnerability is an unknown functionality of the component NFC Handler. Executing manipulation can …
CVE-2025-66382 low 2.9 2.9 debian debian sles libexpat_project 6mo ago In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.
CVE-2025-13584 low 3.5 3.5 6mo ago A security vulnerability has been detected in Eigenfocus up to 1.4.0. This vulnerability affects unknown code of the component Description Handler. The manipulation of the argument entry.description/…
CVE-2025-65111 low 2.5 7mo ago SpiceDB: LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete Results
CVE-2025-13232 low 3.5 3.5 7mo ago A flaw has been found in projectsend up to r1720. Impacted is an unknown function of the component File Editor/Custom Download Aliases. This manipulation causes cross site scripting. The attack is po…
CVE-2025-64529 low 2.5 7mo ago SpiceDB WriteRelationships fails silently if payload is too big
CVE-2024-56433 low 2.5 rhel rockydebian debian 7mo ago Low: shadow-utils security update
CVE-2025-12919 low 3.7 3.7 evershop 7mo ago EverShop is vulnerable to Unauthorized Order Information Access (IDOR)
CVE-2025-12854 low 3.7 3.7 7mo ago A vulnerability was identified in newbee-mall-plus up to 2.4.1. This vulnerability affects the function executeSeckill of the file /seckillExecution/. The manipulation of the argument userid leads to…
CVE-2025-64481 low 2.5 7mo ago Datasette is an open source multi-tool for exploring and publishing data. In versions 0.65.1 and below and 1.0a0 through 1.0a19, deployed instances of Datasette include an open redirect vulnerability…
CVE-2025-12623 low 3.1 3.1 7mo ago A vulnerability was identified in fushengqian fuint up to 41e26be8a2c609413a0feaa69bdad33a71ae8032. Affected by this issue is some unknown functionality of the file fuint-application/src/main/java/co…
CVE-2025-12251 low 3.5 3.5 7mo ago A vulnerability has been found in OpenWGA 7.11.12 Build 737. This impacts an unknown function of the component Admin UI. The manipulation leads to cross site scripting. The attack can be initiated re…
CVE-2025-12224 low 3.5 3.5 7mo ago A flaw has been found in Iqbolshoh php-business-website up to 10677743a8dfc281f85291a27cf63a0bce043c24. This vulnerability affects unknown code of the file admin/contact.php. This manipulation of the…
CVE-2025-61748 low 3.7 3.7 FIX rhel slesdebian debian oracle 8mo ago RHSA-2025:18824: java-21-openjdk security update (Moderate)
CVE-2025-11945 low 3.5 3.5 8mo ago A vulnerability was identified in toeverything AFFiNE up to 0.24.1. This vulnerability affects unknown code of the component Avatar Upload Image Endpoint. Such manipulation leads to cross site script…
CVE-2025-11851 low 3.5 3.5 8mo ago A vulnerability has been found in Apeman ID71 EN75.8.53.20. The affected element is an unknown function of the file /set_alias.cgi. Such manipulation of the argument alias leads to cross site scripti…
CVE-2025-11731 low 3.1 3.1 FIX slesdebian debian 8mo ago A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during stylesheet parsing. Due to improper type handling, the function may treat an XML d…
CVE-2025-11645 low 2.4 2.4 8mo ago A security vulnerability has been detected in Tomofun Furbo Mobile App up to 7.57.0a on Android. This affects an unknown part of the component Authentication Token Handler. The manipulation leads to …
CVE-2025-11441 low 3.7 3.7 jhumanj 8mo ago A vulnerability was identified in JhumanJ OpnForm up to 1.9.3. The affected element is an unknown function of the component HTTP Header Handler. The manipulation of the argument X-Forwarded-For leads…
CVE-2025-11333 low 2.4 2.4 8mo ago A vulnerability was identified in langleyfcu Online Banking System up to 57437e6400ce0ae240e692c24e6346b8d0c17d7a. This impacts an unknown function of the file /customer_add_action.php of the compone…
CVE-2025-11322 low 3.7 3.7 8mo ago NovoSGA: Manipulation of User Creation Page can lead to weak password requirements
CVE-2025-11308 low 3.5 3.5 8mo ago A vulnerability was identified in Vanderlande Baggage 360 7.0.0. This issue affects some unknown processing of the file /api-addons/v1/messages. Such manipulation of the argument Message leads to cro…
CVE-2025-11283 low 2.4 2.4 frappe 8mo ago A vulnerability was determined in Frappe LMS 2.35.0. This affects an unknown function of the component Course Handler. Executing manipulation of the argument Description can lead to cross site script…
CVE-2025-11280 low 3.7 3.7 frappe 8mo ago A flaw has been found in Frappe LMS 2.35.0. Impacted is an unknown function of the file /files/ of the component Assignment Picture Handler. This manipulation causes direct request. The attack may be…
CVE-2025-11137 low 3.5 3.5 8mo ago A vulnerability has been found in Gstarsoft GstarCAD up to 9.4.0. This affects an unknown function of the component File Renaming Handler. The manipulation leads to cross site scripting. The attack m…
CVE-2025-11134 low 2.4 2.4 8mo ago A security vulnerability has been detected in Cudy TR1200 1.16.3-20230804-164635. Impacted is an unknown function of the file /cgi-bin/luci/admin/network/wireless/config/ of the component Wireless Se…
CVE-2025-10949 low 2.4 2.4 8mo ago A vulnerability was found in Changsha Developer Technology iView Editor up to 1.1.1. This impacts an unknown function of the component Markdown Handler. The manipulation results in cross site scripti…
