Vulnerability Database & Alerts

Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
PlatformAffected Version(s)Vulnerability SeverityFull Post ReporterDate
IBM i Netserver7.2, 7.3, 7.4, 7.5, 7.6Authentication BypasscriticalView or DownloadUNDERCODE2025-07-03
IBM i7.2-7.5Privilege escalationcriticalView or DownloadUNDERCODE2025-06-24
LibreOffice24.8 - 24.8.5, 25.2 - 25.2.1Signature spoofingcriticalView or DownloadUNDERCODE2025-07-03
IBM i7.2-7.6Privilege EscalationcriticalView or DownloadUNDERCODE2025-07-03
IBM i7.3, 7.4, 7.5Host Header InjectioncriticalView or DownloadUNDERCODE2025-07-03
Microsoft Partner CenterPre-July 2025Privilege EscalationcriticalView or DownloadUNDERCODE2025-07-03
eKuiper<1.6.1Path TraversalcriticalView or DownloadUNDERCODE2023-03-15
Windows KernelWindows 10/11, Server 2019/2022Null Pointer DereferencecriticalView or DownloadUNDERCODE2025-07-03
Windows RDSWindows Server 2019/2022Memory Lock BypasscriticalView or DownloadUNDERCODE2025-03-11
Microsoft DataversePre-9.2.2307.1Deserialization RCEcriticalView or DownloadUNDERCODE2025-07-03
Below Service< v0.9.0Privilege EscalationcriticalView or DownloadUNDERCODE2025-07-03
Samsung rLottie0.2Buffer OverreadmediumView or DownloadUNDERCODE2025-06-29
HashiCorp Vagrant≤ 2.4.6Guest-to-host code injectionmoderateView or DownloadUNDERCODE2025-07-02
Microsoft DataverseUnpatched releases (pre-July 2025)Privilege EscalationcriticalView or DownloadUNDERCODE2025-07-03
Ethereum<0.18.0Malleability bypassmoderateView or DownloadUNDERCODE2025-07-03
Visual Studio CodePre-1.90.0Privilege EscalationcriticalView or DownloadUNDERCODE2025-07-03
Microweber CMS< 1.2.11Local File InclusionmoderateView or DownloadUNDERCODE2025-07-03
Azure PlaywrightPre-2.8.1Privilege EscalationcriticalView or DownloadUNDERCODE2025-07-03
Google Chrome<138.0.7204.96Type ConfusionhighView or DownloadUNDERCODE2025-06-30
WindowsexFAT driverHeap overflowcriticalView or DownloadUNDERCODE2025-07-03
n8n<1.99.0DoScriticalView or DownloadUNDERCODE2024-03-15
Microsoft Office Access2016, 2019, 365Use-After-Free RCEcriticalView or DownloadUNDERCODE2025-07-03
eKuiper1.14.1, 1.14.3Path Traversal → RCEcriticalView or DownloadUNDERCODE2024-03-15
WindowsMicrosoft Streaming ServiceHeap-based buffer overflowcriticalView or DownloadUNDERCODE2025-07-03
Windows10, 11Privilege EscalationcriticalView or DownloadUNDERCODE2025-07-03
Windows10/11, Server 2016+Security BypasscriticalView or DownloadUNDERCODE2025-07-03
Windows10/11, Server 2019/2022Privilege EscalationcriticalView or DownloadUNDERCODE2025-07-03
Windows10/11, Server 2022Privilege EscalationcriticalView or DownloadUNDERCODE2025-07-03
Windows Telephony ServiceWindows 10/11, Server 2019/2022Heap buffer overflowcriticalView or DownloadUNDERCODE2025-07-03
Windows HelloWindows 10/11 (pre-2025 patches)Authentication BypasscriticalView or DownloadUNDERCODE2025-07-03
Windows Remote Desktop ServicesPre-July 2025 patchesMemory corruption (RCE)criticalView or DownloadUNDERCODE2025-07-03
Windows File ExplorerWindows 10/11, Server 2019/2022Spoofing via SMBcriticalView or DownloadUNDERCODE2025-07-03
Windows BitLockerUp to 10.0.22000Pre-boot auth bypasscriticalView or DownloadUNDERCODE2025-07-03
Wow-Company Modal Window≤ 6.1.4CSRFmediumView or DownloadUNDERCODE2025-07-02
Audiobookshelf2.17.0-2.19.0Auth BypasscriticalView or DownloadUNDERCODE2025-02-12
XunRuiCMS≤ 4.6.4Deserialization RCEcriticalView or DownloadUNDERCODE2025-07-02
Veeam BackupMicrosoft AzureSSRFcriticalView or DownloadUNDERCODE2025-07-02
Arm GPU Kernel Driversr53p0 to r53pXUse-After-FreecriticalView or DownloadUNDERCODE2025-06-02
Arm GPU Driversr18p0–r54p0Memory buffer overflowcriticalView or DownloadUNDERCODE2025-07-02
Linux Kernel5.14-6.3Use-After-FreecriticalView or DownloadUNDERCODE2023-05-18
PHP8.1.-8.4. (pre-patch)HTTP Redirect TruncationmediumView or DownloadUNDERCODE2025-07-02
MultiVendorX4.2.22 and priorSensitive Data ExposurecriticalView or DownloadUNDERCODE2025-07-02
g5theme Essential Real Estate≤ 5.2.1PHP LFI/RFIcriticalView or DownloadUNDERCODE2025-07-02
PHP8.1.0-8.4.4Header Parsing FlawmediumView or DownloadUNDERCODE2025-07-03
PHP8.1.0-8.1.31, 8.2.0-8.2.27, 8.3.0-8.3.18, 8.4.0-8.4.4Header InjectionmediumView or DownloadUNDERCODE2025-07-02
WordPress (Elementor)≤ 3.6.1Stored XSScriticalView or DownloadUNDERCODE2025-06-06
WordPress≤5.3.58CSRFmediumView or DownloadUNDERCODE2025-06-06
HPE StoreOnceNot specifiedAuthentication BypasscriticalView or DownloadUNDERCODE2025-07-01
HPE StoreOnceVulnerable versions prior to patchCommand Injection (RCE)criticalView or DownloadUNDERCODE2025-07-02
HPE StoreOnceVulnerable versions prior to patchDirectory TraversalcriticalView or DownloadUNDERCODE2025-06-02
ARTEC EMA Mailv6.92Stored XSSmediumView or DownloadUNDERCODE2025-07-02
Linksys RE Series1.0.013.001 - 1.2.07.001OS Command InjectioncriticalView or DownloadUNDERCODE2025-07-01
ShopXO6.5.0Unrestricted File UploadcriticalView or DownloadUNDERCODE2025-07-01
OpenEMR<7.0.3.4Logging bypassmediumView or DownloadUNDERCODE2025-07-02
OpenEMR< 7.0.3.4Stored XSScriticalView or DownloadUNDERCODE2025-05-23
G-Net Dashcam BB GONXAll vulnerable versionsDomain hijackingcriticalView or DownloadUNDERCODE2025-07-02
G-Net DashcamBB GONXUnauthorized video accesscriticalView or DownloadUNDERCODE2025-07-02
vLLM<0.8.0RCEcriticalView or DownloadUNDERCODE2025-03-19
vLLM0.8.0-0.8.xInput ValidationcriticalView or DownloadUNDERCODE2025-05-30
PublicCMS4.0.202406Arbitrary File UploadcriticalView or DownloadUNDERCODE2025-07-01
G-Net Dashcam BB GONXAll < v4.7.2Unauthenticated API accesscriticalView or DownloadUNDERCODE2025-07-01
REDAXO CMS< 5.18.3Arbitrary File UploadcriticalView or DownloadUNDERCODE2025-07-01
G-Net Dashcam BB GONXAll firmwareDefault credentialscriticalView or DownloadUNDERCODE2025-07-02
REDAXO CMS5.0.0 - 5.18.2Reflected XSSmediumView or DownloadUNDERCODE2025-07-01
G-Net DashcamBB GONXAuth BypasscriticalView or DownloadUNDERCODE2025-07-01
Akka<2.10.6Insecure DeserializationmoderateView or DownloadUNDERCODE2025-07-02
Apache Seata2.0.0-2.2.xRCE via deserializationcriticalView or DownloadUNDERCODE2025-07-02
Electron30.0.0-alpha.1 - 30.0.4, 31.0.0-alpha.1 - 31.0.0-beta.1ASAR Integrity BypasscriticalView or DownloadUNDERCODE2025-07-02
Filebrowser2.32.0Command InjectionmediumView or DownloadUNDERCODE2025-06-26
Orkes Conductor< 3.21.13OS Command InjectioncriticalView or DownloadUNDERCODE2025-07-02
BabylonPre-v1.2.0Chain halthighView or DownloadUNDERCODE2025-07-02
File Browser2.32.0Insecure direct downloadcriticalView or DownloadUNDERCODE2025-06-29
Filebrowser2.32.0Scope BypasscriticalView or DownloadUNDERCODE2025-06-25
Electron<28.3.2, 29.x<29.3.3, 30.x<30.0.3Heap Buffer OverflowcriticalView or DownloadUNDERCODE2025-07-02
Mattermost9.11.0-10.8.0Incorrect AuthorizationmoderateView or DownloadUNDERCODE2025-07-02
Pillow (Python Imaging Library)11.2.0+Heap Buffer OverflowcriticalView or DownloadUNDERCODE2024-03-15
@modelcontextprotocol/server-filesystem<= 0.6.2, >= 2025.1.14 < 2025.7.1Path bypasshighView or DownloadUNDERCODE2025-07-02
Filebrowser2.32.0JWT URL leakcriticalView or DownloadUNDERCODE2025-06-26
Janssen & Gluu Flex<1.8.0 / <5.8.0Information DisclosurecriticalView or DownloadUNDERCODE2025-07-02
tiny-secp256k1<2.xKey extractioncriticalView or DownloadUNDERCODE2021-01-19
Node.js/npmtiny-secp256k1 (<2.0)Buffer spoofingcriticalView or DownloadUNDERCODE2023-05-15
ModelContextProtocol/Server-Filesystem<= 0.6.2, >= 2025.1.14 < 2025.7.1Path validation bypasshighView or DownloadUNDERCODE2025-07-02
Graylog<6.2.0Privilege EscalationcriticalView or DownloadUNDERCODE2025-07-02
File Browser2.32.0Weak authcriticalView or DownloadUNDERCODE2025-06-26
SQLiteRace ConditioncriticalView or DownloadUNDERCODE2023-06-15
Infinispan CLI<= 16.0.0.Dev01Information DisclosuremoderateView or DownloadUNDERCODE2025-06-27
Ruby WEBrick<1.8.0HTTP SmugglingmoderateView or DownloadUNDERCODE2025-06-26
Vault Community1.14.8-1.19.9DoSlowView or DownloadUNDERCODE2025-06-27
Apache Airflow<6.4.0SQL InjectioncriticalView or DownloadUNDERCODE2025-06-27
MobSF<affected_versions>SSRF via redirectshighView or DownloadUNDERCODE2025-06-27
TabberNeue3.0.0-3.1.0Stored XSShighView or DownloadUNDERCODE2025-06-27
RaspAP raspap-webgui3.3.1Directory TraversalhighView or DownloadUNDERCODE2025-06-27
OpenBao/HashiCorp VaultLatest (pre-patch)Information disclosuremediumView or DownloadUNDERCODE2025-06-27
Llama Factory<=0.9.3Remote Code ExecutioncriticalView or DownloadUNDERCODE2025-06-27
Java< 2.15.0Stack overflowmediumView or DownloadUNDERCODE2025-06-27
File Browser2.32.0Command InjectioncriticalView or DownloadUNDERCODE2025-03-26
File Browser2.32.0Stored XSScriticalView or DownloadUNDERCODE2025-06-26
OpenBao/HashiCorp Vault< v2.2.2Unauthenticated rekey cancellationmediumView or DownloadUNDERCODE2025-06-26
OpenBao / HashiCorp Vault< 2.3.0 / ≤ 1.19.5Information DisclosuremediumView or DownloadUNDERCODE2025-06-26
Incusv6.12, v6.13ACL BypasscriticalView or DownloadUNDERCODE2025-06-26
Incusv6.12-v6.13ACL BypasscriticalView or DownloadUNDERCODE2025-06-26
Octo-STS< v0.5.3SSRF via OIDC tokenscriticalView or DownloadUNDERCODE2025-06-26
Gogs0.14.0+devStored XSScriticalView or DownloadUNDERCODE2024-05-23
Podman<5.5.2TLS bypasscriticalView or DownloadUNDERCODE2025-06-25
Solidity<2.1.1, <2.2.0Validation bypassmediumView or DownloadUNDERCODE2025-06-25
School Fees Payment System1.0Stored XSSmediumView or DownloadUNDERCODE2025-06-25
JetBrains TeamCity< 2025.03.3DOM-based XSScriticalView or DownloadUNDERCODE2025-06-25
Simple Pizza Ordering System1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-06-25
Anchor CMS0.12.7Stored XSSmediumView or DownloadUNDERCODE2025-06-25
Simple Pizza Ordering1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-06-25
JetBrains TeamCity< 2025.03.3Reflected XSSmediumView or DownloadUNDERCODE2025-06-25
JetBrains TeamCity< 2025.03.3Information DisclosuremediumView or DownloadUNDERCODE2025-06-25
TOTOLINK A3002R1.1.1-B20200824OS Command InjectioncriticalView or DownloadUNDERCODE2025-06-25
TOTOLINK A3002R1.1.1-B20200824.0128Stack overflowcriticalView or DownloadUNDERCODE2025-06-25
WinRARPre-7.0Directory Traversal → RCEcriticalView or DownloadUNDERCODE2025-06-25
Agri-Trading System1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-06-25
SourceCodester1.0XSSmediumView or DownloadUNDERCODE2025-06-25
Macro-video V380E6_C11020302UART code executioncriticalView or DownloadUNDERCODE2025-06-25
Android2.1.44, 2.1.64Information DisclosurecriticalView or DownloadUNDERCODE2025-06-25
Macro-video V380E6_C11020302Arbitrary code executioncriticalView or DownloadUNDERCODE2025-06-25
Linksys RE Series1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001OS Command InjectioncriticalView or DownloadUNDERCODE2025-06-25
Linksys RE Series1.0.013.001-1.2.07.001OS Command InjectioncriticalView or DownloadUNDERCODE2025-06-25
Paragon Software15 - 17.9.1Kernel Memory WritecriticalView or DownloadUNDERCODE2025-03-27
Apache Solr≤ 9.7ConfigSet hijackingcriticalView or DownloadUNDERCODE2025-06-25
AstrBot3.4.4 - 3.5.12Path TraversalcriticalView or DownloadUNDERCODE2025-06-25
Paragon Software15-17.39Kernel access flawcriticalView or DownloadUNDERCODE2025-03-03
vBulletin5.0.0–6.0.3API BypasscriticalView or DownloadUNDERCODE2025-06-25
Paragon Software15 - 17.9.1Null DereferencecriticalView or DownloadUNDERCODE2025-03-03
Paragon Software15 - 17.9.1Kernel Memory MappingcriticalView or DownloadUNDERCODE2025-03-27
Froxlor< 2.2.6HTML InjectionmediumView or DownloadUNDERCODE2025-06-25
Transsnet StoreMITM Code InjectioncriticalView or DownloadUNDERCODE2025-06-25
Samsung ExynosMultipleHeap OOB WritecriticalView or DownloadUNDERCODE2025-06-25
Telerik UI for AJAX2011.2.712 - 2025.1.218Unsafe ReflectioncriticalView or DownloadUNDERCODE2025-06-25
Drupal<1.3.0CSRF bypassmediumView or DownloadUNDERCODE2025-06-25
Devolutions Server2025.1.3.0-2025.1.7.0Privilege EscalationcriticalView or DownloadUNDERCODE2025-06-25
vBulletin5.6.4 - 5.7.2RCEcriticalView or DownloadUNDERCODE2025-06-25
TYPO3≤13.0.0Stored XSSmediumView or DownloadUNDERCODE2025-06-25
Free5GC4.0.0Buffer OverflowcriticalView or DownloadUNDERCODE2025-06-25
Samsung ExynosMultipleOOB WritecriticalView or DownloadUNDERCODE2025-05-19
Drupal Piwik PRO<1.3.2XSSmediumView or DownloadUNDERCODE2025-06-25
Apache Tomcat9.0.0.M1-9.0.104Constraint bypasscriticalView or DownloadUNDERCODE2025-06-25
Drupal<3.1.11, <4.0.2Resource exhaustioncriticalView or DownloadUNDERCODE2025-06-25
Allure 2xunit-xml-pluginXXEcriticalView or DownloadUNDERCODE2025-06-25
PHPGurukul Pre-School Enrollment1.0Directory TraversalcriticalView or DownloadUNDERCODE2025-06-25
PHPGurukul Enrollment1.0Directory TraversalcriticalView or DownloadUNDERCODE2025-06-25
Campcodes Teacher Management1.0SQL Injectioncriticalh2stylecolorblueView or DownloadUNDERCODE2025-06-21
Apache Tomcat9.0.0.M1-9.0.105Resource exhaustioncriticalView or DownloadUNDERCODE2025-06-16
WordPress Plugin≤ 2.3.1LFI → RCEcriticalView or DownloadUNDERCODE2025-06-24
Restaurant Order System1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-06-24
Campcodes HMS1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-06-24
Campcodes OHMS1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-06-21
Campcodes Online Hospital1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-06-24
Node.js<18.16.1, <20.3.1HTTP Request SmugglingcriticalView or DownloadUNDERCODE2023-06-22
Netwrix Directory Manager<=11.0.0.0, 11.1.25134.03Auth BypasscriticalView or DownloadUNDERCODE2025-06-24
PHPGurukul Art Gallery1.1SQL InjectioncriticalView or DownloadUNDERCODE2025-06-24
Dell ThinOS2502 and priorCleartext StoragehighView or DownloadUNDERCODE2025-06-24
vLLM0.7.0-0.9.0Hash collisionmediumView or DownloadUNDERCODE2025-06-24
Node.js<16.4.1, <14.17.2, <12.22.2Prototype PollutionhighView or DownloadUNDERCODE2021-06-15
Fastify5.0.0-5.3.0, 4.9.0Validation BypassmediumView or DownloadUNDERCODE2025-04-18
vLLM0.8.0 - 0.9.0DoScriticalView or DownloadUNDERCODE2025-06-24
FlowiseAI Flowisev2.2.6Arbitrary File UploadcriticalView or DownloadUNDERCODE2025-06-23
Jenkins≤ 2.499 / LTS ≤ 2.492.1Sensitive Data ExposurecriticalView or DownloadUNDERCODE2025-06-23
Jenkins≤ 2.499 / ≤ 2.492.1 (LTS)Sensitive Data ExposurecriticalView or DownloadUNDERCODE2025-06-23
Jenkins≤2.499 / ≤2.492.1 (LTS)CSRFlowView or DownloadUNDERCODE2025-06-23
Jenkins≤2.499, ≤2.492.1 (LTS)Open RedirectmediumView or DownloadUNDERCODE2025-06-23
Kubernetes1.32.0-1.32.5, 1.33.0-1.33.1Authorization bypasslowView or DownloadUNDERCODE2025-06-23
Node.js0.12-2.xPBKDF2 Uint8Array mishandlingcriticalView or DownloadUNDERCODE2017-09-26
pbkdf2-browserify< 3.1.2Predictable key outputcriticalView or DownloadUNDERCODE2023-10-11
MLFlow< 3.1.0SSRFmoderateView or DownloadUNDERCODE2025-06-23
ChangeDetection.io<0.50.4Stored XSShighView or DownloadUNDERCODE2025-06-21
spytrap-adb<0.3.5UI omissionlowView or DownloadUNDERCODE2025-06-23
letmein<= 10.2.0DoScriticalView or DownloadUNDERCODE2025-06-23
Zyxel AMG1302-T10B2.00(AAJC.16)C0Path TraversalcriticalView or DownloadUNDERCODE2025-06-23
SANCHAYA3.0.4Payment ManipulationcriticalView or DownloadUNDERCODE2025-06-23
Tianti CMS2.3Stored XSScriticalView or DownloadUNDERCODE2025-06-23
Adobe Commerce2.4.7-p4, earlierAccess BypasscriticalView or DownloadUNDERCODE2025-06-23
Crawl4AI<=0.4.247SSRFcriticalView or DownloadUNDERCODE2025-06-23
Archer Platform6 - 6.14.00202.10024Immutable field manipulationcriticalView or DownloadUNDERCODE2025-06-23
TOTOLINK A702R4.0.0-B20230721.1521Buffer OverflowcriticalView or DownloadUNDERCODE2025-06-23
VisiCut2.1Insecure DeserializationcriticalView or DownloadUNDERCODE2025-06-23
UnifiedTransform2.0Stored XSSmediumView or DownloadUNDERCODE2025-06-23
DaiCuo1.3.13Stored XSSmediumView or DownloadUNDERCODE2025-06-23
UnifiedTransform2.0Privilege EscalationcriticalView or DownloadUNDERCODE2025-06-23
TOTOLINK EX1200T4.1.2cu.5232_B20210713Buffer OverflowcriticalView or DownloadUNDERCODE2025-06-23
TOTOLINK X151.0.0-B20230714.1105Buffer OverflowcriticalView or DownloadUNDERCODE2025-06-23
Apache OFBiz18.12.17-18.12.18SSTIcriticalView or DownloadUNDERCODE2025-06-23
Apache Camel3.10.0-3.22.3, 4.8.0-4.8.4, 4.10.0-4.10.1Header InjectioncriticalView or DownloadUNDERCODE2025-03-09
TOTOLINK A3002R4.0.0-B20230531.1404Buffer OverflowcriticalView or DownloadUNDERCODE2025-06-23
vvveb CMS1.0.6RCEcriticalView or DownloadUNDERCODE2025-06-23
TOTOLINK A3002RU3.0.0-B20230809.1615Buffer OverflowcriticalView or DownloadUNDERCODE2025-06-23
Artifex Ghostscript< 10.05.0UTF-8 mishandlingcriticalView or DownloadUNDERCODE2025-06-23
GeSHi≤1.0.9.1Stored XSSmediumView or DownloadUNDERCODE2025-03-09
Vert.x4.5.12Context data leakcriticalView or DownloadUNDERCODE2025-06-23
PyTorch2.6.0+cu124Improper InitializationproblematicView or DownloadUNDERCODE2025-06-23
Rollback Rx Professional12.8.0.0Null Pointer DereferencemediumView or DownloadUNDERCODE2025-06-23
PyTorch2.6.0+cu124Memory corruptioncriticalView or DownloadUNDERCODE2025-06-23
Oracle Database Server19.3-23.6Java VM flawmediumView or DownloadUNDERCODE2025-06-23
MySQL Server8.4.0, 9.0.0DDL DoSmediumView or DownloadUNDERCODE2025-06-23
Oracle Hyperion11.2.19.0.000Access Control BypassmediumView or DownloadUNDERCODE2025-06-23
Rebuild CMSv3.9.0 - v3.9.3SQL InjectioncriticalView or DownloadUNDERCODE2025-06-23
Oracle Java SE21.0.6, 24Compiler flawmediumView or DownloadUNDERCODE2025-06-23
Oracle JD Edwards<9.2.9.2Access Control BypasscriticalView or DownloadUNDERCODE2025-06-23
MySQL Server8.0.0-9.2.0UDF DoSmediumView or DownloadUNDERCODE2025-06-23
Oracle APEX23.2, 24.1CSRFmediumView or DownloadUNDERCODE2025-06-23
TCPWave DDI11.34P1C2RCE via File UploadcriticalView or DownloadUNDERCODE2025-06-23
Oracle Hyperion11.2.19.0.000Privilege EscalationhighView or DownloadUNDERCODE2025-06-23
MySQL Enterprise≤8.0.40, ≤8.4.3, ≤9.1.0Firewall DoSmediumView or DownloadUNDERCODE2025-06-23
Codemers KLIMS1.6.DEVPrivilege EscalationcriticalView or DownloadUNDERCODE2025-06-23
Oracle WebLogic12.2.1.4.0, 14.1.1.0.0RCEcriticalView or DownloadUNDERCODE2025-06-23
Oracle Financial Services8.0.8.1, 8.1.2.7, 8.1.2.8CSRFmediumView or DownloadUNDERCODE2025-06-23
Oracle E-Business Suite12.2.3-12.2.10Region MappingmediumView or DownloadUNDERCODE2025-06-23
Oracle E-Business Suite12.2.3-12.2.13Broken Access Controlhighcvss81View or DownloadUNDERCODE2025-06-23
Oracle VM VirtualBox<7.0.24, <7.1.6Privilege EscalationmediumView or DownloadUNDERCODE2025-06-23
Oracle WebLogic14.1.1.0.0HTTP/2 DoShighView or DownloadUNDERCODE2025-06-23
Oracle Hospitality OPERA 55.6.19.20, 5.6.25.8, 5.6.26.6, 5.6.27.1RCE/DoScriticalView or DownloadUNDERCODE2025-06-23
Oracle E-Business Suite12.2.5-12.2.13Unauthorized Data AccesscriticalView or DownloadUNDERCODE2025-06-23
LinuxMultipleUnauthorized write accessmediumView or DownloadUNDERCODE2025-06-23
WordPress0.0.1LFIcriticalView or DownloadUNDERCODE2025-06-23
Netgear EX61201.0.0.68Buffer OverflowcriticalView or DownloadUNDERCODE2025-06-23
Cisco IOS XEWireless LAN ControllersArbitrary file uploadcriticalView or DownloadUNDERCODE2025-06-23
Meteor≤ 3.2.1ReDoSmediumView or DownloadUNDERCODE2025-06-23
Go middleware<1.2.0CSRF bypassmediumView or DownloadUNDERCODE2025-06-23
Open5GS≤ 2.7.2AMF DoSmediumView or DownloadUNDERCODE2025-06-23
Netgear WG302v2≤ 5.2.9Command InjectioncriticalView or DownloadUNDERCODE2025-06-23
DCMTK3.6.9Memory corruptioncriticalView or DownloadUNDERCODE2025-06-23
Microsoft SharePointUnspecified (pre-patch)Privilege EscalationcriticalView or DownloadUNDERCODE2025-06-23
Absolute Secure Access Server9.0 - 13.54Memory corruptioncriticalView or DownloadUNDERCODE2025-06-23
TP-LINK IPC1.0.9Buffer OverflowcriticalView or DownloadUNDERCODE2025-06-23
Vigybagv1.0 and priorStored XSSmediumView or DownloadUNDERCODE2025-06-23
Solon3.1.2Directory Traversal → XSScriticalView or DownloadUNDERCODE2025-06-23
Yi IOT XY-38206.0.24.10Remote Command ExecutioncriticalView or DownloadUNDERCODE2025-06-23
Yi IOT XY-3820v6.0.24.10Directory Traversal → RCEcriticalView or DownloadUNDERCODE2025-06-23
React-Native0.7.11Info DisclosurecriticalView or DownloadUNDERCODE2025-06-23
Windows MediaWindows 10/11, Server 2019/2022Stack overflowcriticalView or DownloadUNDERCODE2025-06-23
OpenC3 COSMOSv6.0.0RCE via file uploadcriticalView or DownloadUNDERCODE2025-06-23
Wix-Incubator Jam<= e87a6fd85cf8SSTImediumView or DownloadUNDERCODE2025-06-23
HPE Performance Cluster ManagerPrior to 3.2.1Authentication BypasscriticalView or DownloadUNDERCODE2025-06-23
mojoPortal<=2.9.0.1Directory TraversalcriticalView or DownloadUNDERCODE2025-06-23
Apple OS ecosystemiOS/iPadOS/macOS (see )Logic flawcriticalView or DownloadUNDERCODE2025-06-16
RISC0-ZKVM2.0.0–2.0.2Circuit Constraint BypasscriticalView or DownloadUNDERCODE2025-06-20
Mattermost10.5.5, 9.11.15, 10.8.0, 10.7.2, 10.6.5Improper Access ControlmoderateView or DownloadUNDERCODE2025-06-20
rfc3161-client≤1.0.2Signature bypasscriticalView or DownloadUNDERCODE2025-06-20
Mattermost10.5.0-10.5.5, 9.11.0-9.11.15, 10.8.0, 10.7.0-10.7.2, 10.6.0-10.6.5Authorization BypassmoderateView or DownloadUNDERCODE2025-06-20
Pingora-proxy<0.1.0Request SmugglingcriticalView or DownloadUNDERCODE2023-10-09
goTenna v1App 5.5.3, Firmware 0.25.5Message InjectioncriticalView or DownloadUNDERCODE2025-06-20
goTenna Mesh5.5.3 (app), 1.1.12 (firmware)Hardcoded CredentialscriticalView or DownloadUNDERCODE2025-05-01
goTenna v15.5.3 (app), 0.25.5 (firmware)Frequency hopping bypasscriticalView or DownloadUNDERCODE2025-06-20
newbee-mall1.0Stored XSSmediumView or DownloadUNDERCODE2025-06-20
powsybl-core<6.7.2XXE & SSRFcriticalView or DownloadUNDERCODE2023-06-15
Velociraptor< 0.74.3Privilege EscalationmoderateView or DownloadUNDERCODE2025-06-20
Powsybl<6.7.2Deserialization flawcriticalView or DownloadUNDERCODE2024-03-15
Webkul QloApps1.6.1Stored XSSmediumView or DownloadUNDERCODE2025-06-20
DotVVM<4.2.10, <4.3.8, <5.0.0-preview03Path TraversalcriticalView or DownloadUNDERCODE2025-06-20
Oracle Communications7.4.0-7.5.0Unauthorized Data AccessmediumView or DownloadUNDERCODE2025-06-20
Oracle Communications7.4.0-7.5.0UI RedressingmediumView or DownloadUNDERCODE2025-06-20
goTenna v15.5.3 (app), 0.25.5 (firmware)Information DisclosurecriticalView or DownloadUNDERCODE2025-06-20
DNN.PLATFORM<10.0.1IP Filter BypasshighView or DownloadUNDERCODE2025-06-20
OSV-SCALIBR0.1.3-0.2.0Path TraversalmoderateView or DownloadUNDERCODE2025-06-20
goTenna v15.5.3 (app), 0.25.5 (firmware)Hardcoded tokencriticalView or DownloadUNDERCODE2025-06-20
Mattermost<=10.5.5, <=9.11.15Path TraversalcriticalView or DownloadUNDERCODE2025-06-20
IBM Security Guardium11.4, 12.1Privilege EscalationcriticalView or DownloadUNDERCODE2025-06-20
go-chiv5.2.1Host header injectionmediumView or DownloadUNDERCODE2023-05-15
goTenna v1App 5.5.3, Firmware 0.25.5Encryption malleabilitycriticalView or DownloadUNDERCODE2025-06-20
goTennav1 (app 5.5.3, firmware 0.25.5)Information DisclosurecriticalView or DownloadUNDERCODE2025-06-20
Oracle Communications7.4.0-7.5.0Improper Access ControlmediumView or DownloadUNDERCODE2025-06-20
Android<8.14.0Data exposurecriticalView or DownloadUNDERCODE2024-03-15
goTenna Mesh5.5.3 (app), 1.1.12 (firmware)Information DisclosuremediumView or DownloadUNDERCODE2025-06-20
CrafterCMS4.0.0-4.2.2Groovy Sandbox BypasshighView or DownloadUNDERCODE2025-06-20
DNN.PLATFORM<10.0.1Stored XSSmoderateView or DownloadUNDERCODE2025-06-20
PowSyBl<6.7.2ReDoSmediumView or DownloadUNDERCODE2025-06-20
DNN.PLATFORM<10.0.1Reflected XSSmoderateView or DownloadUNDERCODE2025-06-20
urllib3<2.0.0Improper Redirect HandlingcriticalView or DownloadUNDERCODE2023-10-11
urllib3 (Pyodide)<2.0.0Open RedirectmediumView or DownloadUNDERCODE2023-09-28
microlight.js0.0.7Null pointer dereferencehighView or DownloadUNDERCODE2025-06-17
JavaScript library0.0.7DoShighView or DownloadUNDERCODE2025-06-17
Python-a2a≤ 0.5.5Path TraversalmoderateView or DownloadUNDERCODE2025-06-17
Phoenix Framework<2.10.0Session fixationcriticalView or DownloadUNDERCODE2023-05-15
Adobe InDesignID20.2, ID19.5.3 (and earlier)Use After FreecriticalView or DownloadUNDERCODE2025-06-16
CodiMD≤ 2.2.0XSS bypasscriticalView or DownloadUNDERCODE2025-06-16
Adobe InDesignID20.2, ID19.5.3 (earlier)Heap OverflowcriticalView or DownloadUNDERCODE2025-06-10
Adobe InDesignID20.2, ID19.5.3Out-of-bounds WritecriticalView or DownloadUNDERCODE2025-06-10
Adobe InDesignID20.2, ID19.5.3Out-of-Bounds ReadmediumView or DownloadUNDERCODE2025-06-16
Adobe InDesignID20.2, ID19.5.3Use-After-FreecriticalView or DownloadUNDERCODE2025-06-16
Adobe InDesignID20.2, ID19.5.3 (earlier)Out-of-bounds writecriticalView or DownloadUNDERCODE2025-06-16
Adobe InDesignID20.2, ID19.5.3 (and earlier)Out-of-Bounds ReadmediumView or DownloadUNDERCODE2025-06-16
DBSyncer2.0.6Stored XSSmediumView or DownloadUNDERCODE2025-06-16
iTranswarpv2.19Authentication BypasscriticalView or DownloadUNDERCODE2025-06-16
Mezzanine CMS6.0.0Stored XSSmediumView or DownloadUNDERCODE2025-06-16
xmall1.1Auth BypasscriticalView or DownloadUNDERCODE2025-06-16
DBSyncer2.0.6Incorrect Access ControlcriticalView or DownloadUNDERCODE2025-06-16
GNU PSPP≤ 2.0.1Out-of-Bounds ReadmediumView or DownloadUNDERCODE2025-06-16
FlatPress1.3.1Stored XSSmediumView or DownloadUNDERCODE2025-06-16
FLIR AX8≤1.46.16XSSmediumView or DownloadUNDERCODE2025-06-16
phpList< 3.6.15XSSmediumView or DownloadUNDERCODE2025-06-16
phpList< 3.6.15Reflected XSSmediumView or DownloadUNDERCODE2025-06-17
Koillection1.6.10Stored XSSmediumView or DownloadUNDERCODE2025-06-16
kkFileView4.4.0Unrestricted UploadcriticalView or DownloadUNDERCODE2025-06-16
Emlog Pro2.5.7Arbitrary File UploadcriticalView or DownloadUNDERCODE2025-06-16
OpenNextJS/Cloudflare<1.3.0SSRFcriticalView or DownloadUNDERCODE2025-06-17
FLIR AX8≤1.46.16Command InjectioncriticalView or DownloadUNDERCODE2025-06-16
TOTOLINK A3002Rv4.0.0-B20230531.1404Buffer OverflowcriticalView or DownloadUNDERCODE2025-06-16
Juzaweb CMS≤ 3.4.2Improper Access ControlcriticalView or DownloadUNDERCODE2025-06-16
D-Link DIR-632FW103B08Stack overflowcriticalView or DownloadUNDERCODE2025-06-10
Apache Tomcat9.0.0-9.0.105DoS via multiparthighView or DownloadUNDERCODE2025-06-16
PHPGurukul VRMS1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-06-16
Tmall Demo≤ 20250505Unrestricted File UploadcriticalView or DownloadUNDERCODE2025-06-16
Firefox< 139.0.4Integer OverflowcriticalView or DownloadUNDERCODE2025-06-11
Liferay Portal7.0.0–7.4.3.4Path TraversalhighView or DownloadUNDERCODE2025-06-16
Teleport13.0.0 - 17.5.1Auth BypasscriticalView or DownloadUNDERCODE2025-06-16
Apache Tomcat9.0.0-105Constraint BypassmoderateView or DownloadUNDERCODE2025-06-16
TOTOLINK EX1200T≤ 4.1.2cu.5232_B20210713Buffer OverflowcriticalView or DownloadUNDERCODE2025-06-16
Drupal Commerce<1.0.3Incorrect AuthorizationmediumView or DownloadUNDERCODE2025-06-16
Joomla1.11.6 - 1.14.4Stored XSScriticalView or DownloadUNDERCODE2025-06-16
Liferay Portal< 38.0.0Session Parameter HandlinghighView or DownloadUNDERCODE2025-06-16
TOTOLINK EX1200T≤4.1.2cu.5232_B20210713Buffer OverflowcriticalView or DownloadUNDERCODE2025-06-09
Drupal Commerce Eurobank0.0.0 - 2.1.0Incorrect AuthorizationcriticalView or DownloadUNDERCODE2025-06-11
Liferay Portal7.4.0-7.4.3.97GraphQL DoShighView or DownloadUNDERCODE2025-06-16
Firefox< 139.0.4Memory corruptioncriticalView or DownloadUNDERCODE2025-06-16
Apache Commons<1.6.0, <2.0.0-M4DoS via headershighView or DownloadUNDERCODE2025-06-16
TOTOLINK EX1200T≤4.1.2cu.5232Buffer OverflowcriticalView or DownloadUNDERCODE2025-06-16
Adobe Experience Manager≤ 6.5.22DOM-based XSScriticalView or DownloadUNDERCODE2025-06-16
ManageEngine ADAudit Plus< 8511SQL InjectioncriticalView or DownloadUNDERCODE2025-06-16
AssamLook CMS1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-06-16
Ubuntuauthd (pre-619ce8e)Privilege EscalationcriticalView or DownloadUNDERCODE2025-06-16
School Fees Payment System1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-06-16
protobuf-python<4.25.8, 5.26.0rc1-5.29.5, 6.30.0rc1-6.31.1DoS via recursionhighView or DownloadUNDERCODE2025-06-16
ManageEngine ADAudit Plus≤ 8510SQL InjectioncriticalView or DownloadUNDERCODE2025-06-16
pycares<4.9.0Use-after-freecriticalView or DownloadUNDERCODE2023-08-10
TOTOLINK N600Rv4.3.0cu.7866_B2022506Buffer OverflowcriticalView or DownloadUNDERCODE2025-06-16
Adobe Experience Manager≤6.5.22Stored XSSmediumView or DownloadUNDERCODE2025-06-10
Tenda AC915.03.02.13CSRFmediumView or DownloadUNDERCODE2025-06-16
Weblate<5.122FA brute-forcemoderateView or DownloadUNDERCODE2025-06-16
Adobe Experience Manager≤6.5.22Stored XSScriticalView or DownloadUNDERCODE2025-06-16
Weblate<5.12IP exposurelowView or DownloadUNDERCODE2025-06-16
TOTOLINK T104.1.8cu.5207Buffer OverflowcriticalView or DownloadUNDERCODE2025-06-16
Ivanti EPMM≤ 12.5.0.0RCEcriticalView or DownloadUNDERCODE2025-05-13
Samsung MagicINFO 9 Server< 21.1052Path TraversalcriticalView or DownloadUNDERCODE2025-05-13
Node.js< 12.22.1, < 14.16.1, < 15.14.0Prototype PollutionhighView or DownloadUNDERCODE2021-03-30
Ivanti EPMM≤ 12.5.0.0Auth BypasscriticalView or DownloadUNDERCODE2025-05-13
OpenC3 COSMOS6.0.0Directory TraversalhighView or DownloadUNDERCODE2025-06-16
Laundry System1.0Missing AuthenticationcriticalView or DownloadUNDERCODE2025-06-09
Firefox for iOS< 139URL spoofingmediumView or DownloadUNDERCODE2025-06-13
Mozilla Thunderbird< 138.0Privilege EscalationcriticalView or DownloadUNDERCODE2025-04-29
osTicket<=1.17.5SQL InjectioncriticalView or DownloadUNDERCODE2025-06-13
Open5GS≤ 2.7.3Reachable assertionmediumView or DownloadUNDERCODE2025-06-03
phpwcms≤1.9.45/1.10.8Remote DeserializationcriticalView or DownloadUNDERCODE2025-06-03
Thunderbird<137.0.2, <128.9.2UI Misleading HovermediumView or DownloadUNDERCODE2025-04-15
Adobe Experience Manager6.5.22 and earlierStored XSScriticalView or DownloadUNDERCODE2025-06-10
Salt>= 3006.0rc1, < 3006.12 | >= 3007.0rc1, < 3007.4File overwrite via unvalidated inputmoderateView or DownloadUNDERCODE2025-06-14
SaltStack3006.0rc1-3006.11, 3007.0rc1-3007.3Path TraversalmoderateView or DownloadUNDERCODE2025-06-14
MCP Inspector< 0.14.1Auth Bypass → RCEcriticalView or DownloadUNDERCODE2025-06-13
SaltStack3006.0rc1-3006.12, 3007.0rc1-3007.4DoS via file readmoderateView or DownloadUNDERCODE2025-06-13
SaltStack3006.0rc1-3006.11Directory TraversalcriticalView or DownloadUNDERCODE2025-06-13
SaltStack>=3006.0rc1, <3006.12 | >=3007.0rc1, <3007.4Authentication BypassmoderateView or DownloadUNDERCODE2025-06-13
SaltStack>= 3007.0, < 3007.4Authorization bypasshighView or DownloadUNDERCODE2025-06-13
SaltStack3006.0rc1-3006.12, 3007.0rc1-3007.4Arbitrary event injectionhighView or DownloadUNDERCODE2025-06-13
GitHub<1.4.3Gadget Chain RCElowView or DownloadUNDERCODE2025-06-13
SaltStack>=3006.0rc1, <3006.12 | >=3007.0rc1, <3007.4Command InjectionmoderateView or DownloadUNDERCODE2025-06-13
SaltStack3006.0rc1-3006.11, 3007.0rc1-3007.3Directory TraversalmoderateView or DownloadUNDERCODE2025-06-13
XWiki7.2-milestone-2 to 16.4.6, 16.5.0-rc-1 to 16.10.2, 17.0.0-rc-1Remote Code ExecutioncriticalView or DownloadUNDERCODE2025-06-13
XWiki15.9-rc-1 to 16.10.1Stored XSSmoderateView or DownloadUNDERCODE2025-06-13
XWiki<15.10.16, 16.0.0-16.4.6, 16.5.0-16.10.1Code ExecutioncriticalView or DownloadUNDERCODE2025-06-13
XWiki10.9-16.4.6Information DisclosuremediumView or DownloadUNDERCODE2025-06-13
XWiki15.9-rc-1 - 16.4.6Incomplete macro rightscriticalView or DownloadUNDERCODE2025-06-13
XWiki11.10.11-12.0, 12.6.3-12.7, 12.8-rc-1-16.4.7, 16.5.0-rc-1-16.10.3, 17.0.0-rc-1RCE via macro defaultscriticalView or DownloadUNDERCODE2025-06-13
XWiki<15.10.16, 16.0.0-16.4.6, 16.5.0-16.10.1Missing security warningmoderateView or DownloadUNDERCODE2025-06-13
XWiki8.2 to 16.4.6Access Control BypasscriticalView or DownloadUNDERCODE2025-06-13
Ibexa DXP4.6.0-beta1 to 4.6.20Persistent XSScriticalView or DownloadUNDERCODE2025-06-13
Ibexa DXP4.6.0-alpha1 to 4.6.20Stored XSSmoderateView or DownloadUNDERCODE2025-06-13
Ibexa DXP4.6.0-beta1 to 4.6.20Stored XSSmoderateView or DownloadUNDERCODE2025-06-13
Ibexa eZ Platform5.3.0-beta1 to 5.3.4Stored XSSmoderateView or DownloadUNDERCODE2025-06-13
Znuny<7.1.4Improper Access ControlcriticalView or DownloadUNDERCODE2025-06-13
StarCitizenTools/Citizen-Skin>=2.31.0, <3.3.1Stored XSSmoderateView or DownloadUNDERCODE2025-06-13
GitHub2.13.0-3.3.0Stored XSSmoderateView or DownloadUNDERCODE2025-06-13
MediaWiki (Citizen Skin)>= 3.3.0, < 3.3.1Stored XSSmoderateView or DownloadUNDERCODE2025-06-13
EngineerCMS1.02-2.0.5SQL InjectioncriticalView or DownloadUNDERCODE2025-06-13
MediaWiki>=2.4.2, <3.3.1Stored XSSmoderateView or DownloadUNDERCODE2025-06-13
Adobe Experience Manager≤ 6.5.22Improper AuthorizationcriticalView or DownloadUNDERCODE2025-06-13
Wavlink WL-WN530H420220801Command InjectioncriticalView or DownloadUNDERCODE2025-06-13
FreeFloat FTP Server1.0Buffer OverflowcriticalView or DownloadUNDERCODE2025-06-12
vantage6<4.11.0Brute-force bypasscriticalView or DownloadUNDERCODE2025-06-12
Vantage6 Server<3.9.0Insecure JWT SecretcriticalView or DownloadUNDERCODE2025-06-12
Zorlan SkyCaiji2.9SSRFcriticalView or DownloadUNDERCODE2025-06-12
XWiki1.0 to 15.10.15, 16.0.0-rc-1 to 16.4.6, 16.5.0-rc-1 to 16.10.1SQL InjectioncriticalView or DownloadUNDERCODE2025-06-12
yshopmall<=1.9.0SQL InjectioncriticalView or DownloadUNDERCODE2025-06-12
Zorlan SkyCaiji2.9Unrestricted UploadcriticalView or DownloadUNDERCODE2025-06-12
Adobe Experience Manager≤ 6.5.22Reflected XSScriticalView or DownloadUNDERCODE2025-06-12
Adobe Experience Manager≤ 6.5.22Stored XSScriticalView or DownloadUNDERCODE2025-06-12
MRCMS3.1.2CSRFmediumView or DownloadUNDERCODE2025-06-12
FoxCMSv1.2.5SQL InjectioncriticalView or DownloadUNDERCODE2025-06-12
FoxCMS2.0.6Directory TraversalcriticalView or DownloadUNDERCODE2025-06-12
FoxCMS1.2.5Arbitrary File DeletioncriticalView or DownloadUNDERCODE2025-06-12
WordPress<1.10.0Path TraversalcriticalView or DownloadUNDERCODE2025-04-01
Znuny≤7.1.3Information DisclosurecriticalView or DownloadUNDERCODE2025-06-12
74CMS≤ 3.33.0Path TraversalmediumView or DownloadUNDERCODE2025-06-12
Znuny≤ 7.1.3Missing HttpOnlymediumView or DownloadUNDERCODE2025-06-12
Netgear DGND37001.1.00.15_1.00.15NAInformation DisclosuremediumView or DownloadUNDERCODE2025-06-12
Flatpress CMS< 1.4Stored XSSmediumView or DownloadUNDERCODE2025-06-12
Netgear DGND37001.1.00.15_1.00.15NAAuthentication BypasscriticalView or DownloadUNDERCODE2025-06-12
ChatGPTPre-2025-03-30SVG-based HTML InjectioncriticalView or DownloadUNDERCODE2025-06-12
Linuxv20-v24Symlink privilege escalationcriticalView or DownloadUNDERCODE2025-06-12
Daily College Class Work1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-06-12
Tiiwee X1 AlarmTWX1HAKV2Replay AttackcriticalView or DownloadUNDERCODE2025-06-12
WordPress<8.85Stored XSShighView or DownloadUNDERCODE2025-06-12
iop-apl-uw basestation3<= 3.0.4Insecure deserializationmediumView or DownloadUNDERCODE2025-06-12
Victure RX1800EN_V1.0.0_r12_110933Command InjectioncriticalView or DownloadUNDERCODE2025-06-12
RSI Queue Management3.0SQL InjectioncriticalView or DownloadUNDERCODE2025-06-12
Jira Core/Service Management9.12.0–10.5.0Privilege Escalationhighcvss72View or DownloadUNDERCODE2025-06-12
Linksys FGW3000<=1.0.17.000000Command InjectioncriticalView or DownloadUNDERCODE2025-06-12
EnGenius ENH500FW3.7.22Auth bypasscriticalView or DownloadUNDERCODE2025-06-12
Linksys FGW3000≤1.0.17.000000Command InjectioncriticalView or DownloadUNDERCODE2025-06-12
WordPress<12.4.0XSSmediumView or DownloadUNDERCODE2025-06-12
VMware Cloud Foundation4.5.x, 5.0.xMissing AuthorizationcriticalView or DownloadUNDERCODE2025-06-12
Netgear DGND37001.1.00.15_1.00.15NAInformation disclosuremediumView or DownloadUNDERCODE2025-06-12
Microsoft WindowsServer 2008-2012, Win10 1507WebDAV Path TraversalcriticalView or DownloadUNDERCODE2025-06-10
Jenkins≤ 374.v194b_d0c8c8Stored XSScriticalView or DownloadUNDERCODE2025-06-12
FluxBB1.5.11Stored XSSmediumView or DownloadUNDERCODE2025-06-12
Jenkins DingTalk Plugin≤ 2.7.3SSL/TLS bypasscriticalView or DownloadUNDERCODE2025-06-12
Jenkins≤ 96.vee8ed882ec4dToken ImpersonationcriticalView or DownloadUNDERCODE2025-06-12
Jenkins Plugin≤4.0.1-286.v9e25a_740b_a_48CSRF → RCEcriticalView or DownloadUNDERCODE2025-06-12
Jenkins≤4.0.1-286.v9e25a_740b_a_48Missing Auth CheckcriticalView or DownloadUNDERCODE2025-06-12
Jenkins≤1.0Auth BypasscriticalView or DownloadUNDERCODE2025-06-12
Lila (Lichess)Pre-ab0beafDOM-based XSScriticalView or DownloadUNDERCODE2025-06-12
LmxCMS1.41SQL InjectioncriticalView or DownloadUNDERCODE2025-06-12
WebERP4.15.2SQL InjectioncriticalView or DownloadUNDERCODE2025-06-12
Zimbra Collaboration Suite9.0 - 10.1CSRF in GraphQLcriticalView or DownloadUNDERCODE2025-06-11
Erlang/OTP<25.3.2.20, <26.2.5.11, <27.3.3Unauthenticated RCEcriticalView or DownloadUNDERCODE2025-06-09
Wazuh4.4.0 to 4.9.0RCE via deserializationcriticalView or DownloadUNDERCODE2025-06-11
Zimbra Collaboration9.0.0-10.1.3SSRFcriticalView or DownloadUNDERCODE2025-06-11
MediaWikiCitizen SkinXSScriticalView or DownloadUNDERCODE2025-06-11
Drupal Lightgallery< 1.6.0Stored XSSmoderateView or DownloadUNDERCODE2025-06-11
Drupal Commerce< 1.0.3Incorrect AuthorizationhighView or DownloadUNDERCODE2025-06-11
Drupal CMS<1.0.5Resource exhaustionhighView or DownloadUNDERCODE2025-06-11
Drupal< 2.0.0Missing AuthorizationmoderateView or DownloadUNDERCODE2025-06-11
Drupal Commerce< 2.1.1Authorization BypasshighView or DownloadUNDERCODE2025-06-11
Hashicorp Nomad<1.10.2, <1.9.10, <1.8.14ACL MisassignmenthighView or DownloadUNDERCODE2025-06-11
Linksys E56001.1.0.26Stored XSScriticalView or DownloadUNDERCODE2025-06-11
Mattermost10.5.4, 9.11.13Information DisclosurelowView or DownloadUNDERCODE2025-06-11
Mattermost10.7.0-10.7.1LDAP InjectionmoderateView or DownloadUNDERCODE2025-06-11
Firefox/Thunderbird<139.0 / <128.11Memory CorruptioncriticalView or DownloadUNDERCODE2025-06-11
.NET8.0.16, 9.0.5RCEcriticalView or DownloadUNDERCODE2025-06-11
Hurl<4.2.0XSScriticalView or DownloadUNDERCODE2025-06-11
CosmWasm (wasmd)0.60.0, 0.51.0-0.55.0Improper error handlinghighView or DownloadUNDERCODE2025-06-10
PostgreSQL JDBC42.7.4 - 42.7.6Auth bypasscriticalView or DownloadUNDERCODE2025-06-11
DedeCMS5.7.117Code InjectioncriticalView or DownloadUNDERCODE2025-06-10
Campcodes Teacher System1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-06-05
FreeFloat FTP1.0Buffer OverflowcriticalView or DownloadUNDERCODE2025-06-10
Vtiger CRM8.3.0Stored XSScriticalView or DownloadUNDERCODE2025-06-10
SourceCodester1.0Buffer OverflowcriticalView or DownloadUNDERCODE2025-06-10
Campcodes ORMS1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-06-10
OrangeHRM5.7Privilege EscalationcriticalView or DownloadUNDERCODE2025-06-10
Samsung Exynos980-2400Double FreecriticalView or DownloadUNDERCODE2025-06-10
Vtiger CRM8.3.0RCEcriticalView or DownloadUNDERCODE2025-06-10
Node.js≤1.1.11ReDoSlowView or DownloadUNDERCODE2025-06-10
Cloudflare CIRCL<1.6.1Low-order point injectioncriticalView or DownloadUNDERCODE2024-04-15
Apache Kafka<3.9.1/4.0.0LDAP Deserialization → RCEcriticalView or DownloadUNDERCODE2023-01-01
Apache Kafka<3.9.1, 4.0.0Arbitrary Read/SSRFcriticalView or DownloadUNDERCODE2024-03-15
Nautobot<1.6.32, <2.4.10Template InjectioncriticalView or DownloadUNDERCODE2024-06-11
GeoServer1.0.0-2.24.3, 2.25.0-2.25.1SSRFcriticalView or DownloadUNDERCODE2025-06-10
Erxes<1.6.1Auth BypasshighView or DownloadUNDERCODE2025-06-10
Erxes<1.6.2Path TraversalhighView or DownloadUNDERCODE2025-06-10
Nautobot<2.4.10, <1.6.32Unauthenticated file accesscriticalView or DownloadUNDERCODE2025-06-10
Apache Kafka<3.4.0RCE/DoShighView or DownloadUNDERCODE2025-06-10
Erxes<1.6.2Path TraversalmoderateView or DownloadUNDERCODE2025-06-10
Matrix-SDK-Crypto0.8.0 - 0.11.0Sender SpoofingmoderateView or DownloadUNDERCODE2025-06-10
GeoServer<= 2.25.0XXE via GeoToolscriticalView or DownloadUNDERCODE2025-06-11
OctoPrint≤1.11.1DoS LoopcriticalView or DownloadUNDERCODE2025-06-10
OctoPrint<= 1.11.1Arbitrary File ExfiltrationcriticalView or DownloadUNDERCODE2025-06-10
GeoNetwork<4.4.8, <4.2.13XXE in WFS APIhighView or DownloadUNDERCODE2025-06-10
GeoServer<= 2.23.xInfinite Loop DoScriticalView or DownloadUNDERCODE2024-06-11
GeoServer<=2.25.0Missing Auth BypassmoderateView or DownloadUNDERCODE2025-06-10
GeoWebCache<= 1.20.0Info DisclosuremediumView or DownloadUNDERCODE2024-06-10
GeoServer<2.25.0XXE/SSRFcriticalView or DownloadUNDERCODE2024-03-15
GeoServer<= 2.25.0SSRF via Coverage APImoderateView or DownloadUNDERCODE2025-06-10
GeoServer<2.24.4, <2.25.2Unauthenticated SSRFhighView or DownloadUNDERCODE2025-06-10
Vue.js CLI≤5.0.8ReDoSmoderateView or DownloadUNDERCODE2025-06-09
GeoTools<23.xXXEcriticalView or DownloadUNDERCODE2025-06-09
Taro (CSS-to-React-Native)<= 4.1.1ReDoSmoderateView or DownloadUNDERCODE2025-06-09
GitOS Command InjectioncriticalView or DownloadUNDERCODE2025-06-09
Pion Interceptorv0.1.36-v0.1.38RTP paniccriticalView or DownloadUNDERCODE2025-06-09
Python Requests< 2.32.4Credential leakmoderateView or DownloadUNDERCODE2025-06-09
HAX CMS<1.12.0Stored XSScriticalView or DownloadUNDERCODE2023-10-15
HAXCMS<vX.X.XLFIcriticalView or DownloadUNDERCODE2025-06-09
Kubernetes (Authorino)<= v0.10.0Resource exhaustion via AuthPolicymoderateView or DownloadUNDERCODE2025-06-09
Laravel Translation Manager< 0.6.8Stored XSSmoderateView or DownloadUNDERCODE2025-06-09
Listmonk<5.0.2Template InjectioncriticalView or DownloadUNDERCODE2024-06-09
Skyvern≤ 0.2.0Jinja runtime leakhighView or DownloadUNDERCODE2025-06-09
Apache InLong1.13.0 to 2.1.0Deserialization RCEmoderateView or DownloadUNDERCODE2025-06-09
Jenkins Gatling Plugin136.vb_9009b_3d33a_eStored XSShighView or DownloadUNDERCODE2025-06-09
Jackson-core<2.13.0Memory leakmediumView or DownloadUNDERCODE2021-09-30
GitHubRust user cratePrivilege escalationhighView or DownloadUNDERCODE2025-06-06
SpiceDB<1.44.2Permission bypasscriticalView or DownloadUNDERCODE2024-06-07
llama_indexv0.12.21SQL InjectioncriticalView or DownloadUNDERCODE2025-06-06
Django<5.2.2, <5.1.10, <4.2.22Log injectionmoderateView or DownloadUNDERCODE2025-06-05
Parav1.50.6Info LeakmediumView or DownloadUNDERCODE2025-06-06
Auth0 Symfony SDK5.0.0 BETA-0 to 5.0.0Insecure DeserializationcriticalView or DownloadUNDERCODE2025-06-06
Erupt1.12.19Unrestricted File UploadmoderateView or DownloadUNDERCODE2025-06-05
Apache HTTP Server2.4.49Path Traversal & RCEcriticalView or DownloadUNDERCODE2021-10-05
Yii 2 (PHP)<2.0.50Info Disclosuremediumh2stylecolorblueView or DownloadUNDERCODE2025-06-05
RTI Connext Professional6.0.0-7.5.0Buffer OverflowcriticalView or DownloadUNDERCODE2025-06-05
Linux KernelUp to 6.8.0NULL DereferencecriticalView or DownloadUNDERCODE2025-06-05
Linux KernelPre-patch (ab15f34d0dd772f6d11327e08a81d46dc9c36276)Use-After-FreemediumView or DownloadUNDERCODE2025-06-05
RTI Connext Professional7.4.0 - 7.5.0Heap OverflowcriticalView or DownloadUNDERCODE2025-06-05
RTI Connext Professional7.4.0-7.5.0, 7.0.0-7.3.0.7, 4.5-6.1.2.23Buffer OverflowcriticalView or DownloadUNDERCODE2025-06-05
Linux Kernel5.15 - 6.8Race ConditionmediumView or DownloadUNDERCODE2025-06-05
IBM CICS TX10.1, 11.1Arbitrary Code ExecutioncriticalView or DownloadUNDERCODE2025-06-05
Linux Kernel<6.8.3Buffer OverflowcriticalView or DownloadUNDERCODE2025-06-05
DataEase< 2.10.10JDBC InjectionmediumView or DownloadUNDERCODE2025-06-05
DataEase< 2.10.10SQLi BypasscriticalView or DownloadUNDERCODE2025-06-05
Google Chrome<137.0.7151.68Heap corruptionhighView or DownloadUNDERCODE2025-06-05
DataEase<2.10.10JWT ForgerycriticalView or DownloadUNDERCODE2025-06-05
Google Chrome<137.0.7151.68Use-After-FreemediumView or DownloadUNDERCODE2025-06-05
WordPress< 3.2.10Stored XSScriticalView or DownloadUNDERCODE2025-06-05
WordPress Plugin< 3.3.6Stored XSScriticalView or DownloadUNDERCODE2025-06-05
WordPress<8.8.2Stored XSShighView or DownloadUNDERCODE2025-06-05
osTicket<1.17.6, <1.18.2Broken Access ControlcriticalView or DownloadUNDERCODE2025-06-05
WordPress≤28.0.3Stored XSScriticalView or DownloadUNDERCODE2025-06-04
Ruby on Rails (Rack)<3.0.0, >2.2.0ReDoScriticalView or DownloadUNDERCODE2025-06-05
WordPress Plugin≤ 26.0.6Stored XSScriticalView or DownloadUNDERCODE2025-06-04
WordPress≤8.9.1Code ExecutioncriticalView or DownloadUNDERCODE2025-06-04
WordPress≤1.9Stored XSScriticalView or DownloadUNDERCODE2025-06-04
WordPress≤ 4.8.1.1Stored XSScriticalView or DownloadUNDERCODE2025-06-04
WordPress<= 4.0.26Arbitrary file readcriticalView or DownloadUNDERCODE2025-06-04
WordPress plugin≤ 5.3Reflected XSSmediumView or DownloadUNDERCODE2025-06-04
WordPress≤ 6.91Arbitrary File ReadcriticalView or DownloadUNDERCODE2025-06-04
WordPress≤ 4.2.19Unauthenticated data deletioncriticalView or DownloadUNDERCODE2025-06-04
WordPress≤8.9.1Stored XSScriticalView or DownloadUNDERCODE2025-06-04
kro (Kube Resource Orchestrator)0.1.0 to 0.2.0Confused DeputymoderateView or DownloadUNDERCODE2025-06-05
WordPress≤ 2.7.11Stored XSScriticalView or DownloadUNDERCODE2025-06-04
WordPress≤6.91Stored XSSmediumView or DownloadUNDERCODE2025-06-04
WordPress≤1.5.2SQL InjectioncriticalView or DownloadUNDERCODE2025-06-04
Hibernate Validator<6.2.0.CR1, 7.0.0.Alpha1-CR1EL InjectionmoderateView or DownloadUNDERCODE2025-06-05
Node.js1.4.4-lts.1 - 2.0.0DoS CrashcriticalView or DownloadUNDERCODE2025-06-05
WordPress5.0.0-BETA0 to 5.0.1Insecure DeserializationcriticalView or DownloadUNDERCODE2025-06-05
Linuxusers crate 0.8.0+Privilege escalationmoderateView or DownloadUNDERCODE2025-06-05
HAX CMSPSU DeploymentInformation DisclosurecriticalView or DownloadUNDERCODE2025-06-05
Deno<1.25.2Import BypasscriticalView or DownloadUNDERCODE2022-08-18
Grafana< 0.0.0-20250521183405Permission bypasshighView or DownloadUNDERCODE2025-06-05
Rust crateAllMemory unsafetylowView or DownloadUNDERCODE2025-06-05
SignXML<4.0.4Algorithm ConfusionmoderateView or DownloadUNDERCODE2025-06-05
SignXML<3.0.0Timing AttackmoderateView or DownloadUNDERCODE2025-06-05
AstrBot< v3.5.13Path TraversalcriticalView or DownloadUNDERCODE2025-06-05
Umbraco CMS<15.4.2, <16.0.0File upload bypasscriticalView or DownloadUNDERCODE2025-06-05
WSO2 Products6.x, 7.xPrivilege EscalationmoderateView or DownloadUNDERCODE2025-06-04
Deno<= 1.40.0Permission BypasscriticalView or DownloadUNDERCODE2025-06-04
Deno<=1.35.0Permission bypassmediumView or DownloadUNDERCODE2025-06-04
Auth0 Next.js SDK4.0.1 - 4.6.0Cache-Control BypasscriticalView or DownloadUNDERCODE2024-03-15
Deno<=1.35.0Env bypasscriticalView or DownloadUNDERCODE2025-06-04
webpack-dev-server< 4.15.1CSWSHcriticalView or DownloadUNDERCODE2024-06-05
Windows<5.8.1Insecure Config LoadingmediumView or DownloadUNDERCODE2024-06-05
Webpack-dev-server<5.0.0Source Code TheftcriticalView or DownloadUNDERCODE2025-03-15
DenoPost-commit 0d1beedAuth-tag bypasscriticalView or DownloadUNDERCODE2025-06-04
Auth0 PHP SDK8.0.0-BETA3 to 8.3.0Insecure DeserializationcriticalView or DownloadUNDERCODE2025-06-04
Apache Superset<4.1.2SQL InjectioncriticalView or DownloadUNDERCODE2025-05-30
WordPress Plugin≤1.4.0Stored XSScriticalView or DownloadUNDERCODE2025-06-04
Zitadel<2.70.12, <2.71.10, <3.2.2Host header injectioncriticalView or DownloadUNDERCODE2025-06-04
WordPress Plugin≤1.12Missing AuthorizationcriticalView or DownloadUNDERCODE2025-06-04
WordPress≤1.5.2Stored XSScriticalView or DownloadUNDERCODE2025-06-04
PHPGurukul Dairy Farm1.3SQL InjectioncriticalView or DownloadUNDERCODE2025-06-04
WordPress≤1.0.31CSRFcriticalView or DownloadUNDERCODE2025-06-04
WordPress≤1.6.3Missing capability checkmediumView or DownloadUNDERCODE2025-06-04
PHPGurukul Dairy1.3SQL InjectioncriticalView or DownloadUNDERCODE2025-06-04
FreeScout<1.8.181Race ConditionmediumView or DownloadUNDERCODE2025-06-04
Qualcomm SnapdragonMultipleMemory corruptioncriticalView or DownloadUNDERCODE2025-06-04
TOTOLINK A950RG4.1.2cu.5204Command InjectioncriticalView or DownloadUNDERCODE2025-05-02
Tenda RX3V16.03.13.11Stack OverflowcriticalView or DownloadUNDERCODE2025-06-04
CodeAstro Real Estate1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-06-04
SCALANCE LPE9403AllStack overflowmediumView or DownloadUNDERCODE2025-06-04
SCALANCE LPE9403All versionsAuth bypasscriticalView or DownloadUNDERCODE2025-06-04
Fortinet FortiPortal7.0.0-7.0.9, 7.2.0-7.2.5, 7.4.0Sensitive Data ExposurecriticalView or DownloadUNDERCODE2025-06-04
FreeScout<1.8.180Activation bypassmediumView or DownloadUNDERCODE2025-06-04
Fortinet FortiOS7.2.0–7.2.7, 7.0.0–7.0.14Integer overflow (DoS)criticalView or DownloadUNDERCODE2025-06-04
FreeScout<1.8.180Mass assignmentmediumView or DownloadUNDERCODE2025-06-04
FreeScout<1.8.180Mass AssignmentcriticalView or DownloadUNDERCODE2025-06-04
FortiClient (Windows)7.2.0 - 7.2.1Information DisclosuremediumView or DownloadUNDERCODE2025-06-04
FreeScout<1.8.180IDORcriticalView or DownloadUNDERCODE2025-06-04
FreeScout<1.8.180Directory DeletioncriticalView or DownloadUNDERCODE2025-06-04
1000 Projects1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-06-04
FreeScout<1.8.180Mass-assignmentcriticalView or DownloadUNDERCODE2025-06-04
FortiClient Mac7.0.0-7.4.2Privilege EscalationcriticalView or DownloadUNDERCODE2025-06-04
FreeScout<1.8.180Path TraversalcriticalView or DownloadUNDERCODE2025-06-04
Fortinet FortiOS7.4.0-7.4.3Buffer Over-readcriticalView or DownloadUNDERCODE2025-06-04
Absolute Secure Access<13.54Permission BypassmediumView or DownloadUNDERCODE2025-06-04
WordPress≤ 2.0.4Reflected XSScriticalView or DownloadUNDERCODE2025-06-04
Drupal AI0.0.0 - 1.0.3Missing AuthorizationcriticalView or DownloadUNDERCODE2025-06-04
Post SMTP≤ 2.9.11Missing AuthorizationcriticalView or DownloadUNDERCODE2025-06-04
SourceCodester Health Center1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-06-04
Drupal AI Module1.0.0 - 1.0.2CSRFmediumView or DownloadUNDERCODE2025-06-04
IBM Security Guardium12.0Information DisclosuremediumView or DownloadUNDERCODE2025-06-04
WordPress (GiveWP)≤ 3.19.3Object InjectioncriticalView or DownloadUNDERCODE2025-06-04
Drupal<2.0.3Brute Force BypasscriticalView or DownloadUNDERCODE2025-06-04
Fortinet FortiProxy/FortiOS7.6.0-7.6.1, 7.4.4-7.4.6Authentication BypasscriticalView or DownloadUNDERCODE2025-06-04
FreeScout<1.8.180Stored XSSmediumView or DownloadUNDERCODE2025-06-04
Django-Helpdesk<1.0.0Data ExposuremoderateView or DownloadUNDERCODE2025-06-04
Apache Roller≤6.1.4Session fixationcriticalView or DownloadUNDERCODE2025-06-03
Apache Airflow<6.2.0SQL InjectioncriticalView or DownloadUNDERCODE2025-06-03
Apple OS StackiOS ≤18.4, macOS ≤15.4, tvOS ≤18.4, visionOS ≤2.4Memory CorruptioncriticalView or DownloadUNDERCODE2025-06-03
Craft CMS<4.15.3 / <5.7.5Session File InjectioncriticalView or DownloadUNDERCODE2025-06-04
ScreenConnect≤25.2.3ViewState RCEcriticalView or DownloadUNDERCODE2025-06-03
FFmpeg≤ 7.1Stack overflowcriticalView or DownloadUNDERCODE2025-06-03
FFmpeg≤ 7.1Null pointer dereferencemediumView or DownloadUNDERCODE2025-06-03
Linux Kernel5.14 - 6.6Use-After-FreecriticalView or DownloadUNDERCODE2024-01-15
Tmall Demo<= 20250505Unrestricted File UploadcriticalView or DownloadUNDERCODE2025-06-03
npm<5.9.2URL validation bypassmediumView or DownloadUNDERCODE2025-06-03
D-Link DI-7003GV224.04.18D1Info DisclosuremediumView or DownloadUNDERCODE2025-06-03
H3C SecCenterSMP-E1114P02 (≤20250513)Path TraversalcriticalView or DownloadUNDERCODE2025-06-03
D-Link DCS-932L2.18.01Stack overflowcriticalView or DownloadUNDERCODE2025-06-03
FoxCMS1.2.5SQL InjectioncriticalView or DownloadUNDERCODE2025-06-03
D-Link DI-7003GV224.04.18D1 R(68125)Improper AuthenticationcriticalView or DownloadUNDERCODE2025-06-03
Campcodes S&I1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-06-03
Tenda AC6V15.03.05.16Stack OverflowcriticalView or DownloadUNDERCODE2025-06-03
Tmall Demo≤ 20250505DOM XSSmediumView or DownloadUNDERCODE2025-06-03
Tmall Demo≤ 20250505Stored XSSmediumView or DownloadUNDERCODE2025-05-24
H3C SecCenter SMPE1114P02Path TraversalmediumView or DownloadUNDERCODE2025-05-25
D-Link DI-7003GV224.04.18D1DoScriticalView or DownloadUNDERCODE2025-06-03
Tmall Demo≤ 20250505Stored XSSmediumcvss51View or DownloadUNDERCODE2025-05-24
H3C GR-5400AX≤ 100R008Buffer OverflowcriticalView or DownloadUNDERCODE2025-06-03
D-Link DI-7003GV224.04.18D1 R(68125)Information DisclosuremediumView or DownloadUNDERCODE2025-06-03
H3C SecCenterSMP-E1114P02 (≤20250513)Path Traversalmediumcvss53View or DownloadUNDERCODE2025-06-03
Snipe-IT< 8.1.0Auth BypasscriticalView or DownloadUNDERCODE2025-06-03
Apache InLong1.13.0 - 2.1.0Deserialization RCEcriticalView or DownloadUNDERCODE2025-06-03
D-Link DI-810016.07.26A1Authentication BypasscriticalView or DownloadUNDERCODE2025-06-03
Android25.03.21.0Cleartext storagemediumView or DownloadUNDERCODE2025-06-03
Infoblox NETMRI<7.6.1Command InjectioncriticalView or DownloadUNDERCODE2025-06-03
Blizzard Battle.netv2.40.0.15267Privilege EscalationcriticalView or DownloadUNDERCODE2025-06-03
DetailDescriptionFW-WGS-804HPTv1.305b241111Stack OverflowcriticalView or DownloadUNDERCODE2025-06-03
DocArray≤0.40.1Prototype PollutioncriticalView or DownloadUNDERCODE2025-06-03
Defog-AI Introspect≤ 0.1.4Code InjectioncriticalView or DownloadUNDERCODE2025-06-03
Infoblox NETMRI<7.6.1Authentication BypasscriticalView or DownloadUNDERCODE2025-06-03
Infoblox NETMRI<7.6.1SQL InjectioncriticalView or DownloadUNDERCODE2025-06-03
CMS Made Simple2.2.21Stored XSSmediumView or DownloadUNDERCODE2025-06-03
Chanjet CRM≤20250510SQL InjectioncriticalView or DownloadUNDERCODE2025-05-25
WCMS≤8.3.11Auth BypasscriticalView or DownloadUNDERCODE2025-06-03
Gokapi1.0.1-1.9.6Stored XSSmediumView or DownloadUNDERCODE2025-06-03
Gokapi1.0.1-1.9.6Stored XSScriticalView or DownloadUNDERCODE2025-06-03
Node.js (tar-fs)<1.16.5, 2.0.0-2.1.2, 3.0.0-3.0.8Directory TraversalcriticalView or DownloadUNDERCODE2025-06-03
quic-gov0.50.0Nil-pointer dereferencecriticalView or DownloadUNDERCODE2025-06-03
Drupal8.0.0-10.3.13Stored XSScriticalView or DownloadUNDERCODE2025-06-02
Drupal Matomo Analytics<1.24.0CSRFcriticalView or DownloadUNDERCODE2025-06-02
Drupal<1.8.0, <2.0.8XSScriticalView or DownloadUNDERCODE2025-06-02
Drupal8.0.0–11.1.2Forceful BrowsingcriticalView or DownloadUNDERCODE2025-06-02
Drupal<1.8.0, <2.0.8CSRFmediumView or DownloadUNDERCODE2025-03-31
ALFA AIP-W512v3.2.2.2.3Stack OverflowcriticalView or DownloadUNDERCODE2025-06-02
Drupal WEB-T0.0.0 - 1.1.0Auth Bypass + DoScriticalView or DownloadUNDERCODE2025-06-02
Drupal<2.0.6Forceful BrowsingcriticalView or DownloadUNDERCODE2025-06-02
Arrow2UnmaintainedOOB AccesshighView or DownloadUNDERCODE2025-05-30
Para Serverv1.50.6Credential LeakhighView or DownloadUNDERCODE2025-05-30
Mattermost10.7.0, 10.5.3, 9.11.12Access Control BypasslowView or DownloadUNDERCODE2025-05-30
Mattermost10.7.0-rc1 to 10.7.0Token validation bypassmoderateView or DownloadUNDERCODE2025-05-30
Mattermost9.11.0-10.7.0OAuth credential leakmoderateView or DownloadUNDERCODE2025-05-30
GitHub CLI (go-gh)< 2.12.1Command InjectioncriticalView or DownloadUNDERCODE2025-05-30
Apache Superset< 4.1.2SQL InjectionhighView or DownloadUNDERCODE2025-05-30
Spring Cloud Gateway4.0.0-4.2.2Header InjectionhighView or DownloadUNDERCODE2025-05-30
ProxyMIS Interview≤ 1.01SQL InjectioncriticalView or DownloadUNDERCODE2025-05-30
WordPress Plugin≤ 2.0.12PHP LFI/RFIcriticalView or DownloadUNDERCODE2025-05-30
WordPress≤2.0.0DOM-Based XSScriticalView or DownloadUNDERCODE2025-05-30
WordPress (Elementor)≤1.0.14Stored XSScriticalView or DownloadUNDERCODE2025-05-30
WordPress Plugin≤2.2.11Object InjectioncriticalView or DownloadUNDERCODE2025-05-30
Wire-Webapp<2025-05-14-production.0Persistent local datamediumView or DownloadUNDERCODE2025-05-22
Group-Office<6.8.119, <25.0.20DOM-based XSSmediumView or DownloadUNDERCODE2025-05-29
IBM Aspera Faspex5.0.0 - 5.0.12Improper Access ControlcriticalView or DownloadUNDERCODE2025-05-29
Wavlink WL-WN579A3v1.0Command InjectioncriticalView or DownloadUNDERCODE2025-05-29
Fiber (Go)2.52.6DoS via panicmediumView or DownloadUNDERCODE2025-05-29
Group-Office<6.8.119, <25.0.20Persistent XSSmediumView or DownloadUNDERCODE2025-05-29
Group-Office<6.8.119, <25.0.20Stored XSSmediumView or DownloadUNDERCODE2025-05-29
Navidrome<0.50.0Auth BypasscriticalView or DownloadUNDERCODE2025-05-29
Apache Tomcat9.0.0-11.0.6Constraint bypasslowView or DownloadUNDERCODE2025-05-29
Mattermost10.7.0-10.7.0Privilege EscalationmoderateView or DownloadUNDERCODE2025-05-29
Gradio<4.13.0Arbitrary File CopycriticalView or DownloadUNDERCODE2023-06-15
WordPress (WooCommerce)≤ 2.2.2Stored XSScriticalView or DownloadUNDERCODE2025-05-29
Xylus Themes≤1.8.5Stored XSScriticalView or DownloadUNDERCODE2025-05-29
CiyaShop≤ 4.18.0Object InjectioncriticalView or DownloadUNDERCODE2025-05-29
Chimpstudio FoodBakery≤ 3.3Insecure DeserializationcriticalView or DownloadUNDERCODE2025-05-29
WordPress≤7.0Object InjectioncriticalView or DownloadUNDERCODE2025-05-29
VideoWhisper Live Streaming≤6.2.4CSRFmediumView or DownloadUNDERCODE2025-05-29
ThemeGoods Altair≤ 5.2.2Object InjectioncriticalView or DownloadUNDERCODE2025-05-29
WordPress≤2.4.6Stored XSScriticalView or DownloadUNDERCODE2025-05-29
OA System< v2025.01.01XSScriticalView or DownloadUNDERCODE2025-05-29
OA System< v2025.01.01Stored XSScriticalView or DownloadUNDERCODE2025-05-29
Microsoft Scripting EnginePre-patch 2025Type ConfusioncriticalView or DownloadUNDERCODE2025-05-29
Math Library0.2.0XXE (CWE-611)criticalView or DownloadUNDERCODE2025-05-29
Navidrome0.55.0 - 0.55.2SQL InjectioncriticalView or DownloadUNDERCODE2025-05-29
Fabio LB<1.8.3Header strippingcriticalView or DownloadUNDERCODE2025-05-30
Next.js13.0.0 - 13.4CSWSHcriticalView or DownloadUNDERCODE2025-05-28
Multicast<2.0.9a3Dependency ConfusioncriticalView or DownloadUNDERCODE2025-05-29
vLLMPre-patchInput validation bypasscriticalView or DownloadUNDERCODE2025-05-28
vLLM< 0.4.0Regex DoSmoderateView or DownloadUNDERCODE2025-05-28
vLLM<= 0.4.1ReDoScriticalView or DownloadUNDERCODE2024-06-10
vLLMPre-fix versionsReDoScriticalView or DownloadUNDERCODE2025-05-28
vLLM<0.4.0Insecure HashingmediumView or DownloadUNDERCODE2024-06-10
Apache Commons<1.11.0, <2.0.0-M2ClassLoader hijackingcriticalView or DownloadUNDERCODE2019-12-01
Mautic<4.4.0Open RedirectionmediumView or DownloadUNDERCODE2025-05-28
Argo CD< v3.0.4, < v2.14.13, < v2.13.8XSS via URLcriticalView or DownloadUNDERCODE2025-05-28
Mautic1.0.0 - 4.4.15, 5.0.0-alpha - 5.2.5, 6.0.0-alpha - 6.0.1User EnumerationmediumView or DownloadUNDERCODE2025-05-28
Mautic<4.4.8Unauthenticated preview accessmediumView or DownloadUNDERCODE2025-05-28
Mautic<4.4.0.env exposurecriticalView or DownloadUNDERCODE2025-05-28
ZITADEL<3.2.2, <2.71.11, <2.70.12Host Header InjectioncriticalView or DownloadUNDERCODE2025-05-28
Mautic<4.4.0IDORcriticalView or DownloadUNDERCODE2025-05-28
LLama-Index CLI<0.4.1OS Command InjectionhighView or DownloadUNDERCODE2025-05-28
Hackney (Erlang/Elixir)< 1.24.0Connection Pool ExhaustionlowView or DownloadUNDERCODE2025-05-28
Amazon Redshift2.0.872-2.1.6SSL bypasscriticalView or DownloadUNDERCODE2025-05-28
Chrome PHP<1.14.0XSS via `CssSelector`moderateView or DownloadUNDERCODE2025-05-28
Edgeless Systems Contrast<=1.7Information DisclosurecriticalView or DownloadUNDERCODE2025-05-28
GitHub ActionsUnpatched workflowsCode InjectioncriticalView or DownloadUNDERCODE2025-05-28
Apache InLong1.13.0 - 2.1.0JDBC DeserializationhighView or DownloadUNDERCODE2025-05-28
Valtimo Backend LibrariesPre-patchUnauthorized Object AccesshighView or DownloadUNDERCODE2025-05-28
Apache InLong1.13.0 - 2.1.0JDBC Invisible Character BypassmoderateView or DownloadUNDERCODE2025-05-28
Apache InLong1.13.0 - 2.1.0JDBC URLEncode bypassmoderateView or DownloadUNDERCODE2025-05-28
Apple WebKit< Safari 18.3Memory corruptioncriticalView or DownloadUNDERCODE2025-05-28
Student Project Allocation System1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-28
Apple ecosystemvisionOS<2.3, iOS<18.3Memory corruptioncriticalView or DownloadUNDERCODE2025-05-28
Blood Bank Mgmt1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-28
Apple OS SuitevisionOS <2.3, iOS/iPadOS <18.3, macOS <15.3, watchOS <11.3, tvOS <18.3File system permission bypasscriticalView or DownloadUNDERCODE2025-05-28
macOSVentura <13.7.3, Sequoia <15.3, Sonoma <14.7.3Filesystem bypasscriticalView or DownloadUNDERCODE2025-05-28
Firefox/Thunderbird<138.0.4/<128.10.2Memory CorruptioncriticalView or DownloadUNDERCODE2025-05-22
Mozilla Firefox/Thunderbird< 138.0.4OOB Read/WritecriticalView or DownloadUNDERCODE2025-05-28
Assimp5.4.3Stack overflowcriticalView or DownloadUNDERCODE2025-05-28
PHPGurukul Directory Management2.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-28
Codeastro Bus Bookingv1.0IDOR ExploitcriticalView or DownloadUNDERCODE2025-05-28
Assimp5.4.3OOB ReadmediumView or DownloadUNDERCODE2025-05-28
SourceCodester CDMS1.0Directory ListingcriticalView or DownloadUNDERCODE2025-05-28
SourceCodester CDMS1.0Unrestricted UploadcriticalView or DownloadUNDERCODE2025-05-28
Campcodes Sales and Inventory System1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-28
SourceCodester Stock Management System1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-28
LibreNMS≤25.4.0Stored XSScriticalView or DownloadUNDERCODE2025-05-28
PyTorch≤2.5.1RCEcriticalView or DownloadUNDERCODE2025-05-28
ITSourceCode Restaurant Mgmt1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-28
Restaurant Management System1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-28
itsourcecode S&I System1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-28
Campcodes Shopping Portal1.0Unrestricted File UploadcriticalView or DownloadUNDERCODE2025-05-27
Campcodes Cybercafe1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-27
PHPGurukul1.0Stored XSSmediumView or DownloadUNDERCODE2025-05-27
PHPGurukul ERMS1.3SQL InjectioncriticalView or DownloadUNDERCODE2025-05-27
SourceCodester CDMS1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-27
Campcodes Online Shopping1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-27
Campcodes Shopping Portal1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-27
Sourcecodester1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-27
Online Time Table Generator1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-27
Python/PyPI≤1.1.5Unsafe DeserializationmoderateView or DownloadUNDERCODE2025-05-26
ActiveMQ Artemis<= 0.0.0-20250418141202Credential ReusemoderateView or DownloadUNDERCODE2025-05-28
Apple OS StackwatchOS <11.5, macOS <14.7.6, iOS <18.5Integer OverflowcriticalView or DownloadUNDERCODE2025-05-27
Apple OS (iOS/macOS/watchOS)Multiple (see fixed versions)Kernel Memory CorruptioncriticalView or DownloadUNDERCODE2025-05-27
iOS/iPadOS<18.5Deleted call recording leakagemediumView or DownloadUNDERCODE2025-05-27
Apple EcosystemiOS/macOS/watchOS/tvOS/visionOS/SafariMemory CorruptioncriticalView or DownloadUNDERCODE2025-05-27
macOSVentura <13.7.6, Sonoma <14.7.6, Sequoia <15.5Sandbox EscapecriticalView or DownloadUNDERCODE2025-05-12
Apple macOS/iOSVentura 13.x, Sonoma 14.x, Sequoia 15.x, iPadOS 17.xKeychain data leakmediumView or DownloadUNDERCODE2025-05-27
macOS<15.5Data exposurecriticalView or DownloadUNDERCODE2025-05-12
Apple iPadOS/macOSiPadOS <17.7.7, Ventura <13.7.6Double-freecriticalView or DownloadUNDERCODE2025-05-27
macOSVentura 13.x, Sequoia 15.x, Sonoma 14.xPrivacy bypasscriticalView or DownloadUNDERCODE2025-05-27
Apple macOS/iPadOSVentura 13.7.5, Sonoma 14.7.5, Sequoia 15.4, iPadOS 17.7.6Location data leakcriticalView or DownloadUNDERCODE2025-05-27
macOSVentura <13.7.6, Sequoia <15.5, Sonoma <14.7.6ASLR bypasscriticalView or DownloadUNDERCODE2025-05-27
macOS<15.5Info DisclosuremediumView or DownloadUNDERCODE2025-05-27
Apple OS StackwatchOS <11.5, macOS <14.7.6/15.5, iOS/iPadOS <18.5Privilege EscalationcriticalView or DownloadUNDERCODE2025-05-27
iOS/iPadOS<18.5Residual call history leakagemediumView or DownloadUNDERCODE2025-05-27
iOS/iPadOS<17.7.7, <18.5Lock screen bypassmediumView or DownloadUNDERCODE2025-05-27
Apple OS (visionOS, iOS, iPadOS, macOS, tvOS)Pre-visionOS 2.5, iOS/iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5Kernel Memory CorruptioncriticalView or DownloadUNDERCODE2025-05-27
Apple OS StackwatchOS <11.5, macOS <14.7.6, tvOS <18.5, iOS/iPadOS <17.7.7/18.5Memory CorruptioncriticalView or DownloadUNDERCODE2025-05-27
Apple OS SuiteiOS <18.5, macOS <15.5Image DoScriticalView or DownloadUNDERCODE2025-05-27
Apple DevicesiOS 18.5, macOS 15.5, Safari 18.5WebKit Input ValidationcriticalView or DownloadUNDERCODE2025-05-27
macOS<14.7.6, <15.5Kernel memory corruptioncriticalView or DownloadUNDERCODE2025-05-27
macOSVentura 13.7.5, Sequoia 15.4, Sonoma 14.7.5File system bypasscriticalView or DownloadUNDERCODE2025-05-27
macOS/iOS/tvOS/visionOSSonoma 14.7.5 and belowKernel panic via IOKitcriticalView or DownloadUNDERCODE2025-05-27
macOSVentura 13.x, Sequoia 15.x, Sonