Vulnerability Database & Alerts

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
PlatformAffected Version(s)Vulnerability SeverityFull Post ReporterDate
Firefox for iOS< 136URL spoofing via redirectmediumView or DownloadUNDERCODE2025-03-28
Nethermind Juno< 0.12.5Integer OverflowhighView or DownloadUNDERCODE2025-03-29
DataEase<2.10.6Arbitrary File Read/DeserializationcriticalView or DownloadUNDERCODE2025-03-28
Wangmarketv4.10-v5.0CSRFcriticalView or DownloadUNDERCODE2025-03-28
Wangmarketv4.10-v5.0CSRFmediumView or DownloadUNDERCODE2025-03-28
TUF (tough)< 0.20.0Incorrect delegation handlingcriticalView or DownloadUNDERCODE2025-03-29
Vyper<0.4.1Iterator side-effectscriticalView or DownloadUNDERCODE2025-03-28
TUF Client<0.20.0Metadata RollbackcriticalView or DownloadUNDERCODE2025-03-29
PHPGurukul3.3SQL InjectioncriticalView or DownloadUNDERCODE2025-03-28
WordPress≤2.2.16Unauthorized user deletioncriticalView or DownloadUNDERCODE2025-03-28
Node.js<18.16.1, <20.3.1HTTP SmugglingcriticalView or DownloadUNDERCODE2023-06-22
Firefox, Thunderbird< 136Buffer OverflowcriticalView or DownloadUNDERCODE2025-03-28
WordPress≤0.9CSRFmediumView or DownloadUNDERCODE2025-03-28
Vyper<0.4.1DynArray BypasscriticalView or DownloadUNDERCODE2025-03-28
PHPGurukul3.3HTML InjectionmediumView or DownloadUNDERCODE2025-03-28
Vyper<0.4.1Precision ErrormediumView or DownloadUNDERCODE2025-03-28
Code-projects Online SchedulingV1.0Stored XSSmediumView or DownloadUNDERCODE2025-03-28
TUF Repository< 0.20.0Cyclical DelegationcriticalView or DownloadUNDERCODE2025-03-29
WordPress≤ 2.2.16SQL InjectioncriticalView or DownloadUNDERCODE2025-03-28
Firefox/Firefox ESR/Thunderbird122–136 / <128.8Out-of-bounds accesscriticalView or DownloadUNDERCODE2025-03-28
Node.js<1.16.4, 2.0.0-2.1.1, 3.0.0-3.0.6Path TraversalhighView or DownloadUNDERCODE2025-03-27
Stencil<2.3.0Zip SlipmediumView or DownloadUNDERCODE2023-01-15
PHPGurukul Land Record1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-03-28
SeaCMSv13.3RCEcriticalView or DownloadUNDERCODE2025-03-28
Seacms<=13.3SQL InjectioncriticalView or DownloadUNDERCODE2025-03-28
SeaCMS<=13.3SQL InjectioncriticalView or DownloadUNDERCODE2025-03-28
SeaCMSv13.3Remote Code ExecutioncriticalView or DownloadUNDERCODE2025-03-28
Seacms<13.3SQL InjectioncriticalView or DownloadUNDERCODE2025-03-28
Devolutions Server<=2024.3.12Auth bypasscriticalView or DownloadUNDERCODE2025-03-28
Nginx1.25.0-1.25.3HTTP SmugglingcriticalView or DownloadUNDERCODE2023-12-14
Devolutions Server≤ 2024.3.13SSH password exposuremediumView or DownloadUNDERCODE2025-03-28
Node.js12.x, 14.x, 16.xHTTP/2 RCEcriticalView or DownloadUNDERCODE2021-09-29
PublifyStored XSSmediumView or DownloadUNDERCODE2023-01-15
WordPress≤ 2.6.2Arbitrary File DownloadcriticalView or DownloadUNDERCODE2025-03-28
WordPress≤ 0.8.2Reflected XSSmediumView or DownloadUNDERCODE2025-03-28
WordPress≤ 3.1.8Reflected XSSmediumView or DownloadUNDERCODE2025-03-28
WordPress≤ 3.1.8LFIcriticalView or DownloadUNDERCODE2025-03-28
TUF (tough)< 0.20.0Metadata RollbackmediumView or DownloadUNDERCODE2025-03-28
TUF<0.20.0Metadata RollbackcriticalView or DownloadUNDERCODE2025-03-28
AimHub3.25.0DoS via APImediumView or DownloadUNDERCODE2025-03-28
Lunary-AI≤1.6.7Stored XSScriticalView or DownloadUNDERCODE2025-03-28
GitHub.com<1.0.1Path TraversalmoderateView or DownloadUNDERCODE2025-03-28
Apache HTTP Server2.4.49Path Traversal/RCEcriticalView or DownloadUNDERCODE2021-10-05
Cisco ISE3.2, 3.1API auth bypasscriticalh2stylecolorblueView or DownloadUNDERCODE2025-03-28
Cisco ISE3.2, 3.1Stored XSScriticalView or DownloadUNDERCODE2025-03-28
Ollama≤0.3.14Null DereferencecriticalView or DownloadUNDERCODE2025-03-28
WordPress≤ 2.1.7Privilege EscalationcriticalView or DownloadUNDERCODE2025-03-28
Dell Avamar19.4+Token ReusecriticalView or DownloadUNDERCODE2025-03-28
Cisco ISE3.1, 3.2Insecure DeserializationcriticalView or DownloadUNDERCODE2025-03-28
WordPress≤ 2.1.7PHP Object InjectioncriticalView or DownloadUNDERCODE2025-03-28
Node.js12.x - 16.xHTTP/2 RCEcriticalView or DownloadUNDERCODE2021-09-29
Synapse≤1.127.0DoS via malformed eventscriticalView or DownloadUNDERCODE2025-03-27
Pitchfork< 0.11.0HTTP Response SplittingcriticalView or DownloadUNDERCODE2025-03-27
Apache Kylin5.0.0 - 5.0.1SSRFlowView or DownloadUNDERCODE2025-03-27
Mesop<=0.14.0Class PollutioncriticalView or DownloadUNDERCODE2023-11-15
Vega/Vega-lite<5.32.0Prototype Pollution → XSScriticalView or DownloadUNDERCODE2025-03-27
Apache Kylin4.0.0 - 5.0.1Code InjectionlowView or DownloadUNDERCODE2025-03-27
Node.js12.x, 14.x, 16.xRCE via HTTP/2criticalView or DownloadUNDERCODE2021-09-29
MLflow<2.19.0Missing Password EnforcementcriticalView or DownloadUNDERCODE2025-03-27
Dell Chassis Management Controller< 2.40.200.202101130302 (FX2), < 3.41.200.202209300499 (VRTX)Stack-based Buffer OverflowcriticalView or DownloadUNDERCODE2025-03-27
Mattermost10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8MFA BypasscriticalView or DownloadUNDERCODE2025-03-27
Mattermost10.4.x <= 10.4.2Command InjectioncriticalView or DownloadUNDERCODE2025-03-27
Mattermost<=10.4.2, <=10.3.3, <=9.11.8Improper Access ControlmediumView or DownloadUNDERCODE2025-03-27
Mattermost9.11.x <= 9.11.8Privilege EscalationmediumView or DownloadUNDERCODE2025-03-27
OpenSlides<4.2.5Timing attackmediumView or DownloadUNDERCODE2025-03-27
xmedcon0.25.0Integer UnderflowmediumView or DownloadUNDERCODE2025-03-27
OpenSlides<4.2.5Stored XSScriticalView or DownloadUNDERCODE2025-03-27
Vega≤5.30.0Arbitrary JS ExecutioncriticalView or DownloadUNDERCODE2025-03-27
OpenSlides<4.2.5Directory TraversalcriticalView or DownloadUNDERCODE2025-03-27
Mattermost<=10.4.2, <=10.3.3MFA BypasscriticalView or DownloadUNDERCODE2025-03-27
WordPress≤ 3.2.1Unauthenticated feature disablemediumView or DownloadUNDERCODE2025-03-26
Westboy CicadasCMS1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-03-26
WordPress≤5.9.4.5PHP Object InjectionmediumView or DownloadUNDERCODE2025-03-26
WordPress≤5.9.4.7SQL InjectioncriticalView or DownloadUNDERCODE2025-03-26
WordPress≤ 5.9.4.4Missing AuthorizationmediumView or DownloadUNDERCODE2025-03-26
Django<5.3.3XSSlowView or DownloadUNDERCODE2025-03-26
xmas-elf<1.2.0OOB ReadmoderateView or DownloadUNDERCODE2025-03-26
Directus<= 10.11.3Information DisclosurecriticalView or DownloadUNDERCODE2024-06-15
OpenDaylight SFCSodium-SR4 and belowPrivilege EscalationcriticalView or DownloadUNDERCODE2025-03-26
WordPress≤ 2.8.3Stored XSSmediumView or DownloadUNDERCODE2025-03-26
Tenda W18Ev16.01.0.11Stack OverflowcriticalView or DownloadUNDERCODE2025-03-26
Snail-Job1.4.0RCE via DeserializationcriticalView or DownloadUNDERCODE2025-03-26
D-Link DAP-16201.03Stack overflowcriticalView or DownloadUNDERCODE2025-03-26
Westboy CicadasCMS1.0Stored XSSmediumView or DownloadUNDERCODE2025-03-26
Ollama<=0.3.14Resource AllocationhighView or DownloadUNDERCODE2025-03-24
Aimhubio3.25.0Denial of ServicehighView or DownloadUNDERCODE2025-03-22
Aim (aimhubio/aim)3.25.0Uncontrolled Resource ConsumptionhighView or DownloadUNDERCODE2025-03-22
MLflow2.17.0 - 2.20.1CSRF in SignupmoderateView or DownloadUNDERCODE2025-03-21
MLflow2.18Weak Password RequirementslowView or DownloadUNDERCODE2025-03-21
Mattermost<= 10.4.2, <= 10.3.3, <= 9.11.8Improper Access ControlmoderateView or DownloadUNDERCODE2025-03-21
go-httpbinAll versions prior to patchCross-Site Scripting (XSS)criticalView or DownloadUNDERCODE2025-03-21
PipeCDv0.49Privilege EscalationhighView or DownloadUNDERCODE2025-03-21
Go (Golang)Pre-patch versionsDoS via memory exhaustioncriticalView or DownloadUNDERCODE2025-03-21
Mattermost10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8Command Execution in Archived ChannelsmoderateView or DownloadUNDERCODE2025-03-21
Mattermost10.4.0 - 10.4.2, 10.3.0 - 10.3.3, 9.11.0 - 9.11.8, 10.5.0MFA BypasshighView or DownloadUNDERCODE2025-03-21
Mattermost10.4.0 - 10.4.2, 10.3.0 - 10.3.3, 9.11.0 - 9.11.8MFA BypassmoderateView or DownloadUNDERCODE2025-03-21
Mattermost10.4.0 - 10.4.2, 10.3.0 - 10.3.3, 9.11.0 - 9.11.8, 10.5.0Improper Access ControlmoderateView or DownloadUNDERCODE2025-03-21
Linux Kernelnilfs2 file systemUse-After-FreecriticalView or DownloadUNDERCODE2025-02-27
Linux KernelUp to 6.13.0-rc3Use-After-FreecriticalView or DownloadUNDERCODE2025-02-27
Parse Server<4.10.0Authentication BypasscriticalView or DownloadUNDERCODE2025-03-21
AWS CDK CLI>=2.172.0, <2.178.2Credential ExposurecriticalView or DownloadUNDERCODE2025-03-21
Kubernetes1.3.0 to 1.32.3Race ConditionlowView or DownloadUNDERCODE2025-03-21
Liferay Portal/DXP7.4.0 - 7.4.3.126, 2024.Q3.0 - 2024.Q2.12, 2024.Q1.1 - 2024.Q1.12, 2023.Q4.0 - 2023.Q4.10, 2023.Q3.1 - 2023.Q3.10Data ExposuremoderateView or DownloadUNDERCODE2025-03-21
DataEase< 2.10.6Arbitrary File Read/DeserializationcriticalView or DownloadUNDERCODE2025-03-13
DataEase< 2.10.6Authentication BypasscriticalView or DownloadUNDERCODE2025-03-13
Linux KernelPre-commit 68f83057b913Use-After-FreecriticalView or DownloadUNDERCODE2025-02-26
Linux KernelUp to 6.12.0-rc6Use-After-FreecriticalView or DownloadUNDERCODE2025-02-26
Linux KernelUp to 5.15.xUse-After-Free (UAF)criticalView or DownloadUNDERCODE2025-02-26
WordPress1.1.9 and earlierUnauthorized AccesscriticalView or DownloadUNDERCODE2025-03-14
WordPress1.6.11 and belowPrivilege EscalationcriticalView or DownloadUNDERCODE2025-03-14
Envoy Proxy<1.30.10, 1.31.0-1.31.5, 1.32.0-1.32.3, 1.33.0Denial of ServicecriticalView or DownloadUNDERCODE2025-03-21
Redlib< v0.36.0Decompression BombcriticalView or DownloadUNDERCODE2025-03-21
InvokeAI5.3.1 - 5.4.2Remote Code ExecutioncriticalView or DownloadUNDERCODE2025-03-21
LibcontainerPre-fix versionsCapabilities ElevationmoderateView or DownloadUNDERCODE2025-03-21
Next.js11.1.4 - 13.5.6, 14.0 - 14.2.24, 15.0 - 15.2.2Authorization BypasscriticalView or DownloadUNDERCODE2025-03-21
WordPress1.7.6 and earlierSQL InjectioncriticalView or DownloadUNDERCODE2025-03-14
Rembg2.0.57 and earlierCORS MisconfigurationcriticalView or DownloadUNDERCODE2025-03-03
Kedro0.19.8Remote Code ExecutioncriticalView or DownloadUNDERCODE2025-03-21
LocalAIv2.21.1Cross-Site Scripting (XSS)moderateView or DownloadUNDERCODE2025-03-21
ZenML0.66.0Unauthenticated DoShighView or DownloadUNDERCODE2025-03-21
vLLM0.6.0Deserialization RCEcriticalView or DownloadUNDERCODE2025-03-21
Composiov0.4.4SSRFmoderateView or DownloadUNDERCODE2025-03-21
vLLM0.6.0Remote Code ExecutioncriticalView or DownloadUNDERCODE2025-03-21
Quivrv0.0.298Unauthenticated DoShighView or DownloadUNDERCODE2025-03-21
MLflow2.15.1Path TraversalhighView or DownloadUNDERCODE2025-03-21
Composiov0.4.2SSRFmoderateView or DownloadUNDERCODE2025-03-21
LiteLLMv1.52.1API Key LeakagehighView or DownloadUNDERCODE2025-03-20
AimCommit bb76afePath TraversalcriticalView or DownloadUNDERCODE2025-03-20
LiteLLMmain-latestImproper AuthorizationhighView or DownloadUNDERCODE2025-03-20
AgentScopePrior to fixPath TraversalcriticalView or DownloadUNDERCODE2025-03-20
AgentScopev.0.0.4Path TraversalhighView or DownloadUNDERCODE2025-03-20
AgentScopeLatest commit 21161feStored XSSmoderateView or DownloadUNDERCODE2025-03-20
AgentScopev0.0.4Improper CORS ConfigurationhighView or DownloadUNDERCODE2025-03-20
LiteLLM<1.44.12API Key LeakagehighView or DownloadUNDERCODE2025-03-20
LiteLLMv1.44.5Denial of Service (DoS)highView or DownloadUNDERCODE2025-03-20
AgentScope0.0.4Directory TraversalhighView or DownloadUNDERCODE2025-03-20
Gradiogit commit 98cbcaeReDoS via crafted HTTP requesthighView or DownloadUNDERCODE2025-03-20
Gradiogit 98cbcaePath TraversalhighView or DownloadUNDERCODE2025-03-20
Prefect< 3.0.3CORS MisconfigurationhighView or DownloadUNDERCODE2025-03-20
Gradiogit 98cbcaeZip Bomb DoShighView or DownloadUNDERCODE2025-03-20
H2O3.46.0Denial of Service (DoS)highView or DownloadUNDERCODE2025-03-20
LiteLLM1.40.12Remote Code Execution (RCE)criticalView or DownloadUNDERCODE2025-03-20
H2O3.46.0.2Denial of Service (DoS)highView or DownloadUNDERCODE2025-03-20
H2O3.46.1Denial of Service (DoS)highView or DownloadUNDERCODE2025-03-20
H2O3.46.0Arbitrary File OverwritehighView or DownloadUNDERCODE2025-03-20
H2O3.46.0Arbitrary File EncryptionmoderateView or DownloadUNDERCODE2025-03-20
H2O3.46.0.1Denial of Service (DoS)highView or DownloadUNDERCODE2025-03-20
H2O3.46.0.1DoS, File WritehighView or DownloadUNDERCODE2025-03-20
Aim3.23.0Denial of Service (DoS)highView or DownloadUNDERCODE2025-03-20
H2O3.46.0.4Deserialization RCEcriticalView or DownloadUNDERCODE2025-03-20
Horovod<= v0.28.1Command InjectioncriticalView or DownloadUNDERCODE2025-03-20
Dask<=2024.8.2Command InjectioncriticalView or DownloadUNDERCODE2025-03-20
LiteLLMCommit 26c03c9Denial of Service (DoS)highView or DownloadUNDERCODE2025-03-20
kcp<0.26.3, <0.27.0Unauthorized Object ManipulationcriticalView or DownloadUNDERCODE2025-03-20
Coraza WAFv3Rule BypasscriticalView or DownloadUNDERCODE2025-03-20
Redisgo-redis (pre-patch versions)Connection TimeoutcriticalView or DownloadUNDERCODE2025-03-20
Apache Seata2.0.0 - 2.2.0Data AmplificationlowView or DownloadUNDERCODE2025-03-20
Spring Security5.7.0 - 6.4.3Password Length BypasshighView or DownloadUNDERCODE2025-03-20
Apache Seata2.0.0 to 2.2.0Deserialization of Untrusted DatalowView or DownloadUNDERCODE2025-03-20
Liferay Portal/DXP7.4.3.82-7.4.3.128, 2024.Q3.0, 2024.Q2.0-2024.Q2.13, 2024.Q1.1-2024.Q1.12, 2023.Q4.0-2023.Q4.10, 2023.Q3.1-2023.Q3.10XSSmoderateView or DownloadUNDERCODE2025-03-20
OpenShift ConsolePre-4.12.0Path TraversalmoderateView or DownloadUNDERCODE2025-03-20
WordPress2.1.13 and earlierUnauthorized Data AccesscriticalView or DownloadUNDERCODE2025-03-12
OpenShift Hivev1.0.0Uncontrolled Resource ConsumptionmoderateView or DownloadUNDERCODE2025-03-20
Jenkins< 1.0.31.v4aInformation DisclosuremoderateView or DownloadUNDERCODE2025-03-20
WordPress1.0.7 and earlierReflected XSScriticalView or DownloadUNDERCODE2025-03-03
WordPressUp to 2.1.8Stored XSScriticalView or DownloadUNDERCODE2025-02-17
WordPress1.3.8 and priorDOM-based XSScriticalView or DownloadUNDERCODE2025-01-09
JenkinsAnchorChain Plugin 1.0Stored XSShighView or DownloadUNDERCODE2025-03-19
Mattermost9.11.x <= 9.11.8Authorization BypassmoderateView or DownloadUNDERCODE2025-03-19
WordPress<= 1.3.6.5Local File InclusioncriticalView or DownloadUNDERCODE2025-03-11
WordPress<= 4.2.2CSRFcriticalView or DownloadUNDERCODE2025-03-06
WOLF1.0.8.5Path TraversalcriticalView or DownloadUNDERCODE2025-02-03
WordPress<= 4.1.25Stored XSScriticalView or DownloadUNDERCODE2025-01-18
GitHub Actionstj-actions/changed-files < 46Information DisclosurecriticalView or DownloadUNDERCODE2025-03-15
FortiOS, FortiProxy7.0.0 - 7.0.16, 7.2.0 - 7.2.12Authentication BypasscriticalView or DownloadUNDERCODE2025-02-11
RealMag777 BEAR1.1.4.4 and earlierStored XSScriticalView or DownloadUNDERCODE2025-02-17
WordPress<= 1.27.6Path TraversalcriticalView or DownloadUNDERCODE2025-02-06
WikiManager REST API5.4-rc-1 to 16.10.0Privilege EscalationcriticalView or DownloadUNDERCODE2025-03-19
XWiki>= 1.9M1, < 15.10.14Information DisclosurecriticalView or DownloadUNDERCODE2025-03-19
XWiki6.1-rc-1 to 15.10.13, 16.0.0-rc-1 to 16.4.5, 16.5.0-rc-1 to 16.10.0-rc-1Authorization BypasscriticalView or DownloadUNDERCODE2025-03-19
Nuxt.jsAll versionsCache PoisoningcriticalView or DownloadUNDERCODE2025-03-19
WordPress1.27.4 and earlierStored XSScriticalView or DownloadUNDERCODE2025-01-15
CodeBard Help Desk1.1.2 and earlierReflected XSScriticalView or DownloadUNDERCODE2025-01-15
OpenAPI3.0.0Zip Bomb ExploitcriticalView or DownloadUNDERCODE2025-03-19
Sylius<1.6.2, <1.7.2, <2.0.2Payment ManipulationcriticalView or DownloadUNDERCODE2025-03-19
Picklescan< 0.0.23ZIP Archive ManipulationmediumView or DownloadUNDERCODE2025-03-10
PyTorchPickleScan < 0.0.23Arbitrary Code ExecutionmediumView or DownloadUNDERCODE2025-03-10
GitHub Actionsreviewdog/action-setup@v1Secret ExposurecriticalView or DownloadUNDERCODE2025-03-19
vLLMPre-vllm-project/vllm14228Unsafe DeserializationcriticalView or DownloadUNDERCODE2025-03-19
Apache AirflowBefore 6.2.0SQL InjectionmoderateView or DownloadUNDERCODE2025-03-19
Node.jsfast-jwt (affected versions)JWT Issuer Claim ValidationcriticalView or DownloadUNDERCODE2025-03-19
ZipList RecipeUp to 3.1CSRFmediumView or DownloadUNDERCODE2025-03-11
ZTE GoldenDB6.1.03 - 6.1.03.04Privilege EscalationcriticalView or DownloadUNDERCODE2025-03-11
ZTE GoldenDB6.1.03 - 6.1.03.07Privilege EscalationcriticalView or DownloadUNDERCODE2025-03-11
CodeVibrant1.0.5 and earlierCSRFcriticalView or DownloadUNDERCODE2025-03-11
ZTE GoldenDB6.1.03 - 6.1.03.05Privilege EscalationcriticalView or DownloadUNDERCODE2025-03-11
WordPress1.0 and earlierCSRFmediumView or DownloadUNDERCODE2025-03-11
WordPress1.2.2 and earlierCSRFcriticalView or DownloadUNDERCODE2025-03-11
WordPress0.1.0 and earlierCSRF to Stored XSScriticalView or DownloadUNDERCODE2025-03-11
Login Logger1.2.1 and earlierCSRFmediumView or DownloadUNDERCODE2025-03-11
WordPressUp to 2.1CSRF to Stored XSScriticalView or DownloadUNDERCODE2025-03-11
ZTE GoldenDB6.1.03 - 6.1.03.04Input Validation BypasscriticalView or DownloadUNDERCODE2025-03-11
Delete Original Image0.4 and earlierCSRFmediumView or DownloadUNDERCODE2025-03-11
Rankchecker.io Integration1.0.9 and earlierCSRF with Stored XSScriticalView or DownloadUNDERCODE2025-03-11
Mojave InverterAll versionsSensitive Info DisclosurecriticalView or DownloadUNDERCODE2025-02-13
TYPO36.0.0 - 9.2.0XSSmoderateView or DownloadUNDERCODE2025-03-19
CosmWasmPrior to v2.2.0Capability BypassmoderateView or DownloadUNDERCODE2025-03-18
Stesvis Frontpage1.0.2 and earlierCSRFcriticalView or DownloadUNDERCODE2025-03-11
Wire< 5.2.0Uncontrolled RecursionmoderateView or DownloadUNDERCODE2025-03-18
jsPDF<3.0.1DoS via CPU exhaustioncriticalView or DownloadUNDERCODE2025-03-18
Contao4.0.0 - 4.13.53, 5.3.0 - 5.3.29, 5.4.0 - 5.5.5XSS via SVGcriticalView or DownloadUNDERCODE2025-03-18
amoCRM WebForm1.1 and earlierDOM-Based XSScriticalView or DownloadUNDERCODE2025-03-11
Apache HTTP Server2.4.49Path TraversalcriticalView or DownloadUNDERCODE2021-10-05
Apache Tomcat11.0.0-M1 to 11.0.2, 10.1.0-M1 to 10.1.34, 9.0.0.M1 to 9.0.98Path EquivalencecriticalView or DownloadUNDERCODE2025-03-10
Sylius<1.6.1, <1.7.1, <2.0.1Payment ManipulationcriticalView or DownloadUNDERCODE2025-03-17
containerd< 1.7.0, 1.6.0Integer OverflowmoderateView or DownloadUNDERCODE2025-03-17
OpenShift HiveMulticluster Engine (MCE), Advanced Cluster Management (ACM)Credential ExposurehighView or DownloadUNDERCODE2025-03-17
Expr<1.17.0Memory ExhaustioncriticalView or DownloadUNDERCODE2025-03-17
BuildKit< v0.21.3Information DisclosurecriticalView or DownloadUNDERCODE2025-03-17
Mattermost Desktop App<=5.10.0Code InjectionlowView or DownloadUNDERCODE2025-03-17
KubernetesBare Metal Operator (BMO)Secret LeakagecriticalView or DownloadUNDERCODE2025-03-17
Tenda AC9v1.0 V15.03.05.14_multiStack OverflowcriticalView or DownloadUNDERCODE2025-03-14
Tenda AC6v15.03.05.16Buffer OverflowcriticalView or DownloadUNDERCODE2025-03-14
Enituretechnology Small Package QuotesUp to 2.4.9Reflected XSScriticalView or DownloadUNDERCODE2025-03-03
Bee Layer Slider1.1 and earlierStored XSScriticalView or DownloadUNDERCODE2025-03-11
Ark Theme Core1.70.0 and earlierCode InjectioncriticalView or DownloadUNDERCODE2025-03-03
Tenda AC8V4V16.03.34.06Stack OverflowcriticalView or DownloadUNDERCODE2025-02-20
Node.js3.0.0Prototype PollutionhighView or DownloadUNDERCODE2025-03-16
GitHub Actionstj-actions/changed-files <= 45.0.7Information DisclosurehighView or DownloadUNDERCODE2025-03-15
Qiskit< 13Arbitrary Code ExecutioncriticalView or DownloadUNDERCODE2025-03-14
JS Html Sanitizer< 2.0.3XSS BypassmoderateView or DownloadUNDERCODE2025-03-14
feldman_vss<1.0.0Timing Side-ChannelcriticalView or DownloadUNDERCODE2025-03-14
Pythonfeldman_vss.pyFault InjectioncriticalView or DownloadUNDERCODE2025-03-14
Flowise1.8.2Path Traversal to RCEcriticalView or DownloadUNDERCODE2025-03-14
Azle0.27.0, 0.28.0, 0.29.0Infinite LoopcriticalView or DownloadUNDERCODE2025-03-14
KubernetesVersions using in-tree gitRepo volumeLocal repository accessmoderateView or DownloadUNDERCODE2025-03-14
xml-crypto<= 6.0.0Signature BypasscriticalView or DownloadUNDERCODE2025-03-14
Flowisev1.0.0Arbitrary File UploadcriticalView or DownloadUNDERCODE2025-03-13
Linux KernelUp to 5.15.90Use-After-FreecriticalView or DownloadUNDERCODE2025-02-26
Linux KernelPre-5.15.90Use-After-FreecriticalView or DownloadUNDERCODE2025-02-26
Kubernetes<1.29.13, 1.30.0-1.30.9, 1.31.0-1.31.5, 1.32.0-1.32.1Command InjectionmoderateView or DownloadUNDERCODE2025-03-13
Windows NTFSAll versions up to patchInformation DisclosurecriticalView or DownloadUNDERCODE2025-03-11
MODXPrior to 3.1.0Cross-Site Scripting (XSS)lowView or DownloadUNDERCODE2025-03-13
WindowsWin32 Kernel SubsystemUse-after-freecriticalView or DownloadUNDERCODE2025-03-11
Snowflake JDBC3.0.13 - 3.23.0Information DisclosuremediumView or DownloadUNDERCODE2025-03-13
Assimp5.4.3Heap-based Buffer OverflowcriticalView or DownloadUNDERCODE2025-03-10
HDF51.14.6Heap-based Buffer OverflowcriticalView or DownloadUNDERCODE2025-03-10
UnifiedTransform2.0Incorrect Access ControlcriticalView or DownloadUNDERCODE2025-03-10
Microsoft EdgeChromium-basedUI SpoofingcriticalView or DownloadUNDERCODE2025-03-07
Ed25519-Java0.3.0 and earlierSignature MalleabilitymoderateView or DownloadUNDERCODE2025-03-13
XPixelGroup BasicSR1.4.2 and priorCommand InjectionmoderateView or DownloadUNDERCODE2025-03-13
Cosmos SDKPre-v3.1.8Chain HaltcriticalView or DownloadUNDERCODE2025-01-01
Apache HTTP Server2.4.49, 2.4.50Path Traversal to RCEcriticalView or DownloadUNDERCODE2025-03-13
WordPressJavo Core <= 3.0.0.080Privilege EscalationcriticalView or DownloadUNDERCODE2025-03-08
WordPressUp to 16.26.10Information ExposurecriticalView or DownloadUNDERCODE2025-03-08
IBM Aspera Shares1.9.9 - 1.10.0 PL7XXE InjectioncriticalView or DownloadUNDERCODE2025-03-07
DenoAll versionsSession HijackingcriticalView or DownloadUNDERCODE2025-03-12
Golang (golang.org/x/net)Pre-2025 patchesProxy Bypass via IPv6 Zone IDsmoderateView or DownloadUNDERCODE2025-03-12
Apache NiFi1.13.0 - 2.2.0Information DisclosuremoderateView or DownloadUNDERCODE2025-03-12
Apache Felix< 1.2.2XSSmoderateView or DownloadUNDERCODE2025-03-12
Plenti<= 0.7.16Code InjectionmoderateView or DownloadUNDERCODE2025-03-12
Ruby SAML>= 1.13.0, < 1.18.0; < 1.12.4Authentication BypasscriticalView or DownloadUNDERCODE2025-03-12
SmallRye Fault Tolerance< 6.9.0Out-of-Memory (OOM)highView or DownloadUNDERCODE2025-03-12
Apache Camel4.9.0-4.10.2, 4.0.0-4.8.5, 3.10.0-3.22.4Header InjectioncriticalView or DownloadUNDERCODE2025-02-15
Ruby SAML< 1.12.4, >= 1.13.0, < 1.18.0Authentication BypasshighView or DownloadUNDERCODE2025-03-12
Omniauth-saml< 1.10.6, 2.0.0-2.1.2, 2.2.0-2.2.2Signature Wrapping AttackcriticalView or DownloadUNDERCODE2025-03-12
GraphQL-Ruby1.11.5-2.4.13Remote Code ExecutioncriticalView or DownloadUNDERCODE2025-03-12
IBC-Go>= v7Non-deterministic JSON UnmarshallingcriticalView or DownloadUNDERCODE2025-03-12
Cosmos SDK<= v0.47.16, <= 0.50.12Denial of ServicecriticalView or DownloadUNDERCODE2025-03-12
WordPress1.0.9 and earlierUnauthorized Data AccesscriticalView or DownloadUNDERCODE2025-03-07
WordPressUp to 16.26.10SQL InjectioncriticalView or DownloadUNDERCODE2025-03-08
Laravel< 3.4.17File Validation BypassmoderateView or DownloadUNDERCODE2025-03-12
Espressif ESP32All firmware versionsHidden HCI Command ExecutioncriticalView or DownloadUNDERCODE2025-03-08
Ruby2.10.0, 2.10.1Out-of-bounds ReadcriticalView or DownloadUNDERCODE2025-03-12
JoomlaJUX Real Estate 3.4.0Cross-Site Scripting (XSS)mediumView or DownloadUNDERCODE2025-03-09
WordPress<= 5.3.1Stored XSScriticalView or DownloadUNDERCODE2025-03-08
cheqd-node< v3.1.7Non-deterministic JSON UnmarshallingcriticalView or DownloadUNDERCODE2025-03-11
JoomlaJUX Real Estate 3.4.0SQL InjectioncriticalView or DownloadUNDERCODE2025-03-09
Rembg2.0.57 and earlierSSRFmoderateView or DownloadUNDERCODE2025-03-11
PimcorePre-11.0.0SQL InjectioncriticalView or DownloadUNDERCODE2025-03-11
Rembg2.0.57 and earlierCORS MisconfigurationhighView or DownloadUNDERCODE2025-03-11
Facebookincubator/below< 0.9.0Privilege EscalationhighView or DownloadUNDERCODE2025-03-11
WordPress<= 1.39.2Stored XSScriticalView or DownloadUNDERCODE2025-02-27
OpenXEUp to 1.12Cross-Site Scripting (XSS)mediumView or DownloadUNDERCODE2025-03-09
FTCMS2.1Cross-Site Scripting (XSS)mediumView or DownloadUNDERCODE2025-03-09
FTCMS2.1SQL InjectioncriticalView or DownloadUNDERCODE2025-03-09
XunRuiCMSUp to 4.6.3Cross-Site Scripting (XSS)mediumView or DownloadUNDERCODE2025-03-09
Customer Account PortalUnspecifiedHTML InjectionmediumView or DownloadUNDERCODE2025-03-11
Babel<7.26.10, <8.0.0-alpha.17Quadratic ComplexitycriticalView or DownloadUNDERCODE2025-03-11
FroxlorPre-2.0.10Account DuplicationmediumView or DownloadUNDERCODE2023-10-15
Keras< 3.9Arbitrary Code ExecutioncriticalView or DownloadUNDERCODE2025-03-11
GNU Binutils2.43Memory LeakcriticalView or DownloadUNDERCODE2025-02-10
CodeBard Help Desk1.1.2 and earlierStored XSScriticalView or DownloadUNDERCODE2025-01-31
SimpleSAMLphpv4Signature ConfusioncriticalView or DownloadUNDERCODE2025-03-11
ASP.NET Core9.0.2, 8.0.13, 2.3.0Elevation of PrivilegecriticalView or DownloadUNDERCODE2025-03-11
OpenHarmonyv5.0.2 and priorArbitrary Code ExecutioncriticalView or DownloadUNDERCODE2025-03-03
WordPress1.1.9 and earlierStored XSScriticalView or DownloadUNDERCODE2025-02-27
WordPress1.7.2 and earlierAuthentication BypasscriticalView or DownloadUNDERCODE2025-02-27
WordPress1.6.3 and earlierArbitrary File DeletioncriticalView or DownloadUNDERCODE2025-02-27
WordPress1.0.1 and earlierStored XSScriticalView or DownloadUNDERCODE2025-02-27
KerasAll versions prior to 3.0.0Arbitrary Code ExecutioncriticalView or DownloadUNDERCODE2025-03-11
MockoonLatest (mockoon-cli)Path Traversal & LFIcriticalView or DownloadUNDERCODE2025-03-11
WordPress<= 3.3.5Stored XSScriticalView or DownloadUNDERCODE2025-02-27
Umbraco CMS<= 10.8.8, >= 11.0.0-rc1, <= 13.7.0Unauthorized Content Access/DeletionmoderateView or DownloadUNDERCODE2025-03-11
Umbraco CMS14.3.2, 15.0.0-rc1 to 15.2.2Improper API Access ControlmoderateView or DownloadUNDERCODE2025-03-11
KubernetesRatify (pre-patch)Authentication BypasscriticalView or DownloadUNDERCODE2025-03-11
Rack<2.2.6Directory TraversalcriticalView or DownloadUNDERCODE2025-03-10
Apache Tomcat11.0.0-M1 to 11.0.2RCE/Info DisclosurehighView or DownloadUNDERCODE2025-03-10
Concrete CMS9.0.0 - 9.3.9Stored XSSmoderateView or DownloadUNDERCODE2025-03-10
Nomad<1.9.7, <1.8.11, <1.7.19Information ExposuremoderateView or DownloadUNDERCODE2025-03-10
Vela Server< 0.25.3, >= 0.26.0, < 0.26.2Insufficient Webhook Payload VerificationcriticalView or DownloadUNDERCODE2025-03-10
Keycloak>= 26.1.0, < 26.1.3; < 26.0.10Improper AuthorizationmoderateView or DownloadUNDERCODE2025-03-10
Keycloak>= 26.1.0, < 26.1.3; < 26.0.10Authentication BypassmoderateView or DownloadUNDERCODE2025-03-10
Apache Camel3.10.0-3.22.3, 4.2.0-4.8.4, 4.9.0-4.10.1Bypass/InjectioncriticalView or DownloadUNDERCODE2025-03-10
Laravel Framework11.9.0 to 11.35.1Reflected XSSmoderateView or DownloadUNDERCODE2025-03-10
PHP<5.25.2DoS via `explode()`lowView or DownloadUNDERCODE2025-03-10
Laravel Framework11.9.0 - 11.35.1Reflected XSSmoderateView or DownloadUNDERCODE2025-03-10
EkuiperPre-1.8.0Stored XSScriticalView or DownloadUNDERCODE2025-03-10
WordPress1.3.52 and earlierStored XSScriticalView or DownloadUNDERCODE2025-01-24
WordPress1.6.10 and earlierRemote File InclusioncriticalView or DownloadUNDERCODE2025-01-27
LocalS3All versionsXXE InjectioncriticalView or DownloadUNDERCODE2025-03-10
WordPressn/a - 2.7.1Missing AuthorizationcriticalView or DownloadUNDERCODE2025-01-24
PyTorchN/AArbitrary Code ExecutioncriticalView or DownloadUNDERCODE2025-03-10
TOTOLINK X189.1.0cu.2024_B20220329Stack-based buffer overflowcriticalView or DownloadUNDERCODE2025-02-16
TOTOLINK X189.1.0cu.2024_B20220329OS Command InjectioncriticalView or DownloadUNDERCODE2025-02-16
Apache Struts2.3.5 - 2.3.31, 2.5 - 2.5.10Remote Code ExecutioncriticalView or DownloadUNDERCODE2025-03-10
Oxidized Web< 0.15.0Unauthenticated RCEcriticalView or DownloadUNDERCODE2025-03-02
WeGIA< 3.2.16Denial of ServicecriticalView or DownloadUNDERCODE2025-03-03
GRUB2All versions with squash4 moduleHeap-based Buffer OverflowcriticalView or DownloadUNDERCODE2025-03-03
Protobuf CrateAffected versionsStack OverflowmoderateView or DownloadUNDERCODE2025-03-07
Node.js@intlify/message-resolver 9.1, @intlify/vue-i18n-core 9.2+Prototype PollutioncriticalView or DownloadUNDERCODE2025-03-07
XWiki Confluence Migrator Pro<= 1.11.6Information ExposurehighView or DownloadUNDERCODE2025-03-07
Ring (Cryptography Library)Pre-patch versionsInteger OverflowmediumView or DownloadUNDERCODE2025-03-07
XWiki Confluence Migrator Pro>= 1.0, < 1.2.0Remote Code ExecutioncriticalView or DownloadUNDERCODE2025-03-07
WinDbgAffected versionsRemote Code ExecutioncriticalView or DownloadUNDERCODE2025-03-06
WordPress<= 2.7.6Stored XSScriticalView or DownloadUNDERCODE2025-02-28
OpenTelemetry .NET1.10.0 to 1.11.1Denial of Service (DoS)criticalView or DownloadUNDERCODE2025-03-06
Jenkins< 2.492.2, >= 2.493, < 2.500Information DisclosuremoderateView or DownloadUNDERCODE2025-03-06
Ray<2.43.0Sensitive Info LoggingmoderateView or DownloadUNDERCODE2025-03-06
Envoy Gateway<1.2.7, <1.3.1Log InjectioncriticalView or DownloadUNDERCODE2025-03-06
Jenkins<= 2.499, <= 2.492.1CSRFmoderateView or DownloadUNDERCODE2025-03-06
WordPress<= 1.6.8.1Reflected XSScriticalView or DownloadUNDERCODE2025-02-28
Fleet< 4.64.2SAML Authentication BypasscriticalView or DownloadUNDERCODE2025-03-06
Jenkins< 2.492.2, >= 2.493, < 2.500Open RedirectmoderateView or DownloadUNDERCODE2025-03-06
NocoDBPre-2025 patchesReflected XSScriticalView or DownloadUNDERCODE2025-03-06
WordPress1.3.3 and earlierStored XSScriticalView or DownloadUNDERCODE2025-01-24
WordPress1.1.7 and belowStored XSScriticalView or DownloadUNDERCODE2025-02-28
Microsoft EdgeChromium-basedSecurity Feature BypasscriticalView or DownloadUNDERCODE2025-02-14
OpenZiti< 3.7.1SSRFcriticalView or DownloadUNDERCODE2025-03-03
OpenZiti< 3.7.1Unauthenticated File UploadcriticalView or DownloadUNDERCODE2025-03-03
ShishuoCMS1.1CSRFmediumView or DownloadUNDERCODE2025-03-03
Jinja2Pre-3.1.3Sandbox EscapecriticalView or DownloadUNDERCODE2024-01-15
ShishuoCMS1.1Cross-Site Scripting (XSS)mediumView or DownloadUNDERCODE2025-03-03
Eclipse OMR0.4.0 and earlierNULL Pointer DereferencemediumView or DownloadUNDERCODE2025-02-21
DGLPre-patch versionsRemote Code ExecutioncriticalView or DownloadUNDERCODE2025-03-05
Eclipse OMR0.2.0 to 0.4.0Buffer OverflowcriticalView or DownloadUNDERCODE2025-02-21
Laravel>= 12.0.0, < 12.1.1; < 11.44.1File Validation BypasscriticalView or DownloadUNDERCODE2025-03-05
WordPress<= 4.2.9Unauthorized AccesscriticalView or DownloadUNDERCODE2025-03-04
Redaxo5.18.2Arbitrary File UploadcriticalView or DownloadUNDERCODE2025-03-05
Adobe Commerce2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11Incorrect AuthorizationcriticalView or DownloadUNDERCODE2025-02-11
Linux KernelUp to 6.13.0-rc4Memory LeakcriticalView or DownloadUNDERCODE2025-02-26
OpenDJ9.2Denial-of-Service (DoS)criticalView or DownloadUNDERCODE2025-03-05
Adobe Commerce2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11Improper AuthorizationcriticalView or DownloadUNDERCODE2025-02-11
Linux KernelLoongArch-based systemsOut-of-Bounds (OoB) AccesscriticalView or DownloadUNDERCODE2025-02-26
Linux Kernel< 6.14.0-rc1Null Pointer DereferencecriticalView or DownloadUNDERCODE2025-02-26
Linux Kernelam65-cpsw Ethernet DriverMemory LeakcriticalView or DownloadUNDERCODE2025-02-26
Adobe Commerce2.4.4-p11 and earlierStored XSScriticalView or DownloadUNDERCODE2025-03-05
FlowiseAIv2.2.6Arbitrary File UploadhighView or DownloadUNDERCODE2025-03-05
VMware ESXi, WorkstationMultiple versions affectedTOCTOU leading to out-of-bounds writecriticalView or DownloadUNDERCODE2025-03-04
VMware ESXi, Workstation, FusionMultiple versions affectedInformation DisclosurecriticalView or DownloadUNDERCODE2025-03-04
i-Drive i11, i12Up to 20250227Improper Access ControlcriticalView or DownloadUNDERCODE2025-03-03
PHPGurukul1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-03-03
NGINX Unit< 1.34.2Infinite LoopmediumView or DownloadUNDERCODE2025-03-03
RubyCGI gem < 0.4.2Denial of Service (DoS)criticalView or DownloadUNDERCODE2025-03-03
WordPress1.8.4.1 and earlierArbitrary File UploadcriticalView or DownloadUNDERCODE2025-03-04
ShishuoCMS1.1Unrestricted File UploadcriticalView or DownloadUNDERCODE2025-03-03
Matrix-Appservice-IRCUp to 3.0.3Arbitrary Command ExecutionCriticalView or DownloadUNDERCODE2025-03-04
OpenHarmonyv5.0.2 and priorUse-After-FreeCriticalView or DownloadUNDERCODE2025-03-04
mySCADA myPROVulnerable versions not specifiedCSRFMediumView or DownloadUNDERCODE2025-03-04
Dingtian DT-R0 SeriesAll versions prior to 2.5.1Authentication BypassCriticalView or DownloadUNDERCODE2025-03-04
mySCADA myPROVulnerable versionsOS Command InjectionCriticalView or DownloadUNDERCODE2025-03-04
mySCADA myPRO ManagerNot specifiedAuthentication BypassCriticalView or DownloadUNDERCODE2025-03-04
WordPress1.5.1 and earlierStored XSSCriticalView or DownloadUNDERCODE2025-03-04
CampCodes1.0Unrestricted File UploadCriticalView or DownloadUNDERCODE2025-03-04
Adobe Commerce2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11Incorrect AuthorizationCriticalView or DownloadUNDERCODE2025-03-04
Pinecone SimulatorUp to commit matrix-org/pinecone@ea4c337Stored XSSModerateView or DownloadUNDERCODE2025-03-04
ZITADEL<2.71.0IDORCriticalView or DownloadUNDERCODE2025-03-04
macOSVentura 13.7.3, Sequoia 15.3, Sonoma 14.7.3Code-Signing BypassCriticalView or DownloadUNDERCODE2025-03-04
macOSVentura 13.7.3, Sequoia 15.3, Sonoma 14.7.3Code-Signing BypassCriticalView or DownloadUNDERCODE2025-03-04
macOSSequoia (< 15.3)Sandbox EscapeCriticalView or DownloadUNDERCODE2025-03-04
GNU BinutilsUp to 2.43Stack-based Buffer OverflowMediumView or DownloadUNDERCODE2025-03-04
macOSVentura 13.7.3, Sequoia 15.3, Sonoma 14.7.3File ParsingCriticalView or DownloadUNDERCODE2025-03-04
Apache Struts2.3.5 to 2.3.31, 2.5 to 2.5.10Remote Code ExecutionCriticalView or DownloadUNDERCODE2025-03-04
Rack<2.2.4Log InjectionMediumView or DownloadUNDERCODE2025-03-04
GLPI<10.0.18Reflected XSSCriticalView or DownloadUNDERCODE2025-03-04
macOSVentura 13.7.3, Sequoia 15.3, Sonoma 14.7.3File ParsingCriticalView or DownloadUNDERCODE2025-03-04
Apple visionOS, Safari, iOS, iPadOS, macOS, watchOS, tvOSvisionOS < 2.3, Safari < 18.3, iOS < 18.3, iPadOS < 18.3, macOS < 15.3, watchOS < 11.3, tvOS < 18.3Denial-of-ServiceCriticalView or DownloadUNDERCODE2025-03-04
macOSVentura 13.7.3, Sequoia 15.3, Sonoma 14.7.3Information LeakCriticalView or DownloadUNDERCODE2025-03-04
macOSVentura 13.7.3, Sequoia 15.3, Sonoma 14.7.3Memory CorruptionCriticalView or DownloadUNDERCODE2025-03-04
Apple DevicesiPadOS 17.7.4, macOS Ventura 13.7.3, iOS 18.3Out-of-Bounds ReadCriticalView or DownloadUNDERCODE2025-03-04
Q-Free MaxTime<= 2.11.0Missing AuthorizationMediumView or DownloadUNDERCODE2025-03-03
tsupv8.3.4DOM ClobberingLowView or DownloadUNDERCODE2025-03-03
Q-Free MaxTime<= 2.11.0Missing AuthorizationCriticalView or DownloadUNDERCODE2025-03-03
Q-Free MaxTime<= 2.11.0Missing AuthorizationCriticalView or DownloadUNDERCODE2025-03-03
Q-Free MaxTime<= 2.11.0Missing AuthorizationCriticalView or DownloadUNDERCODE2025-03-03
Q-Free MaxTime<= 2.11.0Missing AuthorizationCriticalView or DownloadUNDERCODE2025-03-03
Picklescan< 0.0.22RCE BypassModerateView or DownloadUNDERCODE2025-03-03
Q-Free MaxTime<= 2.11.0Missing AuthorizationCriticalView or DownloadUNDERCODE2025-03-03
WordPressUp to 4.7.6Stored XSSCriticalView or DownloadUNDERCODE2025-03-03
CodeCheckerUp to 6.24.5Open RedirectModerateView or DownloadUNDERCODE2025-03-03
OPC UA .NET Standard Stack< 1.5.374.158Authentication BypassModerateView or DownloadUNDERCODE2025-03-03
MinIOPrior to fix in commit 91e1487Authentication BypassCriticalView or DownloadUNDERCODE2025-03-03
OPC UA .NET Standard Stack< 1.5.374.158Authentication BypassModerateView or DownloadUNDERCODE2025-03-03
Ruby URI Gem< 0.11.3, 0.12.0-0.12.3, 0.13.0-0.13.1, 1.0.0-1.0.2Userinfo LeakageHighView or DownloadUNDERCODE2025-03-03
SeaJS2.2.3Cross-site Scripting (XSS)LowView or DownloadUNDERCODE2025-03-03
Apache Ranger< 2.6.0Improper NeutralizationLowView or DownloadUNDERCODE2025-03-03
Mavo0.3.2DOM ClobberingModerateView or DownloadUNDERCODE2025-03-03
Ruby CGI Gem<= 0.3.5, 0.3.6, 0.4.0, 0.4.1Denial of Service (DoS)HighView or DownloadUNDERCODE2025-03-03
Ruby CGI Gem<= 0.3.5, 0.3.6, 0.4.0, 0.4.1Denial of Service (DoS)HighView or DownloadUNDERCODE2025-03-03
Stage.js0.8.10 and earlierDOM Clobbering leading to XSSModerateView or DownloadUNDERCODE2025-03-03
ASCON Cryptographic LibraryPre-patch versionsIncorrect Tag VerificationCriticalView or DownloadUNDERCODE2025-03-03
Oxidized Web< 0.15.0Unauthenticated RCECriticalView or DownloadUNDERCODE2025-03-03
Apache StreamPipes< 0.97.0Improper Privilege ManagementModerateView or DownloadUNDERCODE2025-03-03
Ruby CGI Gem<= 0.3.5, 0.3.6, 0.4.0, 0.4.1Denial of Service (DoS)HighView or DownloadUNDERCODE2025-03-03
PyTorchAll versionsArbitrary Code ExecutionCriticalView or DownloadUNDERCODE2025-01-01
PythonAll versions using pickleUnsafe DeserializationCriticalView or DownloadUNDERCODE2025-03-03
ManifestAll versionsWeak password hashingCriticalView or DownloadUNDERCODE2025-03-03
WSO2MultipleIncorrect AuthorizationModerateView or DownloadUNDERCODE2025-03-03
CampCodes1.0Cross-Site Scripting (XSS)MediumView or DownloadUNDERCODE2025-03-03
WordPress<= 1.7.1006CSRFCriticalView or DownloadUNDERCODE2025-03-03
Code-Projects Chat System1.0SQL InjectionCriticalView or DownloadUNDERCODE2025-03-03
GNU Binutils2.43/2.44Memory CorruptionCriticalView or DownloadUNDERCODE2025-03-03
SourceCodester Contact Manager1.0SQL InjectionCriticalView or DownloadUNDERCODE2025-03-03
GNU Binutils2.43Memory CorruptionCriticalView or DownloadUNDERCODE2025-03-03
SourceCodester Employee Management System1.0Default Credentials ExploitCriticalView or DownloadUNDERCODE2025-03-03
CampCodes School Management Software1.0Cross-Site Scripting (XSS)MediumView or DownloadUNDERCODE2025-03-03
Flask-AppBuilder<= 4.5.3User EnumerationLowView or DownloadUNDERCODE2025-03-03
Adobe InDesignID20.0, ID19.5.1 and earlierInteger UnderflowCriticalView or DownloadUNDERCODE2025-03-03
Adobe InCopy20.0, 19.5.1, and earlierInteger UnderflowCriticalView or DownloadUNDERCODE2025-03-03
Apache HTTP Server2.4.49Path TraversalCriticalView or DownloadUNDERCODE2021-10-05
Adobe InDesignID20.0, ID19.5.1Heap-based Buffer OverflowCriticalView or DownloadUNDERCODE2025-03-03
Rancher
v2.8.0 - v2.10.2
Authentication Bypass
Critical
View or DownloadUNDERCODE2025-03-03
Moodle4.5.0-betaIDORView or DownloadUNDERCODE2025-02-24
Button Block1.1.5Missing AuthorizationCriticalView or DownloadUNDERCODE2025-02-25
Moodle4.5.0-betaPermission BypassModerateView or DownloadUNDERCODE2025-02-24
tarteaucitronjs<1.17.0XSSLowView or DownloadUNDERCODE2025-02-24
Mattermost<10.4.2Arbitrary File ReadCriticalView or DownloadUNDERCODE2025-02-24
WordPress2.36Information ExposureMediumView or DownloadUNDERCODE2025-02-24
Real Estate Property Management System1.0SQL InjectionCriticalView or DownloadUNDERCODE2025-02-24
WordPress3.4.0Stored XSSCriticalView or DownloadUNDERCODE2025-02-24
WordPress8.3.0Unauthorized Settings ChangeCriticalView or DownloadUNDERCODE2025-02-24
Linux KernelOpen vSwitchInfinite LoopCriticalView or DownloadUNDERCODE2025-02-21
Codezips Gym Management System1.0SQL InjectionCriticalView or DownloadUNDERCODE2025-02-20
WordPress2.11.9XSSCriticalView or DownloadUNDERCODE2025-02-20
Progress® Telerik® Report ServerPrior to 11.0.25.211Information DisclosureMediumView or DownloadUNDERCODE2025-02-20
XWiki15.10.11Remote Code ExecutionCriticalView or DownloadUNDERCODE2025-02-20
Namada-apps1.1.0Excessive ComputationCriticalView or DownloadUNDERCODE2025-02-20
Namada-apps1.1.0Integer overflowCriticalView or DownloadUNDERCODE2025-02-20
Craft4, 5RCEHighView or DownloadUNDERCODE2025-02-20
Sliver1.5.42SSRFCriticalView or DownloadUNDERCODE2025-02-19
Sante PACS Server-Memory CorruptionCriticalView or DownloadUNDERCODE2025-02-19
MinttyN/AHeap-based Buffer OverflowCriticalView or DownloadUNDERCODE2025-02-18
LogsignUnified SecOps PlatformAuthentication BypassCriticalView or DownloadUNDERCODE2025-02-18
cie-aspnetcoreN/AAuthentication BypassCriticalView or DownloadUNDERCODE2025-02-18
spid-aspnetcoreN/ASAML Authentication BypassView or DownloadUNDERCODE2025-02-18
cie-aspnetcoreN/ASignature ValidationCriticalView or DownloadUNDERCODE2025-02-18
spid-aspnetcoreN/ASignature ValidationCriticalView or DownloadUNDERCODE2025-02-18
SonicWallSSLVPNImproper AuthenticationCriticalView or DownloadUNDERCODE2025-02-18
TP-Link TL-WR841ND V11V11Buffer OverflowCriticalView or DownloadUNDERCODE2025-02-18
Node.jsN/AReDoSCriticalView or DownloadUNDERCODE2025-02-14
npm@octokit/plugin-paginate-restReDoSView or DownloadUNDERCODE2025-02-14
npm@octokit/endpointReDoSCriticalView or DownloadUNDERCODE2025-02-14
@octokit/request-errorN/AReDoSCriticalView or DownloadUNDERCODE2025-02-14
DOMPurify<3.2.4XSSModerateView or DownloadUNDERCODE2025-02-14
Fyrox0.28.1Memory exposureLowView or DownloadUNDERCODE2025-02-14
GitHubv2.67.0Incorrect exit statusCriticalView or DownloadUNDERCODE2025-02-14
Label Studio<1.16.0Path TraversalCriticalView or DownloadUNDERCODE2025-02-14
Label StudioN/AXSSCriticalView or DownloadUNDERCODE2025-02-14
WeGIA3.2.6Stored XSSMediumView or DownloadUNDERCODE2025-02-13
WeGIA3.2.6XSSMediumView or DownloadUNDERCODE2025-02-13
WeGIA3.2.6XSSView or DownloadUNDERCODE2025-02-13
WeGIA3.2.10Open RedirectMediumView or DownloadUNDERCODE2025-02-13
WeGIA3.2.12SQL InjectionCriticalView or DownloadUNDERCODE2025-02-13
WeGIA3.2.12SQL InjectionCriticalView or DownloadUNDERCODE2025-02-13
WeGIA3.2.12SQL InjectionCriticalView or DownloadUNDERCODE2025-02-13
WeGIA3.2.12SQL InjectionView or DownloadUNDERCODE2025-02-13
WeGIA3.2.12SQL InjectionView or DownloadUNDERCODE2025-02-13
WeGIA3.2.6XSSMediumView or DownloadUNDERCODE2025-02-13
WeGIA3.2.6Stored XSSMediumView or DownloadUNDERCODE2025-02-13
WeGIA3.2.7XSSMediumView or DownloadUNDERCODE2025-02-13
HypercubeUnpatchedRemote Code ExecutionView or DownloadUNDERCODE2025-02-12
PDF-XChange EditorN/AOut-Of-Bounds ReadCriticalView or DownloadUNDERCODE2025-02-12
PDF-XChange EditorN/AHeap-based Buffer OverflowCriticalView or DownloadUNDERCODE2025-02-12
PDF-XChange Editor-Out-Of-Bounds ReadCriticalView or DownloadUNDERCODE2025-02-12
PDF-XChange Editor-Out-Of-Bounds ReadCriticalView or DownloadUNDERCODE2025-02-12
Trimble Cityworks<15.8.9, <23.10DeserializationCriticalView or DownloadUNDERCODE2025-02-12
PDF-XChange EditorN/AUse-After-FreeCriticalView or DownloadUNDERCODE2025-02-12
npmparse-durationReDoSCriticalView or DownloadUNDERCODE2025-02-12
EllipticN/APrivate Key ExtractionCriticalView or DownloadUNDERCODE2025-02-12
Koa2.15.4ReDoSCriticalView or DownloadUNDERCODE2025-02-12
WindowsStoragePrivilege ElevationCriticalView or DownloadUNDERCODE2025-02-12
Magento2.4.7-beta1Improper AuthorizationCriticalView or DownloadUNDERCODE2025-02-12
iOS18.3.1AuthorizationCriticalView or DownloadUNDERCODE2025-02-12
Mitel SIP PhonesR6.4.0.HF1Argument InjectionCriticalView or DownloadUNDERCODE2025-02-12
Samsung Android12.0, 13.0, 14.0UnspecifiedCriticalView or DownloadUNDERCODE2025-02-12
GeoNetwork4.4.0-4.4.5, <4.2.10Information DisclosureModerateView or DownloadUNDERCODE2025-02-11
Microsoft EdgeChromium-basedRemote Code ExecutionHighView or DownloadUNDERCODE2025-02-11
Microsoft EdgeChromium-basedRemote Code ExecutionMediumView or DownloadUNDERCODE2025-02-11
Microsoft EdgeChromium-basedRemote Code ExecutionMediumView or DownloadUNDERCODE2025-02-11
Microsoft EdgeChromium-basedSpoofingMediumView or DownloadUNDERCODE2025-02-11
Microsoft EdgeChromium-basedSpoofingMediumView or DownloadUNDERCODE2025-02-11
pgAgent<4.2.3Directory TraversalMediumView or DownloadUNDERCODE2025-02-11
WooCommerce4.7.1Stored XSSCriticalView or DownloadUNDERCODE2025-02-11
WooCommerce3.8.7Missing AuthorizationCriticalView or DownloadUNDERCODE2025-02-11
WordPress1.8.17.0XSSCriticalView or DownloadUNDERCODE2025-02-11
WP Mailster1.8.15.0XSSCriticalView or DownloadUNDERCODE2025-02-11
WordPress3.3.4Stored XSSCriticalView or DownloadUNDERCODE2025-02-11
AshAuthentication4.4.9Token ReuseView or DownloadUNDERCODE2025-02-11
WindowsunknownElevation of PrivilegeView or DownloadUNDERCODE2025-02-11
WindowsMultiplePrivilege EscalationHighView or DownloadUNDERCODE2025-02-11
Zyxel VMG4325-B10A1.00(AAFR.4)C0_20170615Command InjectionView or DownloadUNDERCODE2025-02-11
Apache CXF<3.5.10, <3.6.5, <4.0.6Denial of ServiceMediumView or DownloadUNDERCODE2025-02-11
LinuxKernelRace ConditionCriticalView or DownloadUNDERCODE2025-02-11
Linux Kernelgpio-xilinx driverSpinlock issueCriticalView or DownloadUNDERCODE2025-02-11
Photoshop25.12, 26.1Uncontrolled Search PathHighView or DownloadUNDERCODE2025-02-11
grcov-Out of Bounds WriteModerateView or DownloadUNDERCODE2025-02-10
NettyN/ADenial of ServiceView or DownloadUNDERCODE2025-02-10
Hickory DNSN/ADNSSEC ValidationView or DownloadUNDERCODE2025-02-10
Net-IMAP<0.4.19, <0.5.6Memory ExhaustionCriticalView or DownloadUNDERCODE2025-02-10
esbuild-CORS MisconfigurationCriticalView or DownloadUNDERCODE2025-02-10
SourceCodester1.0SQL InjectionCriticalView or DownloadUNDERCODE2025-02-10
SourceCodester1.0Improper Access ControlsCriticalView or DownloadUNDERCODE2025-02-10
SourceCodester1.0XSSMediumView or DownloadUNDERCODE2025-02-10
Dell Networking SwitchesEnterprise SONiC OSInformation ExposureHighView or DownloadUNDERCODE2025-02-07
Dell PowerProtect DDDDOS 8.3.0.0CryptographicCriticalView or DownloadUNDERCODE2025-02-07
xml2rfc<= 3.26.0XXE InjectionView or DownloadUNDERCODE2025-02-07
WindowsSecure Kernel ModeElevation of PrivilegeHighView or DownloadUNDERCODE2025-02-07
Microsoft EdgeChromium-basedUI MisrepresentationMediumView or DownloadUNDERCODE2025-02-07
@rpldy/uploader1.8.1Prototype PollutionHighView or DownloadUNDERCODE2025-02-06
Firefox< 135Memory CorruptionCriticalView or DownloadUNDERCODE2025-02-06
Thunderbird< 128.7Code ExecutionMediumView or DownloadUNDERCODE2025-02-06
Firefox< 135Memory CorruptionCriticalView or DownloadUNDERCODE2025-02-06
Firefox<135Certificate ValidationCriticalView or DownloadUNDERCODE2025-02-06
Firefox<135Use-After-FreeCriticalView or DownloadUNDERCODE2025-02-06
Firefox< 135, < 115.20, < 128.7Use-After-FreeCriticalView or DownloadUNDERCODE2025-02-06
Thunderbird< 128.7, < 135Incorrect sender addressMediumView or DownloadUNDERCODE2025-02-06
WhoDBN/AParameter InjectionView or DownloadUNDERCODE2025-02-06
WhoDBN/APath TraversalCriticalView or DownloadUNDERCODE2025-02-06
MDC (Nuxt-Modules)LatestXSSCriticalView or DownloadUNDERCODE2025-02-06
rtmpdumpabandonedmultiplecriticalView or DownloadUNDERCODE2025-02-06
7-ZipN/AMotW BypassView or DownloadUNDERCODE2025-02-06
Microsoft OutlookMultipleRemote Code ExecutionCriticalView or DownloadUNDERCODE2025-02-06
PlentiV8GO (V8 11.1.278)Remote Code ExecutionCriticalView or DownloadUNDERCODE2023-01-25
MobSF< 4.3.1DoSView or DownloadUNDERCODE2025-02-05
Contrastv1.4.1Seed verificationCriticalView or DownloadUNDERCODE2025-02-05
.NET and Visual StudioN/ARemote Code ExecutionHighView or DownloadUNDERCODE2025-02-05
MobSF< 4.3.1Stored XSSView or DownloadUNDERCODE2025-02-05
Microsoft Power Automate-Remote Code ExecutionHighView or DownloadUNDERCODE2025-02-05
CKAN2.10.7, 2.11.2Arbitrary File UploadView or DownloadUNDERCODE2025-02-05
GeoTools31.1, 30.3, 30.2, 29.2, 28.2, 27.5, 27.4, 26.7, 26.4, 25.2, 24.0RCEView or DownloadUNDERCODE2025-02-05
Marblerunv1.7.0ImpersonationView or DownloadUNDERCODE2025-02-04
WordPress2.0.4Stored XSSCriticalView or DownloadUNDERCODE2025-02-04
wasmvm1.5.8, 2.0.6, 2.1.5, 2.2.2Block production slowdownView or DownloadUNDERCODE2025-02-04
PRTG Network Monitor<18.2.40.1683Local File InclusionCriticalView or DownloadUNDERCODE2025-02-04
LinuxKernelNull-ptr-derefCriticalView or DownloadUNDERCODE2025-02-03
Linux Kernel32-bitTruncation ErrorCriticalView or DownloadUNDERCODE2025-02-03
SecMem-Out of Bounds WriteCriticalView or DownloadUNDERCODE2025-02-03
Modem-Out-of-bounds writeCriticalView or DownloadUNDERCODE2025-02-03
WLAN AP DriverN/AOut-of-Bounds WriteCriticalView or DownloadUNDERCODE2025-02-03
Network Hardware-Denial of ServiceCriticalView or DownloadUNDERCODE2025-02-03
TShockLatestBan BypassCriticalView or DownloadUNDERCODE2025-02-03
CometBFTv0.38.16, v1.0.0Blocksync DisruptionMediumView or DownloadUNDERCODE2025-02-03
WordPress3.0.1SQL InjectionCriticalView or DownloadUNDERCODE2025-01-31
WordPress2.7.2.1Stored XSSCriticalView or DownloadUNDERCODE2025-01-31
Wildfly27.0.1.FinalRBAC bypassView or DownloadUNDERCODE2025-01-31
iPadOS17.7.4, 2.3, 18.3, Sequoia 15.3, 11.3FingerprintingView or DownloadUNDERCODE2025-01-31
JetBrains YouTrack<2024.3.55417Token ExposureCriticalView or DownloadUNDERCODE2025-01-30
JetBrains TeamCity<2024.12.1Unauthorized decryptionCriticalView or DownloadUNDERCODE2025-01-30
macOS, iOS, iPadOS15.3, 18.3PrivacyMediumView or DownloadUNDERCODE2025-01-30
macOSSequoia 15.3, Sonoma 14.7.3File ParsingCriticalView or DownloadUNDERCODE2025-01-30
iOS18.3Symlink HandlingCriticalView or DownloadUNDERCODE2025-01-30
ApplemacOS Sequoia 15.3, tvOS 18.3, watchOS 11.3, iOS 18.3, iPadOS 18.3Privilege EscalationCriticalView or DownloadUNDERCODE2025-01-30
macOSVentura 13.7.3, Sequoia 15.3, Sonoma 14.7.3Race conditionCriticalView or DownloadUNDERCODE2025-01-30
AppleMultipleMemory HandlingCriticalView or DownloadUNDERCODE2025-01-30
macOSSequoia 15.3Data accessCriticalView or DownloadUNDERCODE2025-01-30
macOSSequoia 15.3Buffer OverflowCriticalView or DownloadUNDERCODE2025-01-30
macOSSequoia 15.3Memory CorruptionCriticalView or DownloadUNDERCODE2025-01-30
WordPress3.7.8DOM-Based XSSCriticalView or DownloadUNDERCODE2025-01-30
DevDojo Voyager1.8.0Path TraversalHighView or DownloadUNDERCODE2025-01-30
Kubewarden1.21.0PolicyReport ManipulationView or DownloadUNDERCODE2025-01-30
fast-faultUnpatchedSegmentation FaultModerateView or DownloadUNDERCODE2025-01-30
Apache Hive<4.0.0Timing DiscrepancyModerateView or DownloadUNDERCODE2025-01-28
MicrosoftSecure BootBypassMediumView or DownloadUNDERCODE2025-01-27
WindowsCOM ServerInformation DisclosureMediumView or DownloadUNDERCODE2025-01-27
Active DirectoryFederation ServerSpoofingMediumView or DownloadUNDERCODE2025-01-27
WindowsConnected Devices Platform ServiceDenial of ServiceHighView or DownloadUNDERCODE2025-01-27
MicrosoftSecure BootBypassMediumView or DownloadUNDERCODE2025-01-27
MicrosoftSecure BootBypassMediumView or DownloadUNDERCODE2025-01-27
Visual StudioN/ARemote Code ExecutionHighView or DownloadUNDERCODE2025-01-27
Apache CocoonAll versionsIncorrect PRNG Seed UsageLowView or DownloadUNDERCODE2025-01-27
WindowsTelephony ServiceRemote Code ExecutionHighView or DownloadUNDERCODE2025-01-24
WindowsTelephony ServiceRemote Code ExecutionHighView or DownloadUNDERCODE2025-01-24
WordPress1.8.96PHP Object InjectionCriticalView or DownloadUNDERCODE2025-01-24
MavenN/ACredential LeakCriticalView or DownloadUNDERCODE2025-01-24
HL7/fhir-ig-publisher1.7.4XXEHighView or DownloadUNDERCODE2025-01-24
DirectusNot specifiedXSSCriticalView or DownloadUNDERCODE2025-01-23
astevalN/ACode ExecutionView or DownloadUNDERCODE2025-01-23
Silverpeas CoreXSSView or DownloadUNDERCODE2025-01-23
Jenkins<=1.6Missing checksModerateView or DownloadUNDERCODE2025-01-22
Jenkins2.8.0-2.10.2Cache ConfusionModerateView or DownloadUNDERCODE2025-01-22
Keycloak<= 26.1.0Authentication BypassModerateView or DownloadUNDERCODE2025-01-22
Ciliumv1.14-v1.16DoSCriticalView or DownloadUNDERCODE2025-01-22
WindowsDigital MediaElevation of PrivilegeMediumView or DownloadUNDERCODE2025-01-22
WindowsKernelMemory DisclosureMediumView or DownloadUNDERCODE2025-01-22
Microsoft-Security Feature BypassMediumView or DownloadUNDERCODE2025-01-22
WindowsDigital MediaElevation of PrivilegeMediumView or DownloadUNDERCODE2025-01-22
Microsoft-Security Feature BypassMediumView or DownloadUNDERCODE2025-01-22
WindowsKernelMemory DisclosureMediumView or DownloadUNDERCODE2025-01-22
WindowsKernelMemory DisclosureMediumView or DownloadUNDERCODE2025-01-22
Internet ExplorerN/ARemote Code ExecutionHighView or DownloadUNDERCODE2025-01-22
WindowsKernelMemory DisclosureMediumView or DownloadUNDERCODE2025-01-22
gix-worktree-stateAffected versionsPermission bypassCriticalView or DownloadUNDERCODE2025-01-22
MathLiveN/AXSSCriticalView or DownloadUNDERCODE2025-01-22
CodeCheckerv6.58CSRFView or DownloadUNDERCODE2025-01-22
YesWiki<= 4.4.5DOM-Based XSSCriticalView or DownloadUNDERCODE2025-01-22
YesWiki<= 4.4.5Arbitrary File DeletionCriticalView or DownloadUNDERCODE2025-01-22
YesWiki4.4.5Stored XSSCriticalView or DownloadUNDERCODE2025-01-22
DuckDBPre-fixUnauthorized AccessView or DownloadUNDERCODE2025-01-22
Buildah1.38.0-1.38.1Build breakoutHighView or DownloadUNDERCODE2025-01-20
Node.js4.5.0-5.28.5RandomnessModerateView or DownloadUNDERCODE2025-01-22
compose-gov2.10-v2.4.0Resource ConsumptionView or DownloadUNDERCODE2025-01-22
FedifyN/AWebfinger MechanismCriticalView or DownloadUNDERCODE2025-01-21
Substance3D Designer14.0Out-of-bounds writeHighView or DownloadUNDERCODE2025-01-21
Substance3D Designer14.0Heap-based Buffer OverflowHighView or DownloadUNDERCODE2025-01-21
Substance3D Designer14.0Out-of-bounds writeHighView or DownloadUNDERCODE2025-01-21
Substance3D Designer14.0Heap-based Buffer OverflowHighView or DownloadUNDERCODE2025-01-21
Zot-AuthorizationView or DownloadUNDERCODE2025-01-17
AWS CDKv2.177.0Bypass TLS VerificationView or DownloadUNDERCODE2025-02-22
Microsoft AutoUpdateN/AElevation of PrivilegeHighView or DownloadUNDERCODE2025-01-17
Substance3D Stager3.0.4Heap-based Buffer OverflowHighView or DownloadUNDERCODE2025-01-17
Substance3D Stager3.0.4Out-of-bounds writeView or DownloadUNDERCODE2025-01-17
Substance3D Stager3.0.4Out-of-bounds writeView or DownloadUNDERCODE2025-01-17
WindowsVBS EnclavePrivilege EscalationCriticalView or DownloadUNDERCODE2025-01-17
WordPress2.10.43Stored XSSCriticalView or DownloadUNDERCODE2025-01-16
Google Chrome<132.0.6834.83Out of bounds readHighView or DownloadUNDERCODE2025-01-16
matrix-media-repo<1.3.5Unauthenticated writesModerateView or DownloadUNDERCODE2025-01-16
HAL Console< 3.7.7.FinalXSSModerateView or DownloadUNDERCODE2025-01-16
Windows Hyper-VNT Kernel Integration VSPElevation of PrivilegeHighView or DownloadUNDERCODE2025-01-15
SP1v4.0.0Validation MissingCriticalView or DownloadUNDERCODE2025-01-15
Zoom
N/A
Leaked Meeting Links
Medium
View or DownloadUNDERCODE2025-01-15
LodestarUnstableDecoding FailureCriticalView or DownloadUNDERCODE2025-01-14
LodestarUnstableChecksum VerificationCriticalView or DownloadUNDERCODE2025-01-14
.NET8.0, 9.0Remote Code ExecutionView or DownloadUNDERCODE2025-01-14
Windows Hyper-VunknownElevation of PrivilegeHighView or DownloadUNDERCODE2025-01-14
Ivanti9.1-22.7Unauthorized AccessCriticalView or DownloadUNDERCODE2025-01-14
Swift ASN.1GitHub ReviewedParsing CrashLowView or DownloadUNDERCODE2025-01-14
Vyper0.3.10, 0.4.0Precompile Success FlagMediumView or DownloadUNDERCODE2025-01-14
XWiki15.10.9+, 16.2.0+Script ExecutionCriticalView or DownloadUNDERCODE2025-01-14
TYPO311.5.42 ELTSCSRFView or DownloadUNDERCODE2025-01-14
Jte
<= 3.1.15
XSS
Critical
View or DownloadUNDERCODE2025-01-13
Jte<= 3.1.15XSSView or DownloadUNDERCODE2025-01-13
Keycloak< 26.0.8Environment Variable ExposureModerateView or DownloadUNDERCODE2025-01-13
notation-goN/ACRL Cache HandlingView or DownloadUNDERCODE2025-01-13
Microweber2.0.9XSSModerateView or DownloadUNDERCODE2025-01-13
Privileged Remote Access3.1Command InjectionView or DownloadUNDERCODE2025-01-13
Qlik Sense EnterprisePre-August 2023 Patch 2Remote Code ExecutionCriticalView or DownloadUNDERCODE2025-01-13
Code-projects1.0SQL InjectionView or DownloadUNDERCODE2025-01-10
Travel Management System1.0SQL InjectionCriticalView or DownloadUNDERCODE2025-01-10
Vaultwardenv1.32.5Reflected XSSLowView or DownloadUNDERCODE2025-01-09
GitHubv0.5.0-v0.5.21JWK Set CacheCriticalView or DownloadUNDERCODE2025-01-09
Ivanti22.7R2.5Buffer OverflowCriticalView or DownloadUNDERCODE2025-01-08
Mitel MiCollab9.8 SP2Local File ReadView or DownloadUNDERCODE2025-01-07
Oracle WebLogic Server10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0Remote Code ExecutionCriticalView or DownloadUNDERCODE2025-01-07
DenoLatestAuthorization header leakCriticalView or DownloadUNDERCODE2025-01-06
NiceGUI-Authentication BypassHighView or DownloadUNDERCODE2025-01-06
go-git<v5.13DoSHighView or DownloadUNDERCODE2025-01-06
go-gitv4 to v5.12Argument InjectionLowView or DownloadUNDERCODE2025-01-06
Phpspreadsheet3.6.0XSSMediumView or DownloadUNDERCODE2025-01-03
Phpspreadsheet3.6.0XSSView or DownloadUNDERCODE2025-01-03
Phpspreadsheet3.6.0XSSCriticalView or DownloadUNDERCODE2024-12-19
Trix editorversions prior to 2.1.11XSSCriticalView or DownloadUNDERCODE2025-01-03
phpMyFAQHTML InjectionCriticalView or DownloadUNDERCODE2025-01-02
NarayanaView or DownloadUNDERCODE2025-01-02
Google ChromeiOS prior to 131.0.6778.69Insufficient policy enforcement in NavigationView or DownloadUNDERCODE2024-11-12
Google Chromeprior to 131.0.6778.69MediumView or DownloadUNDERCODE2025-01-02
Letta (formerly MemGPT)v0.3.17Incorrect Access ControlHighView or DownloadUNDERCODE2025-01-02
ChromePrior to 129.0.6668.100DetailDescriptionType ConfusionHighView or DownloadUNDERCODE2024-10-08
Versions before 129.0.6668.100DetailDescriptionType ConfusionView or DownloadUNDERCODE2024-10-08
Google ChromeN/AInsufficient data validationMediumView or DownloadUNDERCODE2025-01-02
Google ChromeBefore 126.0.6478.54Inappropriate implementation in V8LowView or DownloadUNDERCODE2025-01-02
GLPI10.0.8 to before 10.0.13 (when debug mode is enabled)Reflected XSS (Cross-Site Scripting)Medium (CVSS score: 5.3)View or DownloadUNDERCODE2025-01-02
GLPIAll versions before 10.0.13SQL InjectionCriticalView or DownloadUNDERCODE2025-01-02
GLPIBefore 10.0.13Arbitrary Object InstantiationMediumView or DownloadUNDERCODE2024-03-18
Google ChromeiOS versions prior to 130.0.6723.58Use after freeView or DownloadUNDERCODE2025-01-02
Google ChromePrior to 130.0.6723.58Use after freeMediumView or DownloadUNDERCODE2025-01-02
Type Confusion (CVE-2024-9859)HighView or DownloadUNDERCODE2025-01-02
Linux KernelAllImproper Handling of Unknown Packet TypesLow (Note: Severity ratings are subjective and may vary depending on the source)View or DownloadUNDERCODE2024-05-19
SourceCodester FAQ Management System1.0Cross-site scripting (XSS)View or DownloadUNDERCODE2024-12-31
EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPressup to, and including, 3.9.8Stored Cross-Site Scripting (XSS)View or DownloadUNDERCODE2024-12-31
DetailDescriptionRecipes1.5.10SSRFNot mentionedView or DownloadUNDERCODE2024-12-31
Wordpress pluginup to 3.9.8Stored Cross-Site Scripting (XSS)View or DownloadUNDERCODE2024-12-31
Improper Error HandlingView or DownloadUNDERCODE2024-12-31
WordPressUp to 4.4.2SQL InjectionN/AView or DownloadUNDERCODE2024-02-13
Medium (CVSS Score: 4.3)View or DownloadUNDERCODE2024-12-31
WordPress RSS Aggregator by Feedzy PluginUp to 4.4.2Unauthorized modification of dataCriticalView or DownloadUNDERCODE2024-12-31
Apache SupersetN/AImproper validation of SQL statementsMediumView or DownloadUNDERCODE2024-02-28
Kirby CMSNot applicableArbitrary JavaScript Code ExecutionMediumView or DownloadUNDERCODE2024-12-31
TemmokuMVCUp to 2.3DeserializationCriticalView or DownloadUNDERCODE2024-12-31
Focus for iOS< 12.3Universal Cross-Site Scripting (UXSS)View or DownloadUNDERCODE2024-02-22
Suite CRM7.14.2Local File Inclusion (LFI)View or DownloadUNDERCODE2024-12-31
Linux KernelNULL Pointer DereferenceMediumView or DownloadUNDERCODE2024-12-30
Linux KernelAllMemory LeakMediumView or DownloadUNDERCODE2024-12-30
Linux kernel6.9.0-rc2-custom-00781-gd5ab772d32f7Use-after-freeView or DownloadUNDERCODE2024-12-30
Linux kernelDouble freeView or DownloadUNDERCODE2024-12-30
Linux KernelNull Pointer DereferenceLowView or DownloadUNDERCODE2024-12-30
Linux KernelAll versions before the fixUse-after-Free (UAF) in cifs_stats_proc_write()High (CVSS score not available)View or DownloadUNDERCODE2024-12-30
Linux kernelAll versions before the fixNull pointer dereferenceMedium (尚未評估)View or DownloadUNDERCODE2024-12-30
Linux kernelDouble freeView or DownloadUNDERCODE2024-12-30
Linux KernelNot specifiedmptcp: prevent BPF accessing lowat from a subflow socket (CVE-2024-35894)MediumView or DownloadUNDERCODE2024-12-30
Linux KernelUse-After-Free (UAF)CriticalView or DownloadUNDERCODE2024-12-30
Linux KernelAllNULL-pointer dereferenceLowView or DownloadUNDERCODE2024-05-17
netfilter: validate user input for expected length

View or DownloadUNDERCODE2024-12-30
RustNot SpecifiedUse of Insecure Cryptographic AlgorithmsLowView or DownloadUNDERCODE2024-12-30
LGSL6.2.1Reflected XSSModerateView or DownloadUNDERCODE2024-12-30
Password PusherAll versionsSession HijackingCriticalView or DownloadUNDERCODE2024-12-30
StripeNot mentionedInsecure Direct Object Reference (IDOR)HighView or DownloadUNDERCODE2024-12-30
Linux KernelUse After Free (UAF)View or DownloadUNDERCODE2024-12-30
Linux KernelUse-After-Free (UAF)Low (CVSS: 3.1)View or DownloadUNDERCODE2024-12-30
Adobe ColdFusion2023.6, 2021.12 and earlierImproper Access ControlCritical (CVSS score: 7.5)View or DownloadUNDERCODE2024-12-30
Critical (CVSS score: 9.8)View or DownloadUNDERCODE2024-12-30
Apple Safari, iOS, iPadOS, macOS, and visionOSCode ExecutionCritical (CVSS score: 8.8)View or DownloadUNDERCODE2024-12-30
Oracle Agile PLM Framework9.3.6Unauthenticated Remote File DisclosureHigh (CVSS: 7.5)View or DownloadUNDERCODE2024-12-30
TCPDF< 6.8.0Incorrect ComparisonModerateView or DownloadUNDERCODE2024-12-27
GStreamerN/AStack-based buffer overflowCriticalView or DownloadUNDERCODE2024-12-27
TCPDF< 6.8.0Missing Certificate ValidationView or DownloadUNDERCODE2024-12-27
SONiCElevation of PrivilegeView or DownloadUNDERCODE2024-12-27
WindowsN/AElevation of PrivilegeHIGHView or DownloadUNDERCODE2024-12-27
UnknownView or DownloadUNDERCODE2024-12-27
Visual Studio CodeElevation of PrivilegeView or DownloadUNDERCODE2024-12-27
WindowsNot MentionedElevation of PrivilegeView or DownloadUNDERCODE2024-12-27
QuincyDHCP design flaw (CVE-2024-3661)ModerateView or DownloadUNDERCODE2024-12-27
python-sql(Not specified)SQL InjectionModerateView or DownloadUNDERCODE2024-12-27

Windows Kernel

Not specified

Elevation of Privilege

View or DownloadUNDERCODE2024-12-27
Windows KernelNot mentionedInformation DisclosureMEDIUMView or DownloadUNDERCODE2024-12-27

Skype for Consumer

Not specified

Remote Code Execution

View or DownloadUNDERCODE2024-12-27
Microsoft QUICNot MentionedDenial of ServiceView or DownloadUNDERCODE2024-12-27
Windows 11-TamperingMedium (CVSS score: 6.5)View or DownloadUNDERCODE2024-12-27
Windows Kernel(not mentioned in the article)Elevation of PrivilegeView or DownloadUNDERCODE2024-12-27
lgsl(Specific version if available)Stored Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-12-26
2.1.4SQL injectionView or DownloadUNDERCODE2024-12-26
Amazon Redshift JDBC Driver2.1.0.31SQL injectionView or DownloadUNDERCODE2024-12-26
Apache HugeGraph-Server1.0.0 to 1.4.9Authentication BypassModerateView or DownloadUNDERCODE2024-12-26
Marp Core>= 3.0.2, <= 3.9.0, = 4.0.0Cross-Site Scripting (XSS)ModerateView or DownloadUNDERCODE2024-12-26
Apache Hive, Spark1.2.0 (Hive), 2.0.0 (Spark)CookieSigner Signature ExposureHighView or DownloadUNDERCODE2024-12-23
All versions before 0.13.1 or 0.14.0+devUnintended Git options ignored for creating tagsView or DownloadUNDERCODE2024-12-23

WildFly

< 3.7.7.Final

Cross-site scripting (XSS)

View or DownloadUNDERCODE2024-12-23
Solana SPL Token SwapNot specifiedUnsound `u8` type castingModerateView or DownloadUNDERCODE2024-12-23
KVM0.1.0 - 0.19.0Undefined BehaviorModerateView or DownloadUNDERCODE2024-12-23
PHP>= 1.0.12, < 1.1.13Cross-site Scripting (XSS)ModerateView or DownloadUNDERCODE2024-12-23
Jinja(Not specified in the provided article)Sandbox BreakoutModerateView or DownloadUNDERCODE2024-12-23
Symlink Editing VulnerabilityView or DownloadUNDERCODE2024-12-23
Gogs< 0.13.1Arbitrary File WriteCriticalView or DownloadUNDERCODE2024-12-23
Acclaim USAHERDS7.4.0.1 and belowHardcoded CredentialsCriticalView or DownloadUNDERCODE2024-12-23
Piranha CMS11.1Cross-site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-12-20
Piranha CMS11.1Stored Cross-site Scripting (XSS)ModerateView or DownloadUNDERCODE2024-12-20
Oqtane Framework6.0.0Incorrect Access ControlHighView or DownloadUNDERCODE2024-12-20
Uptime Kuma(unknown)Improper URL Handling (LFI)CriticalView or DownloadUNDERCODE2024-12-20
SocialStreamAffected versions prior to v6.2Account TakeoverHighView or DownloadUNDERCODE2024-12-20
Spring FrameworkAffected versions are not yet specified.Path TraversalHighView or DownloadUNDERCODE2024-12-19
QOS.CH logback-coreUp to and including 1.5.12Expression Language InjectionModerateView or DownloadUNDERCODE2024-12-19
QOS.ch logback-core1.5.12 (and earlier)Server-Side Request Forgery (SSRF)LowView or DownloadUNDERCODE2024-12-19
OpenShift DedicatedAll versions before 0.0.0-20240604173837-d1557bc283dd (patched)Improper Input Validation (Snyk-GOLANG-GITHUBCOMOPENSHIFTMUSTGATHEROPERATORCONTROLLERSMUSTGATHER-7278175)HighView or DownloadUNDERCODE2024-12-19
WhoDBAll versions up to v0.43.0Denial-of-Service (DoS)CriticalView or DownloadUNDERCODE2024-12-19
AstroSource Map DisclosureLowView or DownloadUNDERCODE2024-12-19
openCart4.0.2.3Server-Side Template Injection (SSTI)ModerateView or DownloadUNDERCODE2024-12-18
golang.org/x/net/htmlUnaffected versions not yet disclosedNon-linear parsing of case-insensitive contentCriticalView or DownloadUNDERCODE2024-12-18
Craft CMS< 5.5.2 and < 4.13.2Remote Code Execution (RCE)CriticalView or DownloadUNDERCODE2024-12-18
Apache Kafka0.10.2.0 - 3.9.0 (excluding fixed versions)Incorrect Implementation of Authentication AlgorithmLow (Exploitable only in plaintext scenarios)View or DownloadUNDERCODE2024-12-18
TShockAffected versions prior to 5.2.1Security EscalationHighView or DownloadUNDERCODE2024-12-18
AgeAffected versionsArbitrary Code ExecutionModerateView or DownloadUNDERCODE2024-12-18
Rage0.6.0, 0.7.0-0.7.1, 0.8.0-0.8.1, 0.9.0-0.9.2, 0.10.0, 0.11.0Arbitrary Code ExecutionModerateView or DownloadUNDERCODE2024-12-18
Bun< 1.1.30Prototype PollutionModerateView or DownloadUNDERCODE2024-12-18
Laravel Filemanager< 2.9.1Remote Code Execution (RCE)HighView or DownloadUNDERCODE2024-12-18

hd-wallet crate

v0.4.x (vulnerable), v0.6.0 (patched)

Infinite loop in Slip10-like derivation for curves other than secp256k1 and secp256r1

Low

View or DownloadUNDERCODE2024-12-18
Spatie Browsershot< 5.0.2Directory TraversalHighView or DownloadUNDERCODE2024-12-18
jsiiPrototype PollutionView or DownloadUNDERCODE2024-12-18
Cleartext Transmission of Sensitive InformationModerateView or DownloadUNDERCODE2024-12-18
Reolink devices (RLC-410W, C1 Pro, C2 Pro, RLC-422W, RLC-511W)Up to 1.0.227Command InjectionCriticalView or DownloadUNDERCODE2024-12-18
Reolink RLC-410Wv3.0.0.136_20121102Command InjectionCRITICALView or DownloadUNDERCODE2021-12-22
NUUO NVRmini2Up to 3.11Unauthenticated Remote Code Execution (RCE)CriticalView or DownloadUNDERCODE2024-12-18

Astro

Not specified (versions before 6031962ab5f56457de986eb82bd24807e926ba1b)

CSRF Protection Bypass

Low

View or DownloadUNDERCODE2024-12-18
Apache Tomcat11.0.0-M1 through 11.0.1, 10.1.0-M1 through 10.1.33, 9.0.0.M1 through 9.0.97Uncontrolled Resource ConsumptionModerateView or DownloadUNDERCODE2024-12-17
TraefikAffected versions are not explicitly specified.Improper handling of HTTP/3 connectionsModerateView or DownloadUNDERCODE2024-12-17
Cleo Harmony, VLTrader, LexiComBefore 5.8.0.24Remote Code Execution (RCE)CriticalView or DownloadUNDERCODE2023-11-14
Next.jsAll versions before 14.2.15 (vulnerable)Authorization BypassHighView or DownloadUNDERCODE2024-12-17
TOTOLINK X5000RV.9.1.0u.6369_B20230113Denial of Service (DoS)Critical (CVSS 3.x not available)View or DownloadUNDERCODE2024-12-16
TOTOLINK X6000RV9.4.0cu.1041_B20240224Unrestricted File Upload (Uci_Set Str function without strict parameter filtering)View or DownloadUNDERCODE2024-12-16
TOTOLink RouterX5000R V9.1.0u.6118-B20201102, A7000R V9.1.0u.6115-B20201022Buffer OverflowCriticalView or DownloadUNDERCODE2024-12-16
Totolink X6000R9.4.0cu.852_20230719OS Command Injection (CVE-2024-2353)CriticalView or DownloadUNDERCODE2024-12-16
NetApp SnapCenter4.8 and earlierImproper Authorization (CVE-2024-21987)Not yet analyzed (awaiting analysis)View or DownloadUNDERCODE2024-12-16
Oracle Java SE, GraalVM Enterprise Edition8u411, 8u411-perf, 11.0.23 (Java SE), 20.3.14, 21.3.10 (GraalVM)Partial DoSLow (CVSS score: 3.7)View or DownloadUNDERCODE2024-12-16
OpenHarmonyUp to v3.2.4 (inclusive)Insecure Storage of Sensitive InformationMedium (CVSS v3.1 score: 4.3)View or DownloadUNDERCODE2024-12-16
AndroidAndroid 12.0, 12.1, 13.0, 14.0 (potentially others)Privilege Escalation (Carrier Restriction Bypass)Critical (CVSS score not provided)View or DownloadUNDERCODE2024-12-16
Android12.0, 12.1, 13.0, 14.0 (potentially other versions as well)Heap Buffer Overflow (CVE-2024-0051)CriticalView or DownloadUNDERCODE2024-12-16
Android12, 12L, 13, 14Heap Buffer Overflow (CVE-2024-0049)HighView or DownloadUNDERCODE2024-12-16
Android12, 12L, 13, 14Privilege Escalation (CVE-2024-0048)HighView or DownloadUNDERCODE2024-12-16
Apache HugeGraph-Server1.0.0 to 1.2.1 (Java 8 or Java 11)Remote Code Execution (RCE)View or DownloadUNDERCODE2024-12-16
Concrete CMSPrior to 9.2.8 and 8.5.16Stored XSS in the Search FieldLow (CVSS v3 score: 3.1)View or DownloadUNDERCODE2024-12-16
Concrete CMS9.0.0 - 9.3.2 (Versions below 9 are not affected)Stored XSSMedium (CVSS v3 score: 3.1, CVSS v4 score: 1.8)View or DownloadUNDERCODE2024-12-16
Concrete CMSBelow 9.2.8 and 8.5.16Stored XSSMedium (CVSS v3.1 score: 3.1)View or DownloadUNDERCODE2024-12-16
Mattermost10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12Data Amplification (DoS)ModerateView or DownloadUNDERCODE2024-12-16
Cosmos SDKNot Applicable (multiple versions affected)Stack Overflow (ASA-2024-0012), Resource Exhaustion (ASA-2024-0013)HighView or DownloadUNDERCODE2024-12-16
ColdFusion2023.6, 2021.12 and earlierImproper Access ControlHIGH (CVSS: 7.4)View or DownloadUNDERCODE2024-12-16
WindowsAll versions (affected versions not specified)Elevation of Privilege in Kernel-Mode DriversCritical (CVSS v3 score: 7.8)View or DownloadUNDERCODE2024-12-16
D-Tale< 3.16.1Remote Code ExecutionModerateView or DownloadUNDERCODE2024-12-13
FHIR/Ucum-java1.0.8 and belowXXECriticalView or DownloadUNDERCODE2024-12-13
Browsershot< 5.0.1Local File InclusionHighView or DownloadUNDERCODE2024-12-13
phpMyFAQAll versions before 3.2.10Unrestricted File DownloadCriticalView or DownloadUNDERCODE2024-12-13
Cleo Harmony, VLTrader, LexiComBefore 5.8.0.21Unrestricted File Upload/DownloadCriticalView or DownloadUNDERCODE2024-12-13
Adobe Framemaker2020.7, 2022.5 and earlierStack-based Buffer Overflow (CVE-2024-53959)Critical (CVSS: 7.8)View or DownloadUNDERCODE2024-12-13
Adobe Substance 3D Modeler1.14.1 and earlierOut-of-Bounds Write (CWE-787)Critical (CVSS 3.1 base score: 7.8)View or DownloadUNDERCODE2024-12-12
F5 BIG-IP (Advanced WAF/ASM)All versions before 17.1.1 (17.x) are vulnerable. No fix available for 15.x and 16.x versions.Request Body Handling vulnerability (CVE-2024-23308)High (CVSS score: 7.5)View or DownloadUNDERCODE2024-12-12
Cache SystemsN/AMD5 Collision VulnerabilityCriticalView or DownloadUNDERCODE2024-12-12
python-libarchiveUp to 4.2.1Directory TraversalHighView or DownloadUNDERCODE2024-12-12
XWikiAll versions between 2.3 and 15.10.8 (excluding 15.10.9) and between 16.0.0-rc-1 and 16.2.9 (excluding 16.3.0)Remote Code Execution (RCE) via XWiki.ConfigurableClass objectCriticalView or DownloadUNDERCODE2024-12-12
XWikiAll versions between 9.7-rc-1 and 16.5.0 (excluding patched versions)Remote Code Execution (RCE) through Macro Descriptions (CVE-ID not yet assigned)CriticalView or DownloadUNDERCODE2024-12-12
XWikiXWiki versions 1.2-milestone-2 to 15.10.8 and 16.0.0-rc-1 to 16.2.9 are affected.Unauthorized execution of scheduled operationsModerateView or DownloadUNDERCODE2024-12-12
Apache SupersetBefore 4.1.0SQL InjectionHighView or DownloadUNDERCODE2024-12-12
ryanbekhen/nanoproxyNot specifiedOutdated golang.org/x/crypto dependencyHighView or DownloadUNDERCODE2024-12-12
Remote Code Execution (RCE)CriticalView or DownloadUNDERCODE2024-12-12
Online Class and Exam Scheduling System1.0SQL Injection (CVE-2024-12487)CriticalView or DownloadUNDERCODE2024-12-12
Apache Fineract< 1.8.5SQL InjectionCRITICALView or DownloadUNDERCODE2024-12-12
Tenda AC10U Router15.03.06.48Stack-Based Buffer Overflow (CVE-2024-2764)CriticalView or DownloadUNDERCODE2024-12-12
Codezips Technical Discussion Forum1.0SQL Injection (CVE-2024-12484)CriticalView or DownloadUNDERCODE2024-12-12
Online Class and Exam Scheduling System1.0 (specifically vulnerable)SQL Injection (CWE-74, CWE-89)Critical (CVSS v3.1: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L)View or DownloadUNDERCODE2024-12-12
macOS SonomaAll versions before 14.7.1File System Modification (CVE-2024-44301)CriticalView or DownloadUNDERCODE2024-12-12
WordPressGutenberg Blocks by Kadence Blocks plugin up to 3.2.23Stored XSS (Cross-Site Scripting)CriticalView or DownloadUNDERCODE2024-12-12
Online Class and Exam Scheduling System1.0SQL InjectionCritical (CVSS v3: MEDIUM)View or DownloadUNDERCODE2024-12-12
GitLab CE/EE12.5 before 16.9.6, 16.10 before 16.10.4, 16.11 before 16.11.1Unauthenticated ReDoS in FileFinder with crafted wildcard filtersHigh (CVSS: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)View or DownloadUNDERCODE2024-12-12
Online Class and Exam Scheduling System1.0SQL InjectionView or DownloadUNDERCODE2024-12-12
Apache Fineract< 1.8.5SQL Injection (CVE-2024-23539)HIGHView or DownloadUNDERCODE2024-12-12
Qualcomm Windows WLAN HostNot specifiedImproper Restriction of Operations within the Bounds of a Memory Buffer (CVE-2024-43053)High (CVSS Score: 7.8)View or DownloadUNDERCODE2024-12-12
Apple iOSNot specified (all versions before 17.7 and 18)Unexpected App TerminationCritical (An attacker can exploit the vulnerability to crash applications)View or DownloadUNDERCODE2024-12-12
macOSNot specified (all versions before 14.7 and 15 are potentially vulnerable)Out-of-bounds writeCritical (CVSS details not available yet)View or DownloadUNDERCODE2024-12-12
macOS, iOS, iPadOSAll versions before macOS Ventura 13.7, iOS 17.7/iPadOS 17.7, visionOS 2, iOS 18/iPadOS 18, macOS Sonoma 14.7, macOS Sequoia 15 (inclusive)Race condition in archive unpacking (CVE-2024-27876)Critical (CVSS v3 score likely high)View or DownloadUNDERCODE2024-12-12
LinuxNot specifiedOut-of-bounds memory accessCVSS information is not yet available in the public record.View or DownloadUNDERCODE2024-12-12
Linux KernelNot specifiedInteger Overflow in pagemap_scan_get_args()Moderate (CVSS score: 5.5)View or DownloadUNDERCODE2024-12-12
rahman SelectCours 1.0 (Template Handler component)Not specifiedTemplate Injection (CVE-2024-2064)CriticalView or DownloadUNDERCODE2024-12-12
Synack TargetAllSQLi Blind Time-BasedMediumView or Download + Steps to reproduceDailyCve.com12-12-2024
golangorg/x/crypto/sshbefore v0.31.0, partially mitigated in v0.31.0Authorization Bypass via Misused ServerConfig.PublicKeyCallbackMediumView or DownloadUNDERCODE2024-12-11
Linux KernelNot specified (all versions before the fix)Memory Leak (due to missing kfree_skb())Low (addressed in kernel updates)View or DownloadUNDERCODE2024-12-11
GitLab CE/EEAll versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1Uncontrolled Resource Consumption (DoS)MediumView or DownloadUNDERCODE2024-12-11

Linux Kernel

Unaffected versions not listed (all potentially affected)
A memory leak vulnerability exists in the Linux

Medium (CVSS v3 base score not available yet)

View or DownloadUNDERCODE2024-12-11
macOS SonomaAll versions before 14.6Buffer Overflow (CVSS: High)CriticalView or DownloadUNDERCODE2024-12-11
Linux KernelUnaffected versions not listed (all versions before the fix are assumed vulnerable)Memory Leak (vsock sk_error_queue)Medium (CVSS 3.x Base Score: 5.5)View or DownloadUNDERCODE2024-12-11
kcpAffected versions are prior to 0.26.1.Impersonation vulnerabilityCriticalView or DownloadUNDERCODE2023-11-28
SiYuan<= 0.0.0-20241210012039-5129ad926a21Server-Side Template Injection (SSTI)ModerateView or DownloadUNDERCODE2024-12-11
SiYuan<= 0.0.0-20241210012039-5129ad926a21Arbitrary File ReadHighView or DownloadUNDERCODE2024-12-11
SiYuan<= 0.0.0-20241210012039-5129ad926a21Arbitrary File WriteHighView or DownloadUNDERCODE2024-12-11
Apple iOS, iPadOS, tvOS, and visionOSUnaffected versions not listed (Update to the latest version is recommended)Kernel Memory Corruption (CVE-2024-44277)CriticalView or DownloadUNDERCODE2024-12-11
Linux KernelNot specified (all versions potentially affected)Bluetooth handle release issueMedium (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-12-11
DowngradeView or DownloadUNDERCODE2024-12-11
Apple Products (iOS, iPadOS, macOS, watchOS, visionOS)Unaffected versions not listed (all prior versions potentially vulnerable)Information Disclosure (CVE-2024-44278)CriticalView or DownloadUNDERCODE2024-12-11
JFinalCMS1.0Server-Side Template InjectionView or DownloadUNDERCODE2024-12-11
Liferay Digital Experience PlatformUp to 7.4.3.15Remote Code Execution (RCE)CriticalView or DownloadUNDERCODE2024-12-11
Kashipara E-learning Management Systemv1.0CriticalView or DownloadUNDERCODE2024-12-11
Liferay Portal, Liferay DXP7.2.0 through 7.4.3.12 (Portal), all versions before update 9 (DXP 7.4), all versions before service pack 3 (DXP 7.3), all versions before fix pack 19 (DXP 7.2), and older unsupported versions.Open Redirect (CVE-2024-25609)Critical (CVSS: 6.1)View or DownloadUNDERCODE2024-12-11
macOSNot specified (potentially all versions before Ventura 13.7.1 and Sonoma 14.7.1)PackageKit flaw allowing modification of protected file system areas (CVE-2024-44275)Unknown (awaiting analysis)View or DownloadUNDERCODE2024-12-11
Kashipara E-learning Management Systemv1.0SQL InjectionCritical (CVSS score unavailable)View or DownloadUNDERCODE2024-12-11
JFinalCMS1.0Cross-Site Request Forgery (CSRF)MediumView or DownloadUNDERCODE2024-12-11
Linux KernelNot specifiedUndefined Behavior due to stack usageLow (CVSS details not provided)View or DownloadUNDERCODE2024-12-11
Linux KernelNot specifiedBluetooth handle overflow (CVE-2024-42132)Low (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-12-11
Linux Kernel (ARM)Not specifiedCache Flushing IssueCritical (CVSS details not provided)View or DownloadUNDERCODE2024-12-11
OpenHarmonyPrior to 4.0.1Out-of-Bounds ReadView or DownloadUNDERCODE2024-12-11
Linux KernelUnaffected versions not mentionedUse-after-free (UAF) in the sctp_v6_available() functionCritical (DoS)View or DownloadUNDERCODE2024-12-11
Hewlett Packard Enterprise Insight Remote Support( not specified )Directory TraversalCRITICAL (CVSS Score: 9.8)View or DownloadUNDERCODE2024-12-11
Linux KernelNot specifiedUnbalanced pm_runtime_enable! (CVE-2024-53134)MediumView or DownloadUNDERCODE2024-12-11
Linux KernelNot specifiedDeadlock when accessing tmpfs over NFSMedium (CVSS details not provided)View or DownloadUNDERCODE2024-12-11
Huawei (exact platform unspecified)(not specified)Insufficient verification in system sharing pop-up module (CVE-2024-32989)High (availability impact)View or DownloadUNDERCODE2024-12-11
HarmonyOSAll versions before a patch is applied (specifically mentioned for 4.0.0 and 4.2.0)Permission verification vulnerability in the system sharing pop-up moduleMEDIUM (CVSS score: 6.1)View or DownloadUNDERCODE2024-12-11
Apache Airflow2.8.0 - 2.8.2 (inclusive)Incorrect Privilege AssignmentModerateView or DownloadUNDERCODE2024-12-11
HarmonyOS (all versions mentioned in the references are vulnerable)Not specifiedOut-of-bounds memory accessView or DownloadUNDERCODE2024-12-11
Apache AirflowBefore 2.9.2Use of Web Browser Cache Containing Sensitive InformationMediumView or DownloadUNDERCODE2024-12-11
HarmonyOSNot specifiedInsufficient verification vulnerability in the baseband moduleHighView or DownloadUNDERCODE2024-12-11
MEDIUM (CVSS 3.1 score: 6.2)View or DownloadUNDERCODE2024-12-11
wpa_supplicant module (platform not specified)Not specifiedPermission verification vulnerability (CVE-2024-32991)Critical (CVSS score not explicitly mentioned but the description indicates critical impact)View or DownloadUNDERCODE2024-12-11
Linux KernelUnaffected versions not specified (all before the patch)Privilege EscalationLowView or DownloadUNDERCODE2024-12-11
Missing outer runtime PM protection in drm/xe driverMedium (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-12-11
Local Privilege Escalation (SBAMSvc Link Following)Critical (CVSS score likely high)View or DownloadUNDERCODE2024-12-11
Linux KernelNot specified (all versions using nilfs2 file system are potentially affected)Null Pointer DereferenceLow (CVSS score might be available elsewhere)View or DownloadUNDERCODE2024-12-11
Local Privilege EscalationCritical (CVSS score likely high)View or DownloadUNDERCODE2024-12-11
Heap-based Buffer Overflow (CVE-2024-8025)CriticalView or DownloadUNDERCODE2024-12-11
IBM Cognos Controller11.0.0, 11.0.1Malicious File Upload (CVE-2024-25019)CriticalView or DownloadUNDERCODE2024-12-11
Visteon Infotainment SystemN/ALocal Privilege Escalation (LPE)CriticalView or DownloadUNDERCODE2024-12-11
Visteon Infotainment App SoC (System-on-Chip)Not specifiedMissing Immutable Root of Trust (Hardware Local Privilege Escalation)View or DownloadUNDERCODE2024-12-11
Visteon Infotainment Systems(not specified)Command Injection (CVE-2024-8359)High (CVSS score: 6.8)View or DownloadUNDERCODE2024-12-11
IBM Cognos Controller11.0.0, 11.0.1Exposure of Sensitive InformationNot available (CVSS details not provided)View or DownloadUNDERCODE2024-12-11
IBM Cognos Controller11.0.0, 11.0.1Unrestricted File UploadCritical (CVSS 3.1 score not provided)View or DownloadUNDERCODE2024-12-11
IBM Cognos Controller11.0.0, 11.0.1File Upload Vulnerability (CVE-2024-45676)CriticalView or DownloadUNDERCODE2024-12-11
IBM Cognos Controller11.0.0, 11.0.1Weak Cryptographic AlgorithmsCritical (CVSS details not provided)View or DownloadUNDERCODE2024-12-11
Checkmk Exchange Plugin for MikroTik2.0.0 - 2.5.5 & 0.4a_mk - 2.0aImproper Certificate Validation (CVE-2024-38861)MEDIUM (CVSS v4.0: 4.9)View or DownloadUNDERCODE2024-12-11
Multiple Apple products (iOS, iPadOS, macOS, watchOS, tvOS)All versions before iOS/iPadOS 17.7, macOS 13.7, etc. (see NVD for specifics)CVE-2024-44169 (Kernel Logic Issue)Not specified (likely medium or high)View or DownloadUNDERCODE2024-12-11
macOSAll versions before macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15 (patched)Buffer overflow in Intel Graphics Driver (CVE-2024-44160)CriticalView or DownloadUNDERCODE2024-12-11
CheckmkBefore 2.3.0p16 and 2.2.0p34Cross-Site Scripting (XSS)MEDIUM (CVSS v3: 5.1)View or DownloadUNDERCODE2024-12-11
Apple iOSAll versions before iOS 18 and iPadOS 18 (Vulnerable)Authentication Bypass (CVE-2024-44202)CriticalView or DownloadUNDERCODE2024-12-11
Wazifa System1.0Cross-site Scripting (XSS)Medium (CVSS score: 5.3)View or DownloadUNDERCODE2024-12-11
1000 Projects Library Management System1.0SQL Injection (CVE-2024-12188)CriticalView or DownloadUNDERCODE2024-12-11
PHPGurukul Complaint Management System1.0SQL Injection (CVE-2024-12230)CriticalView or DownloadUNDERCODE2024-12-11
WeiYe-Jing datax-web2.1.1OS Command Injection (CVE-2024-12358)CriticalView or DownloadUNDERCODE2024-12-11
TP-Link VN020 F3v(T)TT_V6.2.1021Buffer OverflowCriticalView or DownloadUNDERCODE2024-12-11
Online Class and Exam Scheduling System1.0SQL Injection (CWE-74, CWE-89)Critical (CVSS v2: 6.5, CVSS v3: 6.3, CVSS v4: 5.3)View or DownloadUNDERCODE2024-12-11
TOTOLINK EX1800T9.1.0cu.2112_B20220316Stack Overflow (CVE-2024-12352)MediumView or DownloadUNDERCODE2024-12-11
code-projects Online Notice BoardUp to 1.0Unrestricted File UploadCritical (CVSS v3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)View or DownloadUNDERCODE2024-12-11
SourceCodester Phone Contact Manager System1.0Improper Input ValidationMedium (CVSS v3.1: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)View or DownloadUNDERCODE2024-12-11
PHPGurukul Complaint Management System1.0SQL Injection (CVE-2024-12228)CriticalView or DownloadUNDERCODE2024-12-11
SourceCodester Petrol Pump Management Software1.0Unrestricted File UploadCritical (CVSS score not provided)View or DownloadUNDERCODE2024-12-11
SourceCodester Best House Rental Management System1.0File InclusionMedium (CVSS v3: 4.3, CVSS v2: 5.0, CVSS v4: 6.9)View or DownloadUNDERCODE2024-12-11
SourceCodester Phone Contact Manager System1.0Improper Input ValidationMedium (CVSS v3.1: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)View or DownloadUNDERCODE2024-12-11
Tenda Routers (FH451, FH1201, FH1202, FH1206)Up to 20241129Null Pointer Dereference (in websReadEvent function of /goform/GetIPTV)MEDIUM (CVSS score: 5.3)View or DownloadUNDERCODE2024-12-11

Override leakage to global cache

Critical

View or DownloadUNDERCODE2024-12-10
Ruby on RailsCross-Site Scripting (XSS)LowView or DownloadUNDERCODE2024-12-10
peerigon/angular-expressionsUnaffected versions: >= 1.4.3Remote Code Execution (RCE)CriticalView or DownloadUNDERCODE2024-12-10
wasmvm, cosmwasm-vm(details not yet available)Medium (Moderate + Likely)View or DownloadUNDERCODE2024-12-10
CosmWasm VMMultiple (see Affected Versions)Unspecified (details pending)MediumView or DownloadUNDERCODE2024-12-10
Linux KernelNot specified (versions up to 6.11.3 are vulnerable)Integer overflow in AMD display driver (CVE-2024-50177)MediumView or DownloadUNDERCODE2024-12-10
SourceCodester Simple Online Bidding System1.0SQL InjectionCritical (CVSS v3 Base Score: 5.3 - MEDIUM)View or DownloadUNDERCODE2024-12-10
SourceCodester Simple Online Bidding System1.0Cross-Site Request Forgery (CSRF)MEDIUM (CVSS score: 6.9)View or DownloadUNDERCODE2024-12-10
SourceCodester Simple Online Bidding System1.0SQL InjectionView or DownloadUNDERCODE2024-12-10
SourceCodester Simple Online Bidding System1.0Cross-Site Request Forgery (CSRF)MEDIUMView or DownloadUNDERCODE2024-12-10
Linux KernelAll versions with MPTCP enabled (potentially from 5.7 to later)mptcp: handle consistently DSS corruptionMedium (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-12-10
SourceCodester Simple Online Bidding System1.0SQL InjectionCritical (CVSS v3.1: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L)View or DownloadUNDERCODE2024-12-10
Hugo>= 0.123.0, < 0.139.4Unescaped Attributes in Internal TemplatesModerateView or DownloadUNDERCODE2024-12-09
Apache Superset2.0.0 to 4.1.0 (excluding 4.1.0)Improper AuthorizationHighView or DownloadUNDERCODE2024-12-09
Winter CMSAffected versionsTwig Sandbox BypassCriticalView or DownloadUNDERCODE2024-12-09
idna<= 0.5.0Punycode Spoofing (CVE- not mentioned)CriticalView or DownloadUNDERCODE2024-12-09
League/CommonMarkAffected versions prior to 2.6.0Denial of Service (DoS)CriticalView or DownloadUNDERCODE2023-11-28
HarmonyOSNot specified (all versions before May 2024 patch are likely vulnerable)Null Pointer Access (CVE-2024-32998)MediumView or DownloadUNDERCODE2024-12-09
HarmonyOSNot specified (all versions before 17.5 are likely vulnerable)Race condition in binder driver module (CVE-2024-32997)HighView or DownloadUNDERCODE2024-12-09
(Multiple - see below)(All versions before 17.5/10.5/14.5)Logic Issue (CVE-2024-27816)CriticalView or DownloadUNDERCODE2024-12-09
HuaweiEMUI 14, EMUI 13, HarmonyOS 4.2, HarmonyOS 4.0, HarmonyOS 3.1, HarmonyOS 3.0 (based on Huawei security bulletin)PIN enhancement failures in the screen lock moduleHighView or DownloadUNDERCODE2024-12-09
Cracking vulnerability in the OS security moduleView or DownloadUNDERCODE2024-12-09
EMUI (Huawei)Not specifiedImproper Permission Control in Window ManagementMediumView or DownloadUNDERCODE2024-12-09
HarmonyOSAll versions before a fix is applied (specific versions not mentioned)Cracking vulnerability in the OS security moduleMedium (CVSS score: 6.4)View or DownloadUNDERCODE2024-12-09
HarmonyOSAll versions (not specified)Privilege Escalation due to permission control issue in the App Multiplier moduleHighView or DownloadUNDERCODE2024-12-09
Apple Vision ProNot specified (versions before 1.1 are vulnerable)Permissions IssueCriticalView or DownloadUNDERCODE2024-12-09
macOS SonomaNot specifiedCode ExecutionCritical (CVSS score likely high)View or DownloadUNDERCODE2024-12-09
Apple Platforms (tvOS, iOS, iPadOS, macOS, watchOS)Unaffected versions are tvOS 17.4, iOS 17.4, iPadOS 17.4, macOS Sonoma 14.4, and watchOS 10.4 or later.CVE-2024-23293 - Spotlight vulnerability allowing access to sensitive user data through Siri with physical access.CriticalView or DownloadUNDERCODE2024-12-09
Rockwell Automation Arena Simulation SoftwareNot specifiedHeap-based memory buffer overflowHIGH (CVSS v3 score: 7.8)View or DownloadUNDERCODE2024-12-09
Rockwell Automation Arena Simulation softwareNot specifiedMemory buffer overflowCritical (CVSS v3 score: 7.8, CVSS v4 score: 8.4)View or DownloadUNDERCODE2024-12-09
Rockwell Automation Arena SimulationAll Versions (not specified)Memory Buffer OverflowMedium (CVSS v3 score: 4.4)View or DownloadUNDERCODE2024-12-09
Palo Alto Networks PAN-OS (with Captive Portal enabled)Not specifiedReflected Cross-Site Scripting (XSS) - CVE-2024-0011MEDIUM (CVSS v3 score: 4.3)View or DownloadUNDERCODE2024-12-09
Palo Alto Networks PAN-OSReflected Cross-Site Scripting (XSS) - CVE-2024-0010MEDIUM (CVSS score: 4.3)View or DownloadUNDERCODE2024-12-09
Rockwell Automation Arena SimulationAll versions (not specified)Arbitrary Code ExecutionCritical (CVSS v3: 7.8, CVSS v4: 8.4)View or DownloadUNDERCODE2024-12-09
Not specified (all versions before iOS 17.4, iPadOS 17.4, macOS Monterey 12.7.4, etc. are vulnerable)

Validation Issue

High

View or DownloadUNDERCODE2024-12-09
macOS SonomaAll versions before 14.4Improper handling of temporary files (CVE-2024-23287)CriticalView or DownloadUNDERCODE2024-12-09
Apple GarageBandAll versions before 10.4.11 (Vulnerable)Use-after-freeCritical (CVSS score not provided)View or DownloadUNDERCODE2024-12-09
macOS, iOS, iPadOS(Unaffected versions not specified)Incomplete data redaction in log entriesCritical (An app may be able to access user-sensitive data)View or DownloadUNDERCODE2024-12-09
macOS (various versions)Not specifiedMemory CorruptionCriticalView or DownloadUNDERCODE2024-12-09
Apple (iOS, iPadOS, macOS, watchOS)All versions before iOS 16.7.6, iPadOS 16.7.6, iOS 17.4, iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4Lock Screen Bypass via SiriCriticalView or DownloadUNDERCODE2024-12-09
Apple iOSAll versions before 16.7.6 and 17.4System Notification SpoofingCritical (CVSS score unavailable)View or DownloadUNDERCODE2024-12-09

Remote Code Execution (RCE)

Critical (unauthenticated attacker can execute arbitrary code)

View or DownloadUNDERCODE2024-12-09
WhatsUp GoldBefore 2023.1.2Server-Side Request Forgery (SSRF)MEDIUMView or DownloadUNDERCODE2024-12-09
WhatsUp GoldBefore 2023.1.2SSRFMedium (CVSS v3 score: 4.2)View or DownloadUNDERCODE2024-12-09
WhatsUp GoldBefore 24.0.1SQL Injection (CVE-2024-46906)Critical (CVSS score: 8.8)View or DownloadUNDERCODE2024-12-09
Drupal CoreVulnerable versionsImproper Error HandlingModerateView or DownloadUNDERCODE2024-12-07
AndroidAffected versions are prior to 2.3.4.Deserialization vulnerabilityLowView or DownloadUNDERCODE2024-12-07
ModerateView or DownloadUNDERCODE2024-12-07
`path-to-regexp`0.1.xReDoSModerateView or DownloadUNDERCODE2024-12-07
(not specified in the article)HTML Injection (CVE-2024-54128)CriticalView or DownloadUNDERCODE2024-12-07
PyO30.23.0 to 0.23.2Build corruptionModerateView or DownloadUNDERCODE2024-12-07
pprof(Unaffected versions not specified)Unsound memory access due to type mismatch and misalignmentLowView or DownloadUNDERCODE2024-12-07
linkmeAffected versionsType MismatchLowView or DownloadUNDERCODE2024-12-07
Drupal Core>= 10.1.0, = 10.2.0, < 10.2.2Denial of ServiceHighView or DownloadUNDERCODE2024-12-07
Solana Web3.js1.95.6 and 1.95.7Supply chain attack leading to private key theftCriticalView or DownloadUNDERCODE2024-12-07
anstream (Rust)< 0.6.8UnsoundnessModerateView or DownloadUNDERCODE2024-12-07
GitHub CLINot specified (versions before 2.63.1)Path TraversalModerateView or DownloadUNDERCODE2024-12-07

PAN-OS

Privilege EscalationMEDIUMView or DownloadUNDERCODE2024-12-07
MetabaseAffected versions include 0.40.4 and earlier, and 1.40.4 and earlier.Local File Inclusion (LFI)Critical (CVSS Score: 10.0)View or DownloadUNDERCODE2024-12-07
WindowsMultiple Windows versions are affected.Elevation of PrivilegeHIGHView or DownloadUNDERCODE2024-12-07
Atlassian Jira Server and Data CenterBefore 8.5.14, 8.6.0-8.13.6, 8.14.0-8.16.1Path TraversalCriticalView or DownloadUNDERCODE2021-03-16
Safari, iOS, iPadOS, macOS, visionOSAffected versions are older than Safari 18.1.1, iOS 17.7.2, iPadOS 17.7.2, macOS Sequoia 15.1.1, iOS 18.1.1, iPadOS 18.1.1, visionOS 2.1.1.Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-12-07
Kemp LoadMasterAll versions before 7.2.48.10, 7.2.54.8, 7.2.59.2Unauthenticated Command InjectionCritical (CVSS v3 score: 10.0)View or DownloadUNDERCODE2024-12-07
vCenter ServerAffected versions are not explicitly mentioned.Heap-overflow vulnerability in the DCERPC protocol implementation.Critical (CVSS Score: 9.8)View or DownloadUNDERCODE2024-12-07
Palo Alto Networks Expedition(Not specified)SQL Injection (CVE-2024-9465)Critical (CVSS score: 9.2)View or DownloadUNDERCODE2024-12-07
Zyxel ATP Series, USG FLEX Series, USG FLEX 50(W) Series, and USG20(W)-VPN SeriesV5.00 through V5.38Directory TraversalHIGHView or DownloadUNDERCODE2024-12-07
Oracle Agile PLM Framework9.3.6Information DisclosureHighView or DownloadUNDERCODE2024-12-07
ProjectSendPrior to r1720Improper AuthenticationCritical (CVSS Score: 9.8)View or DownloadUNDERCODE2024-12-07
Not specified (WebKit is used across various Apple products)Versions prior to those mentioned above (specific versions not provided)Sandbox Escape (Critical)CriticalView or DownloadUNDERCODE2024-12-06
Apple iOS, iPadOS, macOSVersions before iOS 17.4, iPadOS 17.4, and macOS Sonoma 14.4Authentication Bypass in Hidden Photos AlbumCritical (CVSS details not shown in excerpt)View or DownloadUNDERCODE2024-12-06
Apple (mentioned in source)Not specified (all versions before the fixed ones are vulnerable)Race Condition (mentioned in description)High (implied by potential access to user-sensitive data)View or DownloadUNDERCODE2024-12-06
Zyxel USG FLEX H SeriesuOS versions up to (excluding) 1.30Insufficiently protected credentialsCritical (CVSS v3 score details not provided)View or DownloadUNDERCODE2024-12-06
iOS, iPadOS, tvOS, watchOS, macOS (all versions before the mentioned fixes)Not applicable (all versions before the fixes)Unrestricted Microphone AccessView or DownloadUNDERCODE2024-12-06
macOS SonomaNot specified (all versions before 14.4 are vulnerable)Improper memory handlingMedium (allows denial-of-service or potential information disclosure)View or DownloadUNDERCODE2024-12-06
macOS Sonoma(Not specified in the provided text)Memory Access IssueCritical (CVE-2024-23249)View or DownloadUNDERCODE2024-12-06
Apple iOSVersions before 17.4Shake-to-Undo information disclosure (CVE-2024-23240)CriticalView or DownloadUNDERCODE2024-12-06
macOSSonoma 14.4, Monterey 12.7.4 (Unaffected versions not listed)Privilege EscalationCriticalView or DownloadUNDERCODE2024-12-06
macOS SonomaBefore 14.4Permissions Issue (CVE-2024-23253)LowView or DownloadUNDERCODE2024-12-06
macOSNot specified (all versions vulnerable before macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5)Out-of-bounds write in Kerberos v5 PAM moduleCritical (CVSS v3.1: CISA-ADP AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)View or DownloadUNDERCODE2024-12-06
(see below)(see below)Information LeakageView or DownloadUNDERCODE2024-12-06
macOSSonoma 14.4, Monterey 12.7.4, Ventura 13.6.5 (all prior versions are vulnerable)Improper Memory Handling (Code Execution)CriticalView or DownloadUNDERCODE2024-12-06
DirectusNot specified (update to latest version)Client-Side HTML Injection (CVE-2024-54128)CriticalView or DownloadUNDERCODE2024-12-05
sigstore-javaLow (for non-monitors/witnesses)View or DownloadUNDERCODE2024-12-05
Drupal CoreN/AImproper Error HandlingModerateView or DownloadUNDERCODE2024-12-05
Drupal Core10.1.0 - 10.1.7, 10.2.0 - 10.2.1Denial of ServiceHighView or DownloadUNDERCODE2024-12-05
Apache Hive4.0.0-alpha-1Deserialization of untrusted dataHighView or DownloadUNDERCODE2024-12-05
Perl (App::cpanminus package)Up to 1.7047Insecure HTTP DownloadCritical (CVSS 3.0: 9.8/10)View or DownloadUNDERCODE2024-12-05
LowView or DownloadUNDERCODE2024-12-05
PyO30.23.0 - 0.23.2Build CorruptionModerateView or DownloadUNDERCODE2024-12-05
Microsoft Brokering File System (Platform details not specified)(Version information not provided)Elevation of PrivilegeHIGH (CVSS v3 Base Score: 7.8)View or DownloadUNDERCODE2024-12-05
Dell Secure Connect Gateway (SCG) Policy ManagerAllStored Cross-Site Scripting (XSS)HIGHView or DownloadUNDERCODE2024-12-05
RpgpAll versions prior to 0.14.1Multiple vulnerabilities leading to denial-of-serviceCriticalView or DownloadUNDERCODE2024-12-05
Spring LDAPAll versions before 2.4.0, 2.4.0 through 2.4.3, 3.0.0 through 3.0.9, 3.1.0 through 3.1.7, 3.2.0 through 3.2.7Information ExposureModerate (CVE-2024-38829)View or DownloadUNDERCODE2024-12-04
Anstream (platform unspecified)Not specifiedUnhandled Character EncodingView or DownloadUNDERCODE2024-12-04
Apache HTTP ServerAffected versions include 2.4.49 and earlier.A remote code execution vulnerability that can be exploited to execute arbitrary code on the server.CriticalView or DownloadUNDERCODE2024-12-04
LinkmeAffected versionsType MismatchLowView or DownloadUNDERCODE2024-12-04
CheckmkUp to 2.0.0, specific 2.1.0 and 2.2.0 versionsMultiple vulnerabilities (CVE-2023-43277, CVE-2023-43278, CVE-2023-43279)High (CVE-2023-43277), Medium (CVE-2023-43278, CVE-2023-43279)View or DownloadUNDERCODE2024-12-04
PDF-XChange Editor(not specified)Out-of-Bounds Read Information DisclosureView or DownloadUNDERCODE2024-12-04
Adobe Animate24.0 and earlier (including 23.0.3)Out-of-Bounds Read (CVE-2024-20762)MEDIUM (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-12-04
Zabbix ServerNot specified (all versions before 6.4.16rc1 and 7.0.0 are vulnerable)Code Injection (CWE-94)Critical (CVSS score: 9.9)View or DownloadUNDERCODE2024-12-04
Adobe Animate23.0.4 and earlierOut-of-bounds read (CVE-2024-20797)Critical (CVSS score: 7.8)View or DownloadUNDERCODE2024-12-04
Adobe Animate23.0.4 and earlierOut-of-bounds read (CVE-2024-20796)Medium (CVSS 3.1 base score: 5.5)View or DownloadUNDERCODE2024-12-04
GitHub CLIPrior to 2.63.1Path TraversalCriticalView or DownloadUNDERCODE2024-12-04
CyberPanelBefore 1c0c6cb (through 2.3.6 and unpatched 2.3.7)Command InjectionCritical (CVSS score: 10.0)View or DownloadUNDERCODE2024-12-04
Adobe Experience ManagerVersions 6.5.19 and earlier (not specified)Stored Cross-Site Scripting (XSS)Medium (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUM (CVSS 3.x Base Score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)Medium (CVSS v3 base score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUM (CVSS 3.1 base score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUM (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
ChargePoint Home Flex(Not specified in the article)Denial-of-Service (DoS)MEDIUM (CVSS score: 4.3)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUMView or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUM (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
Trimble SketchUpAll versions (unaffected versions not specified yet)Stack-based buffer overflow remote code executionCriticalView or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUM (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUM (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
PDF-XChange EditorAll versions before a patch is released (information not yet available)Out-of-bounds read leading to remote code execution (RCE)High (CVSS v3 score to be determined)View or DownloadUNDERCODE2024-12-03
IBM QRadar Suite, IBM Cloud Pak for Security1.10.12.0 through 1.10.17.0 (QRadar Suite), 1.10.0.0 through 1.1.11.0 (Cloud Pak for Security)Information ExposureCritical (CVSS score details unavailable)View or DownloadUNDERCODE2024-12-03
Linux KernelNot specified (all versions using the iwlwifi driver are potentially vulnerable)Memory Error (improper response handling)Critical (CVE-2024-53059)View or DownloadUNDERCODE2024-12-03
Linux KernelNot specified (all versions potentially affected)Null pointer dereferenceCriticalView or DownloadUNDERCODE2024-12-03
HighView or DownloadUNDERCODE2024-12-03
code-projects FarmaciaUp to 1.0SQL InjectionCritical (CVSS score: 5.3 MEDIUM)View or DownloadUNDERCODE2024-12-03
CheckmkBelow 2.3.0p22, 2.2.0p37, and 2.1.0p50Information DisclosureMedium (CVSS v3: 6.5, CVSS v4: 5.7)View or DownloadUNDERCODE2024-12-03
element-hq/synapseBefore 1.106Unauthenticated Writes to Media RepositoryModerateView or DownloadUNDERCODE2024-12-03
element-hq/synapseBefore 1.120.1Malformed Invite Disrupts /sync FunctionalityHighView or DownloadUNDERCODE2024-12-03
SynapseBelow 1.120.1Unsupported content type handling (multipart/form-data)HighView or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)Medium (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
Stack-based Buffer Overflow (Remote Code Execution)Critical (CVSS score likely high)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierReflected Cross-Site Scripting (XSS)MediumView or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierReflected Cross-Site Scripting (XSS) (CWE-79)Important (CVSS Score: 5.4 - Medium)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierCross-Site Scripting (XSS)Medium (CVSS v3 score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUM (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS) - CVE-2024-26038MEDIUM (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)Medium (CVSS 3.1 score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUM (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
Zyxel ATP Series, USG FLEX Series, USG FLEX 50(W) Series, and USG20(W)-VPN SeriesV5.00 through V5.38Directory TraversalHIGHView or DownloadUNDERCODE2024-12-03
ProjectSendPrior to r1720Improper AuthenticationCritical (CVSS score: 9.8)View or DownloadUNDERCODE2024-12-03
Adobe InDesign Desktop19.0, 20.0 and earlierOut-of-bounds read (CVE-2024-49529)MEDIUM (CVSS 3.x Base Score: 5.5)View or DownloadUNDERCODE2024-12-03
Adobe Dreamweaver Desktop21.3 and earlierOS Command Injection (CVE-2024-30314)CriticalView or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierDOM-based Cross-Site Scripting (XSS)MEDIUM (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUM (CVSS 3.x Base Score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Substance 3D Stager3.0.2 and earlierOut-of-bounds read (CVE-2024-52998)Medium (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS) - CVE-2024-26043MEDIUM (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierDOM-based XSS (Cross-Site Scripting)Medium (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored XSSMEDIUMView or DownloadUNDERCODE2024-12-03
Adobe Premiere Pro23.6.5, 24.4.1 and earlierUntrusted Search PathCriticalView or DownloadUNDERCODE2024-12-03
Adobe Experience Manager (AEM)6.5.20 and earlierStored Cross-Site Scripting (XSS)Medium (CVSS v3 score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.20 and earlierDOM-based XSS (CVE-2024-49524)MediumView or DownloadUNDERCODE2024-12-03
Adobe Experience Manager (AEM)6.5.19 and earlier (all versions before 6.5.20 are potentially vulnerable)DOM-based Cross-Site Scripting (XSS)MEDIUM (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Substance 3D Painter9.1.2 and earlierOut-of-bounds readImportant (CVSS Score: 5.5)View or DownloadUNDERCODE2024-12-03
Adobe Experience ManagerVersions 6.5.19 and earlier (information incomplete due to reanalysis)Stored Cross-Site Scripting (XSS)Medium (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe InDesign DesktopID18.5.2, ID19.3 and earlierNULL Pointer DereferenceImportant (CVSS Score: 5.5)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlier (all prior versions are vulnerable)Stored Cross-Site Scripting (XSS) (CVE-2024-26056)MEDIUM (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUM (CVSS 3.x score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUMView or DownloadUNDERCODE2024-12-03
Adobe Substance 3D Painter9.1.2 and earlierOut-of-bounds read (CVE-2024-30308)Important (CVSS Score: 5.5)View or DownloadUNDERCODE2024-12-03
Adobe InDesignID18.5.2, ID19.3 and earlierHeap-based Buffer Overflow (CVE-2024-39392)Critical (CVSS score: 7.8)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUM (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
RailsRails >= 7.1.0 and Nokogiri < 1.15.7, or 1.16.x < 1.16.8 (Rails::HTML::Sanitizer 1.6.0 is vulnerable)XSSCriticalView or DownloadUNDERCODE2024-12-03

Rails

Rails >= 7.1.0 & Rails::HTML::Sanitizer 1.6.0

Cross-Site Scripting (XSS)

Medium

View or DownloadUNDERCODE2024-12-03
Potential XSS (Cross-Site Scripting)View or DownloadUNDERCODE2024-12-03
RailsRails >= 7.1.0 with Rails::HTML::Sanitizer 1.6.0XSSCriticalView or DownloadUNDERCODE2024-12-03
Mongoose< 8.8.3Search InjectionHighView or DownloadUNDERCODE2024-12-03

Rails::HTML::Sanitizer

1.6.0

XSS (Cross-Site Scripting)

Medium

View or DownloadUNDERCODE2024-12-03
Adobe FrameMaker2020.5, 2022.3 and earlier (all versions before 2020.6 or 2022.4)Out-of-bounds read (CVE-2024-30287)Important (CVSS 3.x Base Score: 5.5)View or DownloadUNDERCODE2024-12-02
Adobe FrameMaker2020.5, 2022.3 and earlierHeap-Based Buffer Overflow (CVE-2024-30288)Critical (CVSS Score: 7.8)View or DownloadUNDERCODE2024-12-02
Adobe FrameMaker2020.5 and earlier (including 2022.3)Out-of-bounds read (CVE-2024-30286)Medium (CVSS score: 5.5)View or DownloadUNDERCODE2024-12-02
Adobe Acrobat Reader20.005.30574 and earlierUse After Free (CVE-2024-30284)Critical (CVSS: 3.1 High - 7.8)View or DownloadUNDERCODE2024-12-02
Adobe Acrobat ReaderVersions 20.005.30574, 24.002.20736 and earlier (fill in "all" if all versions are affected)Use After FreeCritical (CVSS score: 7.8)View or DownloadUNDERCODE2024-12-02
Adobe Acrobat ReaderAll versions before 20.005.30635 and 24.002.20759Improper Access Control (CVE-2024-34099)HIGH (CVSS: 7.8)View or DownloadUNDERCODE2024-12-02
Adobe Acrobat ReaderVersions before 20.005.30574 and 24.002.20736Out-of-bounds write vulnerabilityHIGH (CVSS 3.1 base score: 7.8)View or DownloadUNDERCODE2024-12-02
Adobe Acrobat Reader20.005.30574, 24.002.20736 and earlierOut-of-Bounds ReadHIGH (CVSS 3.x Base Score: 7.8)View or DownloadUNDERCODE2024-12-02
Adobe Acrobat ReaderVersions before 20.005.30635 and 24.002.20759 (inclusive)Use After Free (CVE-2024-34095)HIGH (CVSS v3 score: 7.8)View or DownloadUNDERCODE2024-12-02
Adobe Acrobat Reader DC20.005.30539, 23.008.20470 and earlierUse After Free (CVE-2024-30301)Critical (CVSS 7.8)View or DownloadUNDERCODE2024-12-02
Adobe Acrobat Reader20.005.30574, 24.002.20736 and earlierUse After Free (CVE-2024-34100)Critical (CVSS: 3.1/7.8)View or DownloadUNDERCODE2024-12-02
Adobe Acrobat Reader20.005.30574, 24.002.20736 and earlierOut-of-bounds read (CVE-2024-30311)MediumView or DownloadUNDERCODE2024-12-02
Adobe Acrobat Reader20.005.30574 and earlierOut-of-bounds read (CVE-2024-30312)CriticalView or DownloadUNDERCODE2024-12-02
Adobe Acrobat ReaderAll versions before 20.005.30574 and 24.002.20736Out-of-bounds read (CVE-2024-34101)Medium (CVSS 3.x Base Score: 5.5)View or DownloadUNDERCODE2024-12-02
Adobe FrameMaker2020.5, 2022.3 and earlier (all versions before 2020.6 or 2022.4)Out-of-Bounds Read (CVE-2024-30283)Medium (CVSS score: 5.5)View or DownloadUNDERCODE2024-12-02
`ruzstd`Affected versionsUninitialized and Out-of-Bounds Memory ReadsModerateView or DownloadUNDERCODE2024-12-02
Python-multipartAffected versionsDenial of Service (DoS)HighView or DownloadUNDERCODE2024-12-02
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUM (CVSS v3 score: 5.4)View or DownloadUNDERCODE2024-12-02
Google ChromeBefore 122.0.6261.57Inappropriate implementation in NavigationCritical (Chromium security severity: Medium)View or DownloadUNDERCODE2024-12-02
Symfony!ERROR! B1103 -> Formula Error: Unexpected ,DeserializationHighView or DownloadUNDERCODE2024-12-02
Ant-Media-Server2.8.2Improper Output Neutralization for LogsHighView or DownloadUNDERCODE2024-12-02
SymfonyAffected versions are not explicitly mentioned. It is recommended to upgrade to the latest version to mitigate the risk.Authentication BypassModerateView or DownloadUNDERCODE2024-12-02
SimpleSAMLphpAll versions before 2.3.4, 2.2.4, 2.1.7, and 2.0.15XXE (XML External Entity)CriticalView or DownloadUNDERCODE2024-12-02
N/A (Lettuce is a Java library)Affected versions < 6.5.1.RELEASENetty vulnerability (CVE-TBD)ModerateView or DownloadUNDERCODE2024-12-02
Ibexa Admin UIAffected versions are not explicitly mentioned.Cross-site Scripting (XSS)ModerateView or DownloadUNDERCODE2024-12-02
SFTPGo2.3.0 to 2.6.3Brute Force Takeover of OpenID Connect Session CookiesModerateView or DownloadUNDERCODE2024-12-02
SimpleSAMLphp SAML2(Unaffected versions not specified)XXEModerateView or DownloadUNDERCODE2024-12-02
Node.js10.0.4Prototype PollutionCriticalView or DownloadUNDERCODE2024-12-02
Not specifiedNot specifiedCache ConfusionModerateView or DownloadUNDERCODE2024-12-02
Versions before 10.0.0Cross-Site Scripting (XSS)MediumView or DownloadUNDERCODE2024-12-02
veraPDF CLIAffected versions are not explicitly specified.XXE (XML External Entity Injection)LowView or DownloadUNDERCODE2024-12-02
SimpleSAMLphpNot specifiedXXEHighView or DownloadUNDERCODE2024-12-02
(Not specified in the provided text)libarchive versions before 3.7.5Out-of-bounds memory access in execute_filter_audio functionHIGH (CVSS v3 score: 7.8)View or DownloadUNDERCODE2024-12-02
AMTT Hotel Broadband Operation SystemUp to 3.0.3.151204SQL Injection (CVE-2024-11051)CriticalView or DownloadUNDERCODE2024-12-02
Concert Ticket Ordering System1.0SQL InjectionView or DownloadUNDERCODE2024-12-02
Team Plugins360 All-in-One Video GalleryAll versions up to 3.5.2Missing AuthorizationHIGHView or DownloadUNDERCODE2024-12-02
Veritas Enterprise VaultBefore 15.2Remote Code ExecutionCritical (CVSS score: 9.8)View or DownloadUNDERCODE2024-11-29
Veritas Enterprise VaultBefore 15.2Remote Code Execution (RCE)Critical (CVSS 3.x score: 9.8)View or DownloadUNDERCODE2024-11-29
Microsoft WindowsNot specified (all versions potentially affected)Elevation of PrivilegeHIGH (CVSS 3.1 base score: 7.0)View or DownloadUNDERCODE2024-11-29
Open Management Infrastructure (OMI)Not specified (all versions likely affected)Remote Code Execution (RCE)Critical (CVSS: 9.8)View or DownloadUNDERCODE2024-11-29
.NET7.0 (<= 7.0.16), 8.0 (<= 8.0.2)Denial of Service (DoS)HIGH (CVSS score: 7.5)View or DownloadUNDERCODE2024-11-29
Kerberos Security Feature BypassHIGH (CVSS 3.1 base score: 7.5)View or DownloadUNDERCODE2024-11-29
WordPressProfileGrid plugin versions up to 5.9.3.6Unauthorized data modificationMedium (CVSS: 6.5)View or DownloadUNDERCODE2024-11-29
HIGH (CVSS: 7.0)View or DownloadUNDERCODE2024-11-29
Microsoft Dynamics 365 (on-premises)Not specifiedCross-site Scripting (XSS)HIGH (CVSS v3 score: 7.6)View or DownloadUNDERCODE2024-11-29
WordPressAshe theme versions up to 2.243Reflected Cross-Site Scripting (XSS)MEDIUM (CVSS: 6.1)View or DownloadUNDERCODE2024-11-29
WordPress Plugin - MailChimp Forms by MailMunchAll versions up to 3.2.3 (inclusive)Reflected Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-11-29
Veritas Enterprise VaultBefore 15.2Remote Code Execution (RCE)Critical (CVSS v3 score: 9.8)View or DownloadUNDERCODE2024-11-29
Out-of-Bounds Read Remote Code Execution (RCE)Critical (CVSS v3 score: 7.8)View or DownloadUNDERCODE2024-11-29
PDF-XChange Editor(not specified in available information)Out-of-Bounds Write Remote Code ExecutionHIGH (CVSS score: 7.8) based on Zero Day Initiative (ZDI)View or DownloadUNDERCODE2024-11-29
MediumView or DownloadUNDERCODE2024-11-29
PDF-XChange EditorAll versions before a patch is releasedInformation DisclosureView or DownloadUNDERCODE2024-11-22
PDF-XChange EditorNot specified (all versions before a patch is released are vulnerable)Out-of-Bounds Read Remote Code ExecutionHIGHView or DownloadUNDERCODE2024-11-29
PDF-XChange Editor(information not available)Out-of-bounds read remote code execution (RCE)Critical (CVSS v3.0 base score likely high)View or DownloadUNDERCODE2024-11-29
EMF File Parsing Out-Of-Bounds ReadLOW (CVSS: 3.3)View or DownloadUNDERCODE2024-11-29
Out-of-Bounds Read Remote Code Execution (RCE) in XPS parsingCritical (CVSS score likely high)View or DownloadUNDERCODE2024-11-29
Foxit PDF ReaderAll versions (unspecified)Out-of-Bounds Read Remote Code ExecutionCriticalView or DownloadUNDERCODE2024-11-29
Foxit PDF ReaderNot specified in this sourceAnnotation Use-After-FreeCriticalView or DownloadUNDERCODE2024-11-29
Local Privilege EscalationCriticalView or DownloadUNDERCODE2024-11-29
Foxit PDF Reader (all versions)Not specifiedIncorrect Permission Assignment in Update Service (Local Privilege Escalation)CriticalView or DownloadUNDERCODE2024-11-29
Foxit PDF ReaderAll versions (not specified)Out-of-Bounds Read Information DisclosureCriticalView or DownloadUNDERCODE2024-11-29
Annotation Use-After-Free Remote Code ExecutionCritical (CVSS score likely high)View or DownloadUNDERCODE2024-11-29
Annotation Out-of-Bounds ReadCriticalView or DownloadUNDERCODE2024-11-29
Out-of-Bounds Write Remote Code ExecutionCriticalView or DownloadUNDERCODE2024-11-29
SolarWinds Web Help Desk (WHD)Not specified in the provided information.Hardcoded CredentialsCritical (CVSS score: 9.1)View or DownloadUNDERCODE2024-11-29
SolarWinds Serv-UAll versions up to 15.4.2 Hotfix 1Directory TraversalCriticalView or DownloadUNDERCODE2024-11-29
D-Link NAS devices (DNS-320L, DNS-325, DNS-327L, DNS-340L)All versions up to April 3rd, 2024 (EOL)Command Injection (CVE-2024-3273)Critical (CVSS score likely high)View or DownloadUNDERCODE2024-11-29
Windows (10 and above), Windows Server (2016 and later)Not specifiedHeap-based buffer overflow in DWM Core LibraryHIGH (CVSS v3 score: 7.8)View or DownloadUNDERCODE2024-11-29
AndroidAll versions (initially reported on Pixel devices but affects all)Privilege Escalation (CVE-2024-32896)CriticalView or DownloadUNDERCODE2024-11-29
IrfanViewAll versionsHeap-based buffer overflow due to SVG file parsingCritical (CVSS score: 7.8)View or DownloadUNDERCODE2024-11-29
IrfanViewAll versions (unaffected version not specified)Out-of-Bounds Read Remote Code Execution (RCE)View or DownloadUNDERCODE2024-11-29
IrfanViewAll versionsDXF File Parsing Type Confusion Remote Code ExecutionCriticalView or DownloadUNDERCODE2024-11-29
CriticalView or DownloadUNDERCODE2024-11-29
Foxit PDF ReaderAll versions up to (including) 13.1.3 (Windows) & 13.1.2 (Mac)Use-After-Free Remote Code Execution (RCE)CriticalView or DownloadUNDERCODE2024-11-29
Microsoft Windows KernelNot specifiedTime-Of-Check Time-Of-Use (TOCTOU) race conditionCritical (CVSS score: 7.0)View or DownloadUNDERCODE2024-11-29
Windows MSHTML Platform(Not specified in the provided information)Security Feature BypassCritical (CVSS v3 score: 8.8)View or DownloadUNDERCODE2024-11-29
Oracle CRM Technical Foundation (Oracle E-Business Suite)12.2.3 - 12.2.13Partial Denial of Service (DoS)Medium (CVSS 3.1 Base Score: 4.3)View or DownloadUNDERCODE2024-11-29
JD Edwards EnterpriseOne ToolsPrior to 9.2.8.1Information DisclosureCriticalView or DownloadUNDERCODE2024-11-29
Oracle MySQL Server8.0.35 and prior, 8.2.0 and priorPrivilege Escalation (CVE-2024-20964)Critical (CVSS 3.1 Base Score: 5.3)View or DownloadUNDERCODE2024-11-29
Hugging Face TransformersNot specifiedDeserialization of Untrusted Data (Remote Code Execution)CriticalView or DownloadUNDERCODE2024-11-28
Hugging Face Transformers (MaskFormer model)Not specifiedDeserialization of Untrusted Data (Remote Code Execution)ImportantView or DownloadUNDERCODE2024-11-28
Linux KernelNot specifiedImproper lock handling (CVE-2024-53086)Moderate (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-11-28
Linux KernelNot specified (potentially all versions with the vulnerable remoteproc driver)Error Handling Vulnerability (CWE-755)Low (CVSS v3 details not provided)View or DownloadUNDERCODE2024-11-28
Linux KernelNot specifiedUse-After-Free (UAF)Moderate (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-11-28
Linux KernelNot specified (all versions potentially affected)Exec Queue LeakMedium (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-11-28
Linux KernelNot specified (versions 6.5 to 6.12 likely affected)Uninitialized variables (hdr_len and txbuf_len)Medium (CVSS 3.1 base score: 5.5)View or DownloadUNDERCODE2024-11-28
Linux KernelNot specified (all versions potentially affected)Race ConditionModerate (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-11-28
Linux KernelNot specified (all versions potentially affected)Access to uninitialized variable in tick_ctx_cleanup() functionMedium (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-11-28
Hugging Face Transformers (Library)(Unaffected versions not specified yet)Remote Code Execution (RCE)Critical (CVSS score unavailable, but details suggest high severity)View or DownloadUNDERCODE2024-11-28
Linux kernelNot specified (likely impacts specific kernel versions)Improper use of use_count in media:qcom:camss:stop_streaming functionMedium (CVSS 3.x Base Score: 5.5)View or DownloadUNDERCODE2024-11-28
Linux KernelNot specified (potential impact on all versions with Loongson 3 CPU support)Improper Resource Handling (use of incorrect function)LowView or DownloadUNDERCODE2024-11-28
Linux KernelNot specified (all versions affected by commit de8548813824)Race condition during group handle conversionMedium (CVSS 3.x Base Score: 4.7)View or DownloadUNDERCODE2024-11-28

Cilium

v1.16.0 - v1.16.3 (inclusive)

Layer 7 policy enforcement bypass with port ranges

Medium

View or DownloadUNDERCODE2024-11-28
MLflowN/APrivilege EscalationHighView or DownloadUNDERCODE2024-11-28
deno_doc(not specified)Self-XSSLowView or DownloadUNDERCODE2024-11-28
Querydsl (with JPA)Not specified (but vulnerable in versions up to 6.8.0)HQL Injection (Blind)CriticalView or DownloadUNDERCODE2024-11-28
SPEmailHandler-PHP< 1.0.0Arbitrary Email SendingHighView or DownloadUNDERCODE2024-11-28
Python0.1.13Credential HarvestingHighView or DownloadUNDERCODE2024-11-28
sigstore-javav1.0.0Improper verification of log entry in bundle verification (CVE-2024-53267)CriticalView or DownloadUNDERCODE2024-11-28
libre-chat0.0.6Path TraversalModerateView or DownloadUNDERCODE2024-11-28
lakeFSAffected versions are not explicitly specified.Privilege EscalationModerateView or DownloadUNDERCODE2024-11-28
Jenkins< 0.0.15Path TraversalModerateView or DownloadUNDERCODE2024-11-28
Keycloak26 and earlierDenial-of-Service (DoS)CriticalView or DownloadUNDERCODE2023-11-21
Keycloak!ERROR! B1187 -> Formula Error: Unexpected ,Sensitive Data ExposureView or DownloadUNDERCODE2024-11-28
Jenkins1.4.4 and earlierStored Cross-Site Scripting (XSS)HighView or DownloadUNDERCODE2024-11-28
GitHub CLIPrior to 2.63.0Token LeakCriticalView or DownloadUNDERCODE2024-11-28
Devolutions.XTS.NETAll versionsTiming AttackModerateView or DownloadUNDERCODE2024-11-28
Android (uses Apache ExternalStorageProvider)Unaffected versions not specified (potential for widespread impact)File Path Filter BypassCriticalView or DownloadUNDERCODE2024-11-28
Safari, iOS, iPadOS, macOS, visionOSAffected versions prior to Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, macOS Sequoia 15.1.1, iOS 18.1.1 and iPadOS 18.1.1, visionOS 2.1.1Arbitrary Code ExecutionCriticalView or DownloadUNDERCODE2024-11-28
vCenter ServerAffected versionsPrivilege EscalationHIGHView or DownloadUNDERCODE2024-11-28
Oracle Agile PLM Framework9.3.6Information DisclosureHIGHView or DownloadUNDERCODE2024-11-28
SQL Injection (CVE-2024-9465)Critical (CVSS score: 9.2)View or DownloadUNDERCODE2024-11-28
CyberPanel (aka Cyber Panel)Before 5b08cd6d53f4dbc2107ad9f555122ce8b0996515 (versions through 2.3.6 and unpatched 2.3.7)Remote Code Execution (RCE)Critical (CVSS 10.0)View or DownloadUNDERCODE2024-11-28
Progress Kemp LoadMasterAll versions after 7.2.48.1 (including LoadMaster Multi-Tenant VFNs)Unauthenticated Command InjectionCRITICALView or DownloadUNDERCODE2024-11-28
Missing AuthenticationCritical (CVSS score: 9.3)View or DownloadUNDERCODE2024-11-28
NTLMv2 Hash Disclosure SpoofingView or DownloadUNDERCODE2024-11-28
Cisco Adaptive Security Appliance (ASA)Not specifiedCross-site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-11-28
Palo Alto Networks PAN-OSView or DownloadUNDERCODE2024-11-28
WindowsMultiple versions affectedElevation of PrivilegeHighView or DownloadUNDERCODE2024-11-28
Apple Products (Safari, iOS, iPadOS, macOS, visionOS)Affected versions include Safari 18.1, iOS 17.7, iPadOS 17.7, macOS Sonoma 15.1, iOS 18.1, iPadOS 18.1, and visionOS 2.1.Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-11-28
Hugging Face Transformers MaskFormer ModelAll versions before a fix is appliedDeserialization of Untrusted Data Remote Code ExecutionCriticalView or DownloadUNDERCODE2024-11-27
Linux KernelNot specified (the vulnerability was identified in a pre-release version)Suspicious RCU usage in ip_tunnel_find() functionMediumView or DownloadUNDERCODE2024-11-27
Linux KernelNot specified (all versions potentially affected)Memory Corruption in drm/vc4 driverModerate (CVSS v3 score to be determined)View or DownloadUNDERCODE2024-11-27
go-ghPrior to 2.11.1Improper Token HandlingModerateView or DownloadUNDERCODE2024-11-27
GitHub CLIPrior to 2.63.0Token LeakCriticalView or DownloadUNDERCODE2024-11-27
SPEmailHandler-PHP< 1.0.0Arbitrary Email SendingHighView or DownloadUNDERCODE2024-11-27
Linux KernelUnaffected versions not specified yet (Needs Evaluation for most Ubuntu versions)Use-after-free (accessing uninitialized variable)Moderate (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-11-27
Linux KernelNot specified (potentially all versions with qcom:camss driver)Incorrect usage of reference counter in qcom:camss driver (CVE-2024-50175)ModerateView or DownloadUNDERCODE2024-11-27
Linux KernelNot specified (versions 6.10 to 6.12 likely affected)Race condition (CVE-2024-50174)Moderate (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-11-27
ServiceNow VancouverMultipleRemote Code Execution (RCE)CriticalView or DownloadUNDERCODE2024-11-27
Linux KernelNot specified (all versions before the fix are potentially vulnerable)Exec Queue LeakMedium (CVSS score details not yet available)View or DownloadUNDERCODE2024-11-27
Google ChromePrior to 124.0.6367.207Out-of-bounds write in V8 JavaScript engineCritical (High in Chromium)View or DownloadUNDERCODE2024-11-27
Linux KernelNot specifiedResource Leak due to Object Reference LoopMediumView or DownloadUNDERCODE2024-11-27
Linux KernelNot specifiedRace condition in TPM suspension (CVE-2024-53085)Moderate (CVSS score details not provided)View or DownloadUNDERCODE2024-11-27
Linux KernelNot specified (all versions using the vulnerable cpufreq driver)cpufreq: loongson3: Use raw_smp_processor_id() in do_service_request() (CVE-2024-50178)CriticalView or DownloadUNDERCODE2024-11-27
Apple Safari, iOS, iPadOS, macOS SequoiaAll versions before Safari 18.1.1, iOS 17.7.2, iPadOS 17.7.2, macOS Sequoia 15.1.1, iOS 18.1.1, iPadOS 18.1.1, and visionOS 2.1.1Code Execution (CVE-2024-44308)CriticalView or DownloadUNDERCODE2024-11-27
Google ChromePrior to 124.0.6367.201Use After Free in VisualsHighView or DownloadUNDERCODE2024-11-27
Linux KernelNot specifiedImproper Error Handling (remoteproc driver)Moderate (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-11-27
Linux KernelNot specifiedUninitialized variable (hdr_len, txbuf_len)MediumView or DownloadUNDERCODE2024-11-27
ServiceNow Now PlatformAll versions before Xanadu General Availability (vague)Sandbox Escape (allows remote code execution)Critical (CVSS score: 9.3)View or DownloadUNDERCODE2024-11-27
Jenkins< 0.0.15Path TraversalModerateView or DownloadUNDERCODE2024-11-27
QuerydslNot specified (vulnerable since initial versions)HQL InjectionCriticalView or DownloadUNDERCODE2024-11-27
Devolutions.XTS.NETAll versions before 2024.11.26Timing Attack (CVE-2024-11862)ModerateView or DownloadUNDERCODE2024-11-27
Google ChromeBefore 125.0.6422.112Type Confusion in V8 JavaScript EngineView or DownloadUNDERCODE2024-11-27
Google ChromePrior to 128.0.6613.84 (Unaffected versions not specified)Type Confusion (CVE-2024-7971)Critical (CVSS score likely high)View or DownloadUNDERCODE2024-11-27
Linux KernelNot specifiedBounds checking error in snd_soc_dapm_widget_listMediumView or DownloadUNDERCODE2024-11-27
Oracle WebCenter Portal (Oracle Fusion Middleware)12.2.1.4.0 (affected version)Unauthorized access (update, insert, delete, read) to some of Oracle WebCenter Portal dataMedium (CVSS v3 score: 4.4)View or DownloadUNDERCODE2024-11-27
Oracle Agile Product Lifecycle Management for ProcessPrior to 6.2.4.2Unauthenticated remote code executionCritical (CVSS 3.1 Base Score: 7.3)View or DownloadUNDERCODE2024-11-27
MySQL Server8.0.35 and prior, 8.2.0 and priorServer : Security : FirewallMediumView or DownloadUNDERCODE2024-11-27
Oracle BI Publisher6.4.0.0.0, 7.0.0.0.0Unauthorized access (update, insert, delete, read)Critical (CVSS score: 5.4)View or DownloadUNDERCODE2024-11-27
Linux KernelUnaffected versions not specified (likely all before a patched version is released)Integer underflow in PLL value checks for Samsung Arbiter 0521 sensorCriticalView or DownloadUNDERCODE2024-11-27
Oracle Hospitality Simphony (component: Simphony Enterprise Server)19.1.0 - 19.5.4Easily exploitable via HTTPCritical (CVSS 3.1 Base Score: 9.9)View or DownloadUNDERCODE2024-11-27
Oracle MySQL Server8.0.36 and prior, 8.3.0 and priorInformation Schema flawCritical (CVSS score: 5.3)View or DownloadUNDERCODE2024-11-27
Oracle WebLogic Server (Core component)12.2.1.4.0, 14.1.1.0.0Security Feature BypassCritical (CVSS 3.1 Base Score: 6.1)View or DownloadUNDERCODE2024-11-27
Oracle E-Business Suite12.2.3 - 12.2.13Unauthorized data accessMedium (CVSS 3.1 Base Score: 5.3)View or DownloadUNDERCODE2024-11-27
Oracle Solaris11Zone component vulnerabilityCritical (CVSS score: 8.2)View or DownloadUNDERCODE2024-11-27
Oracle MySQL Server8.0.35 and prior, 8.2.0 and prior (all versions before these are vulnerable)Improper handling within the Optimizer componentCritical (CVSS 3.1 Base Score: 4.9)View or DownloadUNDERCODE2024-11-27
Oracle E-Business Suite12.2.3 - 12.2.13CVE-2024-20958Medium (CVSS 3.1 Base Score: 5.4)View or DownloadUNDERCODE2024-11-27
Oracle Database Sharding19.3-19.22 & 21.3-21.13An attacker with DBA privileges and network access can cause a partial denial-of-service (DoS).Low (CVSS v3 base score: 2.4)View or DownloadUNDERCODE2024-11-27
Linux KernelNot specifiedBuffer overflow in video capture when using more than 32 buffers.Medium (CVSS v3.1: 5.5)View or DownloadUNDERCODE2024-11-27
Linux KernelUnaffected versions not specified (all before 6.11.8 likely vulnerable)Missing buffer index check in dvb_vb2_expbuf() functionLow (CVSS v3 score not yet available)View or DownloadUNDERCODE2024-11-27
Linux Kernel (Xilinx axienet)Not specified (affects specific platforms)Race condition in network transmissionModerate (CVSS: 5.5)View or DownloadUNDERCODE2024-11-27
Linux KernelUnaffected versions not listed (all potentially vulnerable)Btrfs reference list handling error in `insert_delayed_ref()`LowView or DownloadUNDERCODE2024-11-27
Linux KernelNot specified (all versions potentially affected)Infinite Loop in filemap_read()Medium (CVSS v3: 5.5)View or DownloadUNDERCODE2024-11-27
Linux KernelNot specified (all versions vulnerable before a fix is applied)Crash due to invalid pointer accessMedium (CVSS score not yet assigned)View or DownloadUNDERCODE2024-11-27
Linux KernelNot specifiedInteger overflow in damon_feed_loop_next_input functionModerate (CVSS score details might be available elsewhere)View or DownloadUNDERCODE2024-11-26
Linux Kernel(Unaffected versions not specified)Improper IO Mapping HandlingHighView or DownloadUNDERCODE2024-11-26
CRI-O!ERROR! B1251 -> Formula Error: Unexpected ,Malicious checkpoint file can lead to arbitrary node accessModerateView or DownloadUNDERCODE2024-11-26
TCPDF6.7.5Local File Inclusion (LFI)ModerateView or DownloadUNDERCODE2024-11-26
Tungsten Automation Power PDFAll versions (not specified)Out-of-Bounds Read Remote Code Execution (RCE) in JP2 file parsingCriticalView or DownloadUNDERCODE2024-11-26
Tungsten Automation Power PDFAll versions (not specified)JPG File Parsing Out-Of-Bounds ReadInformation Disclosure (allows attackers to see sensitive information)View or DownloadUNDERCODE2024-11-26
Tungsten Automation Power PDFAllJP2 File Parsing Out-Of-Bounds Read Remote Code ExecutionCriticalView or DownloadUNDERCODE2024-11-26
Tungsten Automation Power PDFNot specifiedOut-of-Bounds Read Information DisclosureNot officially rated (CVSS information not yet available)View or DownloadUNDERCODE2024-11-26
WordPressSirv plugin up to 7.3.0Unauthorized modification of data leading to Denial-of-Service (DoS)CriticalView or DownloadUNDERCODE2024-11-26
WordPress Restaurant Menu – Food Ordering System PluginUp to and including 2.4.2Reflected Cross-Site Scripting (XSS)Medium (CVSS v3: 6.1)View or DownloadUNDERCODE2024-11-26
WordPressContact Form 7 Email Add On plugin <= 1.9Local File InclusionHIGHView or DownloadUNDERCODE2024-11-26
WordPressWooCommerce Product Table Lite plugin versions up to 3.8.6Arbitrary Shortcode Execution & Reflected Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-11-26
FastStone Image ViewerAll versions before 7.8 are affected (unspecified in report)Out-of-Bounds Write in GIF ParsingCritical (Allows remote code execution)View or DownloadUNDERCODE2024-11-26
Tungsten Automation Power PDF(not specified)Out-of-Bounds Read in PDF ParsingInformation Disclosure (Exploitation likely requires additional vulnerabilities)View or DownloadUNDERCODE2024-11-26
PDF-XChange Editor (all versions)Not applicableOut-of-bounds write during PDF parsingCriticalView or DownloadUNDERCODE2024-11-26
Perl (Imager package)Before 1.0.25Heap-based buffer overflowCritical (CVSS details not provided)View or DownloadUNDERCODE2024-11-26
Ivanti Cloud Services Appliance (CSA)4.6 (before Patch 518)OS Command Injection (CVE-2024-8190)CriticalView or DownloadUNDERCODE2024-11-26
Use-After-Free leading to Remote Code ExecutionCritical (allows attackers to take full control of the system)View or DownloadUNDERCODE2024-11-26
WordPressWPGYM <= 67.1.0Unauthenticated Arbitrary File UploadCriticalView or DownloadUNDERCODE2024-11-26
WordPressWPGYM plugin up to 67.1.0Privilege EscalationModerate (CVSS score not yet available)View or DownloadUNDERCODE2024-11-26
AMD EPYC Processors (see below for affected models)Firmware versions up to (excluding) milanpi_1.0.0.d or genoapi_1.0.0.c (depending on the model)Details not specified in the excerpt, but likely exploitable by attackers.Critical (highest severity level)View or DownloadUNDERCODE2024-11-26
Dell PowerProtect DDPrior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50Access ControlCriticalView or DownloadUNDERCODE2024-11-26
IrfanViewAll versions (to be confirmed)Out-of-Bounds Read Remote Code Execution (RCE) in SID file parsingCriticalView or DownloadUNDERCODE2024-11-26
IBM Watson Query on Cloud Pak for Data, IBM Db2 Big SQL on Cloud Pak for Data1.8, 2.0, 2.1, 2.2 (Watson Query), 7.3, 7.4, 7.5, 7.6 (Db2 Big SQL)Insufficient session expirationCriticalView or DownloadUNDERCODE2024-11-26
PHP8.1. before 8.1.31, 8.2. before 8.2.26, 8.3. before 8.3.14HTTP Request Smuggling (CVE-2024-11234)CriticalView or DownloadUNDERCODE2024-11-26
Pandora FMS700 through <= 777.4Command Injection (LDAP Authentication)MEDIUMView or DownloadUNDERCODE2024-11-26
WordPressMy Contador lesr plugin <= 2.0Unauthenticated Stored Cross-Site Scripting (XSS)Medium (CVSS: 3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)View or DownloadUNDERCODE2024-11-26
WordPressDino Game - Embed Google Chrome Dinosaur Game plugin versions up to 1.1.0Stored Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-11-26
WordPressPure CSS Circle Progress Bar plugin <= 1.2Stored Cross-Site Scripting (XSS)Critical (Unauthenticated attackers can inject malicious scripts)View or DownloadUNDERCODE2024-11-26
WordPressUp to and including 1.1.6Reflected Cross-Site Scripting (XSS)Medium (CVSS: 6.1)View or DownloadUNDERCODE2024-11-26
WordPressTheater for WordPress <= 0.18.6.2Reflected Cross-Site Scripting (XSS)MediumView or DownloadUNDERCODE2024-11-26
Android(Not specified)Local Privilege Escalation through Screen CaptureCriticalView or DownloadUNDERCODE2024-11-26
Zoho ManageEngine Exchange Reporter Plus5714 and belowAuthenticated SQL injectionCriticalView or DownloadUNDERCODE2024-11-26
Jewel Theme Master Addons for ElementorAll versions up to 2.0.5.4.1 (uncertain about earlier versions)Missing AuthorizationCriticalView or DownloadUNDERCODE2024-11-26
HarmonyOS (based on source)Not specifiedMissing permission check in applyCustomDescription of SaveUi.javaHigh (Local Information Disclosure)View or DownloadUNDERCODE2024-11-26
KiviCareUp to 3.6.2Authorization Bypass Through User-Controlled KeyCriticalView or DownloadUNDERCODE2024-11-26
Keycloak Connector Server< 2.5.5Reflected XSSModerateView or DownloadUNDERCODE2024-11-26

sigstore-java

v1.0.0 (patched in v1.1.0)

Incomplete verification in KeylessVerifier.verify()

Critical

View or DownloadUNDERCODE2024-11-26
AndroidNot specified (All versions potentially affected)Confused Deputy in PrintManagerService.javaMediumView or DownloadUNDERCODE2024-11-26
Qualcomm Snapdragon FirmwareAllCWE-835 (Loop or Recursion Vulnerability)View or DownloadUNDERCODE2024-11-26
Qualcomm Multi-mode Call ProcessorNot Applicable (Affects All Versions)Denial-of-Service (DoS)MediumView or DownloadUNDERCODE2024-11-26

Unknown (reference to CWE-787 suggests Out-of-bounds Write)

Unknown (severity cannot be determined from this blog post)View or DownloadUNDERCODE2024-11-26
UkrSolution Barcode Scanner with Inventory & Order ManagerCriticalView or DownloadUNDERCODE2024-11-26
Lobe ChatBefore 1.19.13Unauthorized SSRFCritical (CVSS: 9.0)View or DownloadUNDERCODE2024-11-26
AndroidNot specified (all versions potentially affected)Out-of-bounds write due to missing bounds checkCritical (allows remote code execution)View or DownloadUNDERCODE2024-11-26
IrfanViewAll versions (unaffected versions not specified)DXF file parsing out-of-bounds read leading to RCECriticalView or DownloadUNDERCODE2024-11-26
IrfanViewAll versions (unaffected versions not yet identified)Out-of-bounds read in DXF file parsing leading to RCECriticalView or DownloadUNDERCODE2024-11-26
IrfanViewAll versions (unaffected version not specified yet)Out-of-Bounds Read Remote Code Execution (DXF File Parsing)CriticalView or DownloadUNDERCODE2024-11-26
CentreonAll versions before 22.04.24, 22.10.22, 23.04.18, 23.10.12, and 24.04.0 (not mentioned in the article)SQL Injection in the updateServiceHost functionCritical (allows remote code execution)View or DownloadUNDERCODE2024-11-26
Centreon WebAll versions before the fixes mentioned belowSQL Injection leading to Remote Code ExecutionCriticalView or DownloadUNDERCODE2024-11-26
Dell PowerProtect DDBefore 7.7.5.50Exposure of Sensitive Information to Unauthorized ActorLow (CVSS: 3.1)View or DownloadUNDERCODE2024-11-26
Dell PowerProtect Data DomainPrior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50Escalation of Privilege (EoP)Critical (CVSS score details not provided)View or DownloadUNDERCODE2024-11-26
Project Worlds Free Download Online Shopping SystemAll versions up to 192.168.1.88 (unclear if specific to this IP or a version range)SQL injectionCritical (CVSS score: 5.3 MEDIUM)View or DownloadUNDERCODE2024-11-26
ManageEngine ADAudit PlusBelow 8121SQL Injection (CVE-2024-5608)Critical (CVSS score: 8.3)View or DownloadUNDERCODE2024-11-26
emqx NeuronUp to 2.10.0Buffer OverflowCritical (CVSS v4.0: MEDIUM)View or DownloadUNDERCODE2024-11-26
E-Health Care System1.0SQL InjectionCriticalView or DownloadUNDERCODE2024-11-26
GitLab CE/EE16.0 to 17.3.6, 17.4 to 17.4.3, 17.5 to 17.5.1 (Fixed in 17.3.7, 17.4.4, 17.5.2)Unauthorized access to Kubernetes agent (CVE-2024-9693)High (CVSS score: 8.5)View or DownloadUNDERCODE2024-11-26
Python0.1.13Credential HarvestingHighView or DownloadUNDERCODE2024-11-25
Linux KernelNot specifiedOut-of-memory access in dvbdevHigh (CVSS score not provided)View or DownloadUNDERCODE2024-11-25
MLflowAffected versions are not explicitly specified.Excessive directory permissionsHighView or DownloadUNDERCODE2024-11-25
IrfanViewAll versionsHeap-based buffer overflow in JPM file parsingCriticalView or DownloadUNDERCODE2024-11-25
IrfanViewAll versionsDJVU File Parsing Use-After-Free Remote Code ExecutionCriticalView or DownloadUNDERCODE2024-11-25
IrfanViewAllHeap-based Buffer Overflow Remote Code ExecutionCriticalView or DownloadUNDERCODE2024-11-25
PDF File Parsing Out-Of-Bounds Read Information DisclosureLOWView or DownloadUNDERCODE2024-11-25
IrfanViewAll versions (unaffected versions not yet disclosed)Out-of-Bounds Read Remote Code Execution (RCE)CriticalView or DownloadUNDERCODE2024-11-25
IrfanViewAll versionsOut-of-Bounds Write in JPM File ParsingCriticalView or DownloadUNDERCODE2024-11-25
IrfanViewAll versionsDXF file parsing memory corruption leading to remote code executionCriticalView or DownloadUNDERCODE2024-11-25
IrfanViewAll versionsOut-of-bounds read during DWG file parsing leading to Remote Code Execution (RCE)Critical (CVSS score: 7.8)View or DownloadUNDERCODE2024-11-25
IrfanViewAll versions (not specified)Out-of-bounds write during ARW file parsingCritical (CVSS score: 7.8)View or DownloadUNDERCODE2024-11-25
IrfanViewAll versions (unaffected versions not specified)Out-of-bounds write during JPM file parsing (CVE-2024-11517)Critical (RCE)View or DownloadUNDERCODE2024-11-25
IrfanViewAll versions (unaffected versions not specified yet)DWG File Parsing Memory Corruption RCECriticalView or DownloadUNDERCODE2024-11-25
IrfanViewAll versions (unaffected versions not yet identified)DXF File Parsing Use-After-Free Remote Code ExecutionCriticalView or DownloadUNDERCODE2024-11-25
WordPressImagePress – Image Gallery plugin versions up to 1.2.2 (inclusive)Cross-Site Request Forgery (CSRF)Medium (CVSS v3 score not provided)View or DownloadUNDERCODE2024-11-25
IrfanViewAll versionsDXF File Parsing Memory Corruption Remote Code ExecutionCritical (CVSS: 7.8)View or DownloadUNDERCODE2024-11-25
Keycloak26 and earlierDenial-of-Service (DoS)CriticalView or DownloadUNDERCODE2024-11-25
Keycloak!ERROR! B1324 -> Formula Error: Unexpected ,Denial-of-Service (DoS)ModerateView or DownloadUNDERCODE2024-11-25
deno_docAll versions before a fix is releasedCross-site Scripting (XSS)LowView or DownloadUNDERCODE2024-11-25
Keycloak!ERROR! B1326 -> Formula Error: Unexpected ,Sensitive data exposureHighView or DownloadUNDERCODE2024-11-25
Dell SmartFabric OS10 Software10.5.3.x, 10.5.4.x, 10.5.5.x, 10.5.6.xImproper Neutralization of Special Elements (Command Injection)HIGHView or DownloadUNDERCODE2024-11-25
Keycloak!ERROR! B1328 -> Formula Error: Unexpected ,Sensitive data exposure during build processModerateView or DownloadUNDERCODE2024-11-25
Keycloak!ERROR! B1329 -> Formula Error: Unexpected ,Path TraversalLowView or DownloadUNDERCODE2024-11-25
Keycloak!ERROR! B1330 -> Formula Error: Unexpected ,Inefficient Regular Expression ComplexityView or DownloadUNDERCODE2024-11-25
Xiaomi Router AX9000Not specifiedPost-authorization Command InjectionMEDIUM (CVSS 3.1 base score: 6.4)View or DownloadUNDERCODE2024-11-25
IrfanViewAll versions (unspecified)Out-of-Bounds Write during SID File Parsing (Remote Code Execution)CriticalView or DownloadUNDERCODE2024-11-25
1000 Projects Beauty Parlour Management System1.0SQL InjectionCriticalView or DownloadUNDERCODE2024-11-25
Tungsten Automation Power PDFNot specifiedJPF File Parsing Out-Of-Bounds Write Remote Code ExecutionCriticalView or DownloadUNDERCODE2024-11-25
IrfanViewAll versions (unaffected versions not specified)WSQ File Parsing Out-Of-Bounds Write Remote Code ExecutionCriticalView or DownloadUNDERCODE2024-11-25
Tungsten Automation Power PDFNot specifiedPSD File Parsing Out-Of-Bounds Write Remote Code ExecutionCritical (CVSS score not provided, but the description indicates remote attackers can execute arbitrary code)View or DownloadUNDERCODE2024-11-25
Tungsten Automation Power PDFNot specifiedStack-based buffer overflow in TIF file parsingCriticalView or DownloadUNDERCODE2024-11-25
WordPressHUSKY - Products Filter Professional for WooCommerce plugin versions up to 1.3.6.3Reflected Cross-Site Scripting (XSS)MediumView or DownloadUNDERCODE2024-11-25
W3speedsterUp to 7.25Cross-Site Request Forgery (CSRF)CriticalView or DownloadUNDERCODE2024-11-25
Vivwebs Dynamic WidgetsUp to 1.6.4Cross-Site Request Forgery (CSRF)Medium (based on CVSS v3.1 score)View or DownloadUNDERCODE2024-11-25
XSS in error messagesLow (user-controlled input needed in error message)View or DownloadUNDERCODE2024-11-25

Taurus Multi-Party Signature Library

Not specified

Critical (both vulnerabilities)

View or DownloadUNDERCODE2024-11-25
Linux KernelNot specified (all versions potentially affected)Race condition in i40e driverModerate (CVSS score not provided)View or DownloadUNDERCODE2024-11-25
lxml (HTML cleaning functionality)Before 0.4.0Improper context handling for special HTML tags (SVG, Math, Noscript)Critical (CVSS score likely high)View or DownloadUNDERCODE2024-11-25
AndroidNot specifiedImproper Input Validation in CompanionDeviceManagerService.java (CVE-2024-0022)HighView or DownloadUNDERCODE2024-11-25
Linux KernelNot specifiedImproper reference count handling for CPU device nodes (RISC-V)Medium (CVSS v3 base score: 5.5)View or DownloadUNDERCODE2024-11-25
Linux KernelNot specified (likely impacts multiple versions)Improper resource handling in iwlwifi driver during AP stop/startMedium (CVSS 3.x Base Score: 5.5)View or DownloadUNDERCODE2024-11-25
Linux KernelNot specified (requires kernel update)Incorrect NULL vs IS_ERR() check in drm/tegra driverLow (CVSS v3 Base Score: 5.5)View or DownloadUNDERCODE2024-11-25
Linux KernelUnaffected versions not listed (potentially all before the fix)Out-of-bounds memory access in virtio_net driverHIGH (CVSS 3.1 base score: 7.1)View or DownloadUNDERCODE2024-11-25
emqx neuronUp to 2.10.0Information Disclosure (CVE-2024-10965)MEDIUMView or DownloadUNDERCODE2024-11-23
AMTT Hotel Broadband Operation SystemUp to 3.0.3.151204Cross-site scripting (XSS)Medium (CVSS score: 5.3)View or DownloadUNDERCODE2024-11-23
code-projects Task Manager1.0SQL InjectionCriticalView or DownloadUNDERCODE2024-11-23
Job Recruitment1.0Cross-site Scripting (XSS)MEDIUMView or DownloadUNDERCODE2024-11-23
WordPress Plugin - CTT Expresso para WooCommerceUp to 3.2.12 (inclusive)Sensitive Information ExposureMediumView or DownloadUNDERCODE2024-11-23
Code4Berry Decoration Management System1.0Improper Access ControlCriticalView or DownloadUNDERCODE2024-11-23
Dropbox DesktopAllMark-of-the-Web BypassCriticalView or DownloadUNDERCODE2024-11-23
WordPressFundEngine plugin versions up to and including 1.7.0Privilege EscalationCriticalView or DownloadUNDERCODE2024-11-23
Code4Berry Decoration Management System1.0Permission Issues (User Handler - /decoration/admin/userregister.php)CriticalView or DownloadUNDERCODE2024-11-23
Linux KernelNot specified (potentially all versions before the fix)mctp i2c NULL header address handlingMedium (CVSS score not provided)View or DownloadUNDERCODE2024-11-22
All versions before the fixMemory LeakMedium (CVSS score to be determined)View or DownloadUNDERCODE2024-11-22
Linux KernelNot specifiedNull pointer dereference in firmware:qcom:scmMedium (CVSS score not provided)View or DownloadUNDERCODE2024-11-22
MBed OS6.16.0Buffer Overflow (CVE-2024-48982)CriticalView or DownloadUNDERCODE2024-11-22
Code4Berry Decoration Management System1.0User Permission Handling Vulnerability (CVE-2024-11486)MediumView or DownloadUNDERCODE2024-11-22
Mbed OS6.16.0Buffer Overflow (CVE-2024-48986)CriticalView or DownloadUNDERCODE2024-11-22
Tailoring Management System1.0 (Unaffected versions not specified)SQL Injection through /expcatedit.php argument manipulation (id)Medium (CVSS v4.0 Base Score: 5.3)View or DownloadUNDERCODE2024-11-22
Code4Berry Decoration Management System1.0SQL Injection (CVE-2024-11487)CriticalView or DownloadUNDERCODE2024-11-22
1000 Projects Bookstore Management System1.0SQL InjectionCriticalView or DownloadUNDERCODE2024-11-22
AVL-DiTEST-DiagDev libdoip1.0.0Null Pointer Dereference in DoIPConnection::reactOnReceivedTcpMessageMediumView or DownloadUNDERCODE2024-11-22
idcCMS1.60Cross-Site Scripting (XSS)MediumView or DownloadUNDERCODE2024-11-22
Linux KernelNot specified (all versions with vulnerable bnxt_re driver)Out-of-bounds memory accessModerate (CVSS v3 base score: 5.5)View or DownloadUNDERCODE2024-11-22
smol-toml<1.3.1Stack OverflowLowView or DownloadUNDERCODE2023-11-13
TornadoPrior to 6.4.2HTTP Cookie Parsing DoSHighView or DownloadUNDERCODE2024-11-22
SentryAll versions before next releasePotential Client ID and Secret exposure in error messageLowView or DownloadUNDERCODE2024-11-22
UAMQP C libraryUnaffected versions not specifiedRemote Code Execution (RCE)Critical (CVSS score likely high)View or DownloadUNDERCODE2024-11-22
WordPressUp to and including 1.7.2Stored Cross-Site Scripting (XSS)MediumView or DownloadUNDERCODE2024-11-22
java_shop1.0File Upload VulnerabilityNot yet rated by NISTView or DownloadUNDERCODE2024-11-22
AndroidNot specified (all versions before August 2024 patch)Logic error in OwnersData.javaHighView or DownloadUNDERCODE2024-11-22
LibreNMSNot specifiedReflected XSS (CVE-2024-51496)MediumView or DownloadUNDERCODE2024-11-22
ManageEngine ADAudit PlusBelow 8110Authenticated SQL Injection (CVE-2024-36518)HighView or DownloadUNDERCODE2024-11-22
Zyxel P-6101C ADSL modemP-6101CSA6AP_20140331Improper AuthenticationHIGHView or DownloadUNDERCODE2024-11-22
LibreNMSAll versions before 24.10.0Reflected XSSCriticalView or DownloadUNDERCODE2024-11-22
WordPressBreakdance versions up to 1.7.2 (inclusive)Unauthorized Access of DataMediumView or DownloadUNDERCODE2024-11-22
java_shop1.0Incorrect Access ControlCritical (CVSS details not yet available)View or DownloadUNDERCODE2024-11-22
SourceCodester Student Record Management System1.0Memory CorruptionCriticalView or DownloadUNDERCODE2024-11-22
Querydsl5.1.0SQL/HQL InjectionHighView or DownloadUNDERCODE2024-11-22
Not specified (versions 3.2.0 through 4.1.3 are vulnerable)Server-Side Request Forgery (SSRF)High (CVSS score: 7.5)View or DownloadUNDERCODE2024-11-22
SFTPGoAll versionsArbitrary Command ExecutionCriticalView or DownloadUNDERCODE2023-10-24
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHigh (CVSS Score: 7.8)View or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHigh (CVSS Score: 7.8)View or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
Luxion KeyShotNot specifiedRemote Code Execution (RCE) through jt file parsingCritical (CVSS score: 7.8)View or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
Luxion KeyShotNot specifiedStack overflow due to improper validation in 3DS file parsingCritical (CVSS score: 7.8)View or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code Execution (RCE)High (CVSS Score: 7.8)View or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHigh (CVSS Score: 7.8)View or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHigh (CVSS Score: 7.8)View or DownloadUNDERCODE2024-11-22
Adobe InDesign(not specified)Information DisclosureLowView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-18
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHigh (CVSS Score: 7.8)View or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
Linux KernelNot specifiedDivision by zero error in v4l2-tpgMediumView or DownloadUNDERCODE2024-11-22
Linux KernelNot specified (all versions potentially affected)Slab-use-after-free in ksmbd_smb2_session_createHigh (CVSS score: 7.8)View or DownloadUNDERCODE2024-11-22
Linux kernelNot specifiedSlab-use-after-free in smb3_preauth_hash_rsp functionHIGH (CVSS v3 score not provided)View or DownloadUNDERCODE2024-11-22
Linux KernelNot specified (all versions vulnerable before a fix)SCTP Chunk Size Validation Error (CVE-2024-50299)Not officially rated by NIST (NVD) yetView or DownloadUNDERCODE2024-11-22
Linux KernelNot specifiedBuffer overflow in amdgpu_debugfs_gprwave_read() functionMedium (CVSS v2: 4.6, CVSS v3: 7.8)View or DownloadUNDERCODE2024-11-22
Linux KernelNot specified (all versions potentially affected)Uninitialized use of regulator_config in rtq2208 driverHigh (CVSS score not yet available from NVD)View or DownloadUNDERCODE2024-11-22
SourceCodester Student Record Management System1.0Stack-based buffer overflowCriticalView or DownloadUNDERCODE2024-11-22
AndroidNot specified (all versions before March 2024 security patch)Local Information Disclosure (exercise route data)HighView or DownloadUNDERCODE2024-11-22
AndroidNot specifiedIncorrect tag used during device policy serialization (CVE-2024-0047)High (Potential for DoS)View or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-21
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-21
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-21
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHigh (CVSS Score: 7.8)View or DownloadUNDERCODE2024-11-21
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-21
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-21
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-21
IrfanViewAffected versions prior to 4.70Remote Code Execution (RCE)High (CVSS Score: 7.8)View or DownloadUNDERCODE2024-11-21
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHigh (CVSS Score: 7.8)View or DownloadUNDERCODE2024-11-21
IrfanView4.69 and earlierRemote Code ExecutionHighView or DownloadUNDERCODE2024-11-21
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-21
Linux Kernel(Not specified in the provided information)Improper access control in raw_copy_{to,from}_user() functionsCritical (CVSS score not yet available)View or DownloadUNDERCODE2024-11-21
Linux KernelNot specified (all versions potentially affected)Use-after-free in USB serial io_edgeport codeMedium (CVSS v2 score: 4.6, CVSS v3 score: 7.8)View or DownloadUNDERCODE2024-11-21
Linux KernelAll versions before the fix for CVE-2024-50265 are vulnerable.Null pointer dereference in ocfs2_xa_remove() functionCriticalView or DownloadUNDERCODE2024-11-21
Linux Kernel(Not specified in the provided information)Flaw in sch_cake's flow accounting logicMediumView or DownloadUNDERCODE2024-11-21
Linux KernelUnaffected versions not specifiedUse-After-Free in vsock/virtio (CVE-2024-50264)Critical (CVSS v3 score details not provided)View or DownloadUNDERCODE2024-11-21
Linux KernelNot specified (all versions vulnerable before fix)Double free of TX skbCriticalView or DownloadUNDERCODE2024-11-21
Oracle Agile PLM Framework9.3.6Information DisclosureHIGH (CVSS Score: 7.5)View or DownloadUNDERCODE2024-11-21
Opencast13 and 14Infinite loop with Elasticsearch queriesCriticalView or DownloadUNDERCODE2024-11-20
LitestarAll versionsDenial of Service (DoS)CriticalView or DownloadUNDERCODE2024-11-20
Microsoft SharePoint ServerNot specifiedRemote Code Execution (RCE)Critical (CVSS score: 7.2)View or DownloadUNDERCODE2024-11-20
Linux KernelNot specified (potential impact on all versions)Information DisclosureLowView or DownloadUNDERCODE2024-11-20
Linux KernelNot specified (likely affects multiple versions)Firmware crash due to invalid peer nss value in association requestModerate (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-11-20
Qualcomm Multiple ProductsVariousMultiple VulnerabilitiesVariesView or DownloadUNDERCODE2024-11-20
Linux KernelNot specified (all versions potentially affected)io_uring overflow handling flawLowView or DownloadUNDERCODE2024-11-20
Linux KernelNot specifiedMemory access issue in drm/amd/display codeModerate (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-11-20
cert-managerAll versions since v0.1.0Denial-of-service (DoS)MediumView or DownloadUNDERCODE2024-11-20
7-ZipAffected versions prior to 24.07Remote Code ExecutionHigh (CVSS Score: 7.8)View or DownloadUNDERCODE2024-11-20
N/AN/AN/AN/AView or DownloadUNDERCODE2024-11-20
Undercoding (mentioned in the article but not a security vulnerability)N/A (Undercoding is not a security vulnerability)View or DownloadUNDERCODE2024-11-20
Linux KernelNot specified (all versions potentially affected)Race condition in ntfs3 driverModerate (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-11-20
Qualcomm devices(not specified)(not specified)(not specified)View or DownloadUNDERCODE2024-11-20
Qualcomm(see article for specific versions)Potential Remote CompromiseCriticalView or DownloadUNDERCODE2024-11-20
D-Link DI-803316.07.26A1Buffer Overflow (CVE-2024-52759)Critical (CVSS v3 score: 9.8)View or DownloadUNDERCODE2024-11-20
Monoprice Select Mini V2V37.115.32Improper input validation in printing filesMedium (CVSS 3.x Base Score: 5.5)View or DownloadUNDERCODE2024-11-20
WordPress Testimonials Widget PluginUp to and including 4.0.4Stored Cross-Site Scripting (XSS)Unlisted (CVSS score not provided)View or DownloadUNDERCODE2024-11-20
Tenda AC6v2.0 v15.03.06.50Buffer overflow in function "fromSetSysTime" (CVE-2024-52714)Critical (CVSS v3 score: 9.8)View or DownloadUNDERCODE2024-11-20
Linux KernelNot specifiedInteger overflow in drm/amd/display codeModerateView or DownloadUNDERCODE2024-11-20
Cosmos SDKcosmossdk.io/math versions <= math/v1.3.0Mismatched bit-length validation in sdk.Int and sdk.DecHighView or DownloadUNDERCODE2024-11-20
MoodleInsecure Direct Object Reference (IDOR)ModerateView or DownloadUNDERCODE2024-11-20
django CMSBefore 4.0Cross-site Scripting (XSS)ModerateView or DownloadUNDERCODE2024-11-20
Linux KernelNot specified (likely affects multiple versions)Improper synchronization when accessing superblock bufferModerate (CVSS v3 base score: 5.5)View or DownloadUNDERCODE2024-11-20
Linux KernelNot specified (potentially all versions with aforementioned configurations enabled)Out-of-bounds read (based on CVE description)Medium (according to CVE details, no exploit exists)View or DownloadUNDERCODE2024-11-20
N/AN/AN/AN/AView or DownloadUNDERCODE2024-11-20
Buffer overflow in `amdgpu_dm` initializationUnknown (CVSS score not yet available)View or DownloadUNDERCODE2024-11-20
Cisco Identity Services Engine (ISE)All versions (at the time of publishing)Cross-site Scripting (XSS)Medium (CVSS score: 6.1)View or DownloadUNDERCODE2024-11-20
Cisco Identity Services Engine (ISE)
All versions (at the time of publication)
Cross-site Scripting (XSS)
MEDIUM
View or DownloadUNDERCODE2024-11-20
Cisco Identity Services Engine (ISE)
All versions (at the time of publication)
Cross-site Scripting (XSS)
MEDIUM
View or DownloadUNDERCODE2024-11-20
Cisco ISEAll versions (at the time of publishing)XXE (CVE-2024-20531)MEDIUM (CVSS score: 5.5)View or DownloadUNDERCODE2024-11-20
Linux KernelAll versions before 6.11.7Null Pointer Dereference (CVE-2024-53050)MediumView or DownloadUNDERCODE2024-11-20
Cisco Identity Services Engine (ISE)All versions (at the time of publication)Cross-site Scripting (XSS)MEDIUMView or DownloadUNDERCODE2024-11-20
Linux kernelNot specifiedNull pointer dereference in `intel_hdcp_get_capability`Medium (CVSS score not yet available)View or DownloadUNDERCODE2024-11-20
Anton Hoelstad WP Quick Setup<= 2.0Unrestricted Upload of File with Dangerous TypeCriticalView or DownloadUNDERCODE2024-11-20
Mindstien Technologies My Geo Posts FreeAll versions up to 1.2 (inclusive)Deserialization of Untrusted DataCriticalView or DownloadUNDERCODE2024-11-20
WordPress Video Robot - The Ultimate Video ImporterAll versions up to 1.20.0SQL InjectionCriticalView or DownloadUNDERCODE2024-11-20
Lis Video GalleryUp to 0.2.1Deserialization of Untrusted DataCriticalView or DownloadUNDERCODE2024-11-20
Post SMTPAll versions up to 2.9.9SQL InjectionCriticalView or DownloadUNDERCODE2024-11-20
GLPIAll versions before 10.0.17Reflected XSSMediumView or DownloadUNDERCODE2024-11-20
GLPIAll versions before 10.0.17SQL InjectionHigh (CVSS score: 8.1)View or DownloadUNDERCODE2024-11-20
code-projects Job Recruitment1.0SQL InjectionCriticalView or DownloadUNDERCODE2024-11-20
Saso Nikolov Event Tickets with Ticket Scannern/a - 2.3.11Improper Neutralization of Special Elements Used in a Template EngineCriticalView or DownloadUNDERCODE2024-11-20
3.1Heap-Overflow Vulnerability in DCERPC ProtocolCRITICALView or DownloadUNDERCODE2024-11-20
LibreNMSAll versions before 24.10.0Stored Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-11-20
LibreNMSAll versions before 24.10.0Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-11-20
MoodleAll versions before 4.5.0-rc2 (unconfirmed)Improper AuthorizationMedium (CVSS v2 score: 5.0, CVSS v3 score: 6.5)View or DownloadUNDERCODE2024-11-20
LibreNMSAll versions before 24.10.0Stored XSSMediumView or DownloadUNDERCODE2024-11-20
LibreNMSUnaffected versions not listed (all versions before 24.10.0 likely vulnerable)Stored Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-11-20
MoodleVersions before 4.5.0-rc2 are affected (unclear which specific versions)Improper AuthorizationMedium (CVSS v2 score: 6.4, CVSS v3 score: 4.3)View or DownloadUNDERCODE2024-11-20
LibreNMSAll versions before 24.10.0Stored XSSCriticalView or DownloadUNDERCODE2024-11-20
Urchenko Drozd – Addons for ElementorUp to 1.1.1Stored XSS (Cross-site Scripting) (CVE-2024-52425)Medium (CVSS details not specified)View or DownloadUNDERCODE2024-11-20
MoodleAll versions before 4.1.14, 4.2.11, 4.3.8, 4.4.4 (not exhaustive)Information DisclosureMediumView or DownloadUNDERCODE2024-11-20
WordPressLinear plugin <= 2.7.11Cross-site Scripting (XSS)Medium (CVSS details not specified)View or DownloadUNDERCODE2024-11-20
LibreNMSAll versions before 24.10.0Stored Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-11-20
LibreNMSUnaffected versions not listed (all versions before 24.10.0 likely vulnerable)Stored XSSCriticalView or DownloadUNDERCODE2024-11-20
LibreNMSAll versions before 24.10.0Stored Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-11-20
SourceCodester Online Eyewear Shop1.0Cross-Site Scripting (XSS)MediumView or DownloadUNDERCODE2024-11-20
WindowsSecureID Software Token for Microsoft WindowsRemote Code ExecutionHighView or DownloadUNDERCODE2024-11-19
eDrawings ViewerAll versions from SOLIDWORKS 2024 through 2025 (unspecified)Heap-based buffer overflow and uninitialized variable vulnerabilities in X_B and SAT file parsingCritical (CVSS: 7.8)View or DownloadUNDERCODE2024-11-19
1000 Projects Beauty Parlour Management System1.0SQL InjectionCriticalView or DownloadUNDERCODE2024-11-19
WordPressWP Activity Log plugin versions up to 5.2.1Stored Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-11-19
GLPIAll versions before 10.0.17 (vulnerable)Access Control Bypass (CVE-2024-45611)MediumView or DownloadUNDERCODE2024-11-19
WordPressTripetto plugin versions up to 8.0.3Stored Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-11-19
1000 Projects Beauty Parlour Management System1.0SQL InjectionCriticalView or DownloadUNDERCODE2024-11-19
1000 Projects Portfolio Management System MCA1.0SQL injectionCriticalView or DownloadUNDERCODE2024-11-19
Farmacia1.0 (all versions likely affected)Cross-Site Scripting (XSS)MediumView or DownloadUNDERCODE2024-11-19
Adobe Audition23.6.9, 24.4.6 and earlierOut-of-bounds read vulnerabilityMedium (CVSS: 5.5)View or DownloadUNDERCODE2024-11-19
Microsoft VHDX(Not specified)Denial-of-Service (DoS)Medium (CVSS score: 5.9)View or DownloadUNDERCODE2024-11-19
GLPIAll versions before 10.0.17Reflected XSS (CVE-2024-45609)Medium (CVSS v3.1 score: 6.5) - Though some sources list it as High (CVSS v2 score: 7.8)View or DownloadUNDERCODE2024-11-19
WordPressUp to and including 2.5.7Stored Cross-Site Scripting (XSS)MediumView or DownloadUNDERCODE2024-11-19
WindowsNot specifiedElevation of Privilege in USB Video Class System DriverMEDIUM (CVSS score: 6.8)View or DownloadUNDERCODE2024-11-19
Windows SMBv3 Server(not specified in this article)Remote Code Execution (RCE)High (CVSS score: 8.1)View or DownloadUNDERCODE2024-11-19
GLPIAll versions before 10.0.17Reflected Cross-Site Scripting (XSS)Pending analysis by NISTView or DownloadUNDERCODE2024-11-19
WordPress Plugin (The Music Player for Elementor)All versions up to 2.4.1Unauthorized modification of data (CVE-2024-10582)CriticalView or DownloadUNDERCODE2024-11-19
Remote Code ExecutionHigh (CVSS score: 8.8)View or DownloadUNDERCODE2024-11-19
Ceph RGW (civetweb)Not specifiedMultiple connection establishment to exhaust file descriptorsDenial-of-Service (DoS)View or DownloadUNDERCODE2024-11-19
Intel Server Board M10JNP2SB Family (exact versions not specified)Not specifiedImproper input validation in UEFI firmwareHigh (CVSS score: 7.5 - 8.7 depending on the version of CVSS used)View or DownloadUNDERCODE2024-11-19
Windows Registry Elevation of Privilege VulnerabilityHIGH (CVSS score: 7.5)View or DownloadUNDERCODE2024-11-19
ImageMagick, GraphicsMagickBefore 1.3.24 (both platforms)Arbitrary Code ExecutionNot specified (CVSS score likely available elsewhere)View or DownloadUNDERCODE2024-11-19
ImageMagickNot specified (versions before the fix are vulnerable)Out-of-bounds write via PDB fileMedium (CVSS v3 score: 6.5)View or DownloadUNDERCODE2024-11-19
LittleCMS (lcms or liblcms)Before 1.18beta2Multiple integer overflowsHigh (CVSS v2 score: 9.3)View or DownloadUNDERCODE2024-11-19
.NET Core9.0Denial of Service (DoS)High (CVSS v3 base score: 7.5)View or DownloadUNDERCODE2024-11-19
tsMuxernightly-2024-05-12-02-01-18 (specific version only)Heap-based buffer under-readNot specified (CVSS score not provided)View or DownloadUNDERCODE2024-11-19
Improper Access Control in UEFI firmwareNot yet analyzed by NVDView or DownloadUNDERCODE2024-11-19
GentleSource AppointmindAll versions before 4.0.0Cross-Site Request Forgery (CSRF) leading to Stored XSSHigh (based on CVE details)View or DownloadUNDERCODE2024-11-19
rclonev1.68.1Insecure Handling of SymlinksHighView or DownloadUNDERCODE2024-11-19
Siemens Tecnomatix Plant SimulationAll versions before V2302.0018 and V2404.0007Out-of-bounds read vulnerability in WRL file parsingHigh (CVSS v3.1 score: 7.8)View or DownloadUNDERCODE2024-11-19
Siemens Tecnomatix Plant Simulation(not specified)Remote Code Execution (RCE) through WRL file parsingHigh (CVSS v3 score: 7.8)View or DownloadUNDERCODE2024-11-19
Siemens Tecnomatix Plant SimulationNot specifiedRemote Code Execution (RCE) through WRL file parsingView or DownloadUNDERCODE2024-11-19
Cesanta Mongoose Web Server7.14Use of Out-of-range Pointer OffsetMediumView or DownloadUNDERCODE2024-11-19
Cesanta Mongoose Web Server7.14Improper Neutralization of DelimitersMedium (CVSS 3.1 score: 4.0)View or DownloadUNDERCODE2024-11-19
Cesanta Mongoose Web Serverv7.14Out-of-range Pointer OffsetMediumView or DownloadUNDERCODE2024-11-19
Cesanta Mongoose Web Server7.14Use of Out-of-range Pointer OffsetMediumView or DownloadUNDERCODE2024-11-19
Cesanta Mongoose Web Server7.14Use of Out-of-range Pointer OffsetHigh (CVSS Score: 8.5)View or DownloadUNDERCODE2024-11-19
EyouCMS1.51Path TraversalMediumView or DownloadUNDERCODE2024-11-19
Cesanta Mongoose Web Server7.14Integer Overflow or WraparoundHigh (CVSS v2 score: 7.8, CVSS v3 score: 7.5)View or DownloadUNDERCODE2024-11-19
Craft CMSPrior to 4.12.2 and 5.4.3Remote Code Execution (RCE) via Twig Server-Side Template Injection (SSTI)HighView or DownloadUNDERCODE2024-11-19
Cesanta Mongoose Web Server7.14Improper Neutralization of DelimitersMediumView or DownloadUNDERCODE2024-11-19
Cesanta Mongoose Web Server7.14Use of Out-of-range Pointer OffsetMedium (CVSS score: 4.3)View or DownloadUNDERCODE2024-11-19
Craft CMSAll versions before 5.4.9 and 4.12.8Information DisclosureHighView or DownloadUNDERCODE2024-11-19
Apache Kafka2.3.0 - 3.5.2, 3.6.2, 3.7.0Improper Privilege ManagementHighView or DownloadUNDERCODE2023-10-17
Linux kernelNot specified (likely affects multiple versions)Unbalanced locking in pc_clock_settime()Moderate (CVSS v3: 5.5, CVSS v4: 6.8)View or DownloadUNDERCODE2024-11-19
ImageMagickNot specifiedDenial-of-Service (DoS) via crafted PSD fileMedium (CVSS score: 6.5)View or DownloadUNDERCODE2024-11-19
Security Center application (vendor not specified)All versions (not specified)HTML InjectionMedium (CVSS 3.x Base Score: 5.9)View or DownloadUNDERCODE2024-11-19
Linux KernelNot specifiedNamespace copy issue (rbtree removal)Not provided (CVSS details likely missing from provided text)View or DownloadUNDERCODE2024-11-19
Linux KernelNot specifiedMemory Corruption in RDMA/bnxt_re driverNot specified (CVSS score not provided)View or DownloadUNDERCODE2024-11-19
Linux kernelNot specifiedImproper locking during sub buffer order change (CVE-2024-50207)Medium (CVSS score not explicitly mentioned)View or DownloadUNDERCODE2024-11-19
WordPressRoyal Elementor Addons and Templates plugin versions up to 1.7.1001Stored Cross-Site Scripting (XSS)Medium (CVSS 3.1 Base Score: 6.4)View or DownloadUNDERCODE2024-11-19
OpenEMR7.0.1Stored XSSHigh (CVSS score not yet available)View or DownloadUNDERCODE2024-11-19
VK All in One Expansion UnitPrior to 9.100.1.0Cross-site scripting (XSS)Medium (CVSS v3 score: 4.8)View or DownloadUNDERCODE2024-11-19
Linux KernelNot specified (potentially all versions using nilfs2)Improper Error Handling in nilfs2Not yet assigned a CVSS score (as of November 19, 2024)View or DownloadUNDERCODE2024-11-19
WordPressAFI plugin up to and including 1.92.0Reflected Cross-Site Scripting (XSS)Medium (CVSS not yet analyzed)View or DownloadUNDERCODE2024-11-19
WordPressRoyal Elementor Addons and Templates plugin versions up to 1.7.1001Stored Cross-Site Scripting (XSS)MediumView or DownloadUNDERCODE2024-11-19
calibre-webNot specifiedCross-site Scripting (XSS)MediumView or DownloadUNDERCODE2024-11-19
WordPressUp to 2.9.5Local File Inclusion (LFI)Critical (CVSS 3.x Base Score: 9.8)View or DownloadUNDERCODE2024-11-19
WordPressMultiManager WP – Manage All Your WordPress Sites Easily plugin (up to 1.0.5)Authentication BypassCriticalView or DownloadUNDERCODE2024-11-19
WordPressRoyal Elementor Addons and Templates plugin versions up to 1.7.1001Stored Cross-Site Scripting (XSS)MediumView or DownloadUNDERCODE2024-11-19
Thunderbird< 128.4.3 and < 132.0.1Disclosure of plaintext in OpenPGP encrypted messagesNot specified (CVSS score likely available elsewhere)View or DownloadUNDERCODE2024-11-19
DolibarrVersions before 'develop' branchImproper AuthorizationMediumView or DownloadUNDERCODE2024-11-19
HarborUnaffected versions not specified (all versions before 2.5.2 likely vulnerable)Improper AuthorizationNot available in provided resourcesView or DownloadUNDERCODE2024-11-19
calibre-webUnknownImproper Access ControlLowView or DownloadUNDERCODE2024-11-19
HarborNot specifiedImproper AuthorizationHigh (CVSS: 7.4)View or DownloadUNDERCODE2024-11-19
SourceCodester Best Employee Management System1.0SQL InjectionMediumView or DownloadUNDERCODE2024-11-19
Harbor1.0 through 1.10.12, 2.0 through 2.4.2 and 2.5 through 2.5.1 (all versions before the fix)Improper AuthorizationHighView or DownloadUNDERCODE2024-11-19
Harbor(Unaffected versions not specified)Insecure Direct Object Reference (IDOR) - CVE-2022-31667High (CVSS details not yet available)View or DownloadUNDERCODE2024-11-19
PHPGurukul User Registration & Login and User Management System3.2Reflected Cross-Site Scripting (XSS)Not officially rated, but likely medium based on similar vulnerabilities.View or DownloadUNDERCODE2024-11-19
HarborAll versions before 2.5.2Insecure Direct Object Reference (IDOR)HighView or DownloadUNDERCODE2024-11-19
SourceCodester Best Employee Management System1.0 (all versions likely affected)SQL InjectionMedium (CVSS v3: 5.1)View or DownloadUNDERCODE2024-11-19
VIWIS LMS9.11Missing Authorization in Print HandlerCriticalView or DownloadUNDERCODE2024-11-19
phpipamAll versions before 1.4.7Cross-Site Scripting (XSS)LowView or DownloadUNDERCODE2024-11-19
WordPress (Hoo Addons for Elementor plugin)Up to 1.0.6Cross-Site Scripting (XSS)Not yet determined (CVSS information is undergoing analysis)View or DownloadUNDERCODE2024-11-18
Kashipara E-learning Management System Project1.0SQL InjectionCritical (CVSS v3 score: 9.8)View or DownloadUNDERCODE2024-11-18
WindowsMultiple versionsElevation of PrivilegeHighView or DownloadUNDERCODE2024-11-18
NTLM Hash Disclosure Spoofing Vulnerability (CVE-2024-43451)Medium (CVSS score: 6.5)View or DownloadUNDERCODE2024-11-18
Palo Alto Networks ExpeditionNot specifiedSQL Injection (CVE-2024-9465)Critical (CVSS score: 9.2)View or DownloadUNDERCODE2024-11-18
Nostromo nhttpd<= 1.9.6Directory TraversalCritical (Remote Code Execution)View or DownloadUNDERCODE2024-11-18
PTZOptics PT30X-SDI/NDI-xxBefore 6.3.40Insufficient Authentication (CVE-2024-8956)Critical (CVSS Score: 9.1)View or DownloadUNDERCODE2024-11-18
Palo Alto Networks ExpeditionAll versions before 1.2.96 (including 1.2.0)OS Command InjectionCRITICAL (CVSS score: 9.9)View or DownloadUNDERCODE2024-11-18
Roundcube WebmailBefore 1.5.7 and 1.6.x before 1.6.7XSS via SVG animate attributesMedium (CVSS score: 6.1)View or DownloadUNDERCODE2024-11-18
PTZOptics PT30X-SDI/NDI-xxBefore 6.3.40OS Command Injection (CVE-2024-8957)HIGH (CVSS: 7.2)View or DownloadUNDERCODE2024-11-18
View or DownloadUNDERCODE2024-11-18
9.0.0.M30Deserialization of untrusted data vulnerabilityCRITICALView or DownloadUNDERCODE2024-11-18
Metabase< 0.40.5 and < 1.40.5Local File Inclusion (LFI)CRITICALView or DownloadUNDERCODE2023-11-28
Windows KernelAllElevation of PrivilegeHIGHView or DownloadUNDERCODE2024-11-18
Palo Alto Networks ExpeditionAll versions before 1.2.92Missing AuthenticationCRITICAL (CVSS Score: 9.3)View or DownloadUNDERCODE2024-11-18
ScienceLogic SL1 (formerly EM7)All versions before 12.1.3, 12.2.3, and 12.3+Remote Code Execution (RCE) due to unspecified third-party component vulnerability (CVE-2024-9537)CRITICAL (CVSS v2: 9.8, CVSS v3: 9.3)View or DownloadUNDERCODE2024-11-18
RavpnMultiple versions affectedRemote Access VPN (RAVPN) Service Denial of Service (DoS) VulnerabilityMEDIUMView or DownloadUNDERCODE2024-11-18
Jira

Critical

View or DownloadUNDERCODE2024-11-18
Spring MVCVulnerable versionsDoSModerateView or DownloadUNDERCODE2024-11-19
Apache Tomcat11.0.0-M23 through 11.0.0-M26, 10.1.27 through 10.1.30, 9.0.92 through 9.0.95Request and/or response mix-upModerateView or DownloadUNDERCODE2024-11-19
Rust crate `sharks`Affected versionsShamir Secret Sharing biasMediumView or DownloadUNDERCODE2024-11-19
django CMS3.11.7, 3.11.8, 4.1.2, 4.1.3Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-11-19
aiohttp(Affected versions)Memory LeakModerateView or DownloadUNDERCODE2024-11-19
PhpSpreadsheetAll versions before 1.9.4, 2.1.3, 2.3.2, and 3.4.0XXE (XML External Entity)HighView or DownloadUNDERCODE2024-11-19
Moodle!ERROR! B1616 -> Formula Error: Unexpected ,IDOR (Insecure Direct Object Reference)ModerateView or DownloadUNDERCODE2024-11-19
Debezium database connector[Specific version affected]Script injectionModerateView or DownloadUNDERCODE2024-11-19
< v2.10.2Multiple Command Injection VulnerabilitiesMediumView or DownloadUNDERCODE2024-11-19
MoodleIDORModerateView or DownloadUNDERCODE2024-11-19
Cobbler3.0.0 - 3.2.2 / 3.3.6 (all prior to 3.2.3 and 3.3.7)Improper AuthenticationCriticalView or DownloadUNDERCODE2024-11-19
MoodleUnauthorized deletion of report audiencesModerateView or DownloadUNDERCODE2024-11-19
UndertowIncorrect Cookie ParsingHighView or DownloadUNDERCODE2024-11-19
Graylog6.1.0, 6.1.1Concurrent PDF report rendering information leakageHighView or DownloadUNDERCODE2024-11-19
PhpSpreadsheet= 2.0.0 = 2.2.0 = 3.3.0 < 3.4.0XXE (XML External Entity)HighView or DownloadUNDERCODE2024-11-19
LibreNMS(Unaffected versions to be filled by official source)Stored XSSCriticalView or DownloadUNDERCODE2024-11-19
aiohttpVulnerable versionsRequest SmugglingModerateView or DownloadUNDERCODE2024-11-19
Regular Expression Denial of Service (ReDoS)LowView or DownloadUNDERCODE2024-11-19
OpenStack[Specific Version Affected]Improper Deletion of Access RulesModerateView or DownloadUNDERCODE2024-11-19
Elevation of Privilege in Secure Kernel ModeMedium (CVSS v3.1 base score: 6.7)View or DownloadUNDERCODE2024-11-19
Elevation of PrivilegeMedium (CVSS score: 6.8)View or DownloadUNDERCODE2024-11-19
Elevation of Privilege in DWM Core LibraryHIGH (CVSS 3.1 base score: 7.8)View or DownloadUNDERCODE2024-11-19
WindowsNot specified (all Windows versions with Kerberos are likely vulnerable)Remote Code Execution (RCE)Critical (CVSS 3.x score: 9.8)View or DownloadUNDERCODE2024-11-19
Windows (affected versions not specified)Not specifiedElevation of Privilege in USB Video Class System DriverMedium (CVSS v3 score: 6.8)View or DownloadUNDERCODE2024-11-19
Windows(not specified)Windows Registry Elevation of PrivilegeHIGH (CVSS v3 score: 7.8)View or DownloadUNDERCODE2024-11-19
TorchGeo (exact platform unspecified)UnknownRemote Code Execution (RCE)HIGH (CVSS score: 8.1)View or DownloadUNDERCODE2024-11-19
Client-Side Caching Elevation of PrivilegeHIGH (CVSS v3 score: 7.8)View or DownloadUNDERCODE2024-11-19
Win32k Elevation of Privilege VulnerabilityHIGH (CVSS v3.1 base score: 7.8)View or DownloadUNDERCODE2024-11-19
Windows KernelNot specifiedElevation of PrivilegeHIGH (CVSS v3 score: 7.8)View or DownloadUNDERCODE2024-11-19
Secure Kernel Mode Elevation of PrivilegeMedium (CVSS v3 score: 6.7)View or DownloadUNDERCODE2024-11-19
Microsoft PC Manager(not specified in available information)Elevation of PrivilegeHigh (CVSS 3.1: 7.8)View or DownloadUNDERCODE2024-11-19
Windows Telephony Service(Not specified)Remote Code Execution (RCE)High (CVSS 3.x Base Score: 8.8)View or DownloadUNDERCODE2024-11-19
Microsoft Hyper-V(not specified in available information)Denial of Service (DoS)Medium (CVSS 3.1 base score: 6.5)View or DownloadUNDERCODE2024-11-19
Moodle< 4.1.14, >= 4.2.0, < 4.2.11, >= 4.3.0, < 4.3.8, >= 4.4.0, < 4.4.4IDOR (Insecure Direct Object Reference)ModerateView or DownloadUNDERCODE2024-11-19
Moodle< 4.1.14, >= 4.2.0, < 4.2.11, >= 4.3.0, < 4.3.8, >= 4.4.0, < 4.4.4IDOR (Insecure Direct Object Reference)ModerateView or DownloadUNDERCODE2024-11-19
Moodle< 4.1.14, >= 4.2.0, < 4.2.11, >= 4.3.0, < 4.3.8, >= 4.4.0, < 4.4.4IDOR (Insecure Direct Object Reference)ModerateView or DownloadUNDERCODE2024-11-19
Moodle< 4.1.14, >= 4.2.0, < 4.2.11, >= 4.3.0, < 4.3.8, >= 4.4.0, < 4.4.4IDOR (Insecure Direct Object Reference)ModerateView or DownloadUNDERCODE2024-11-19
Moodle< 4.1.14, >= 4.2.0, < 4.2.11, >= 4.3.0, < 4.3.8, >= 4.4.0, < 4.4.4IDOR (Insecure Direct Object Reference)ModerateView or DownloadUNDERCODE2024-11-19
Moodle< 4.1.14, >= 4.2.0, < 4.2.11, >= 4.3.0, < 4.3.8, >= 4.4.0, < 4.4.4IDOR (Insecure Direct Object Reference)ModerateView or DownloadUNDERCODE2024-11-19
Moodle< 4.1.14, >= 4.2.0, < 4.2.11, >= 4.3.0, < 4.3.8, >= 4.4.0, < 4.4.4IDOR (Insecure Direct Object Reference)ModerateView or DownloadUNDERCODE2024-11-19
Moodle< 4.1.14, >= 4.2.0, < 4.2.11, >= 4.3.0, < 4.3.8, >= 4.4.0, < 4.4.4IDOR (Insecure Direct Object Reference)ModerateView or DownloadUNDERCODE2024-11-19
Moodle< 4.1.14, >= 4.2.0, < 4.2.11, >= 4.3.0, < 4.3.8, >= 4.4.0, < 4.4.4IDOR (Insecure Direct Object Reference)ModerateView or DownloadUNDERCODE2024-11-19
Moodle< 4.1.14, >= 4.2.0, < 4.2.11, >= 4.3.0, < 4.3.8, >= 4.4.0, < 4.4.4IDOR (Insecure Direct Object Reference)ModerateView or DownloadUNDERCODE2024-11-19
Apple Products (tvOS, visionOS, Safari, watchOS, iOS, iPadOS, macOS)Not applicable (fixed in specific versions)URL protocol handling issue allowing potential web content restriction bypassMedium (CVSS v2: 5.5, CVSS v3 details not provided)View or DownloadUNDERCODE2024-11-19
Hugging Face TransformersAffected versionsRemote Code ExecutionCritical (CVSS 8.8)View or DownloadUNDERCODE2024-11-19
AndroidNot specifiedOut-of-bounds write in PMRWritePMPageList function (pmr.c)High (Local Privilege Escalation)View or DownloadUNDERCODE2024-11-19
Gogs<= 0.12.7Remote Command ExecutionMediumView or DownloadUNDERCODE2024-11-19
usememos/memos0.9.1 (Vulnerable)Stored XSSCriticalView or DownloadUNDERCODE2024-11-19
Wallabag2.5.2CSRFNot specified in the provided informationView or DownloadUNDERCODE2024-11-19
<br>1.0<br>Test<br>Low<br>https://dailycve.com/test/UNDERCODE2023-01-01

🦑 WANT MORE ?

Loading…
Scroll to Top