CVE-2025-10909 low 2.4 2.4 8mo ago Mangati NovoSGA XSS vulnerability in /admin
CVE-2017-20200 low 3.7 3.7 8mo ago A vulnerability has been found in Coinomi up to 1.7.6. This issue affects some unknown processing. Such manipulation leads to cleartext transmission of sensitive information. The attack can be launch…
CVE-2025-10823 low 3.3 3.3 debian debian 8mo ago A vulnerability was found in axboe fio up to 3.41. This affects the function str_buffer_pattern_cb of the file options.c. Performing manipulation results in null pointer dereference. The attack must …
CVE-2025-58009 low 3.8 3.8 9mo ago Missing Authorization vulnerability in codepeople CP Multi View Event Calendar cp-multi-view-calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CP Mu…
CVE-2025-10776 low 3.7 3.7 9mo ago A vulnerability was detected in LionCoders SalePro POS up to 5.5.0. This issue affects some unknown processing of the component Login. Performing manipulation results in cleartext transmission of sen…
CVE-2025-10761 low 3.7 3.7 9mo ago A vulnerability has been found in Harness 3.3.0. Affected is an unknown function of the file /api/v1/login of the component Login Endpoint. The manipulation leads to improper restriction of excessive…
CVE-2025-10671 low 3.7 3.7 9mo ago A vulnerability has been found in youth-is-as-pale-as-poetry e-learning 1.0. Impacted is the function encryptSecret of the file e-learning-master\exam-api\src\main\java\com\yf\exam\ability\shiro\jwt\…
CVE-2025-43357 low 3.3 3.3 FIX macos macos 9mo ago This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26, macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe 26…
CVE-2025-10434 low 2.4 2.4 9mo ago A vulnerability was identified in IbuyuCMS up to 2.6.3. Impacted is an unknown function of the file /admin/article.php?a=mod of the component Add Article Page. The manipulation of the argument Title …
CVE-2025-10423 low 3.7 3.7 newbee-mall_project 9mo ago A vulnerability was found in newbee-mall 1.0. Impacted is the function mallKaptcha of the file /common/mall/kaptcha. The manipulation results in guessable captcha. The attack can be executed remotely…
CVE-2025-10388 low 3.5 3.5 9mo ago A vulnerability was identified in Selleo Mentingo 2025.08.27. This issue affects some unknown processing of the file /api/course/enroll-course of the component Create New Course Basic Settings. Such …
CVE-2025-10340 low 3.5 3.5 9mo ago A vulnerability was determined in WhatCD Gazelle up to 63b337026d49b5cf63ce4be20fdabdc880112fa3. The affected element is an unknown function of the file /sections/tools/managers/change_log.php of the…
CVE-2025-10320 low 3.1 3.1 9mo ago A vulnerability was detected in iteachyou Dreamer CMS up to 4.1.3.2. This issue affects some unknown processing of the file /admin/user/updatePwd. Performing manipulation results in weak password req…
CVE-2025-10287 low 3.1 3.1 9mo ago A vulnerability has been found in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. The affected element is an unknown function of the file /auth/orderQuery. Such manipulation of the …
CVE-2025-10255 low 3.5 3.5 9mo ago A vulnerability was determined in Ascensio System SIA OnlyOffice up to 12.7.0. Impacted is an unknown function of the file /Products/Projects/Messages.aspx of the component Comment Handler. Executing…
CVE-2025-10254 low 3.5 3.5 9mo ago A vulnerability was found in Ascensio System SIA OnlyOffice up to 12.7.0. This issue affects some unknown processing of the file /Products/Projects/Messages.aspx of the component SVG Image Handler. P…
CVE-2025-10253 low 3.5 3.5 9mo ago A vulnerability has been found in openDCIM 23.04. This vulnerability affects unknown code of the file /scripts/uploadifive.php of the component SVG File Handler. Such manipulation of the argument Fil…
CVE-2025-10252 low 3.1 3.1 9mo ago A flaw has been found in SEAT Queue Ticket Kiosk up to 20250827. This affects an unknown part of the component Java RMI Registry Handler. This manipulation causes deserialization. The attack can only…
CVE-2025-10246 low 3.5 3.5 9mo ago A weakness has been identified in lokibhardwaj PHP-Code-For-Unlimited-File-Upload up to 124fe96324915490c81eaf7db3234b0b4e4bab3c. This affects an unknown part of the file /f.php. This manipulation of…
CVE-2025-10216 low 2.6 2.6 9mo ago A vulnerability was detected in GrandNode up to 2.3.0. The impacted element is an unknown function of the file /checkout/ConfirmOrder/ of the component Voucher Handler. The manipulation of the argume…
CVE-2025-10080 low 3.1 3.1 9mo ago A vulnerability has been found in running-elephant Datart up to 1.0.0-rc3. Affected by this issue is the function getTokensecret of the file datart/security/src/main/java/datart/security/util/AESUtil…
CVE-2025-10014 low 3.1 3.1 eladmin 9mo ago A flaw has been found in elunez eladmin up to 2.7. This impacts the function updateUserEmail of the file /api/users/updateEmail/ of the component Email Address Handler. Executing manipulation of the …
CVE-2025-7039 low 3.7 3.7 FIX debian debian sles 9mo ago A flaw was found in glib. An integer overflow during temporary file creation leads to an out-of-bounds memory access, allowing an attacker to potentially perform path traversal or access private temp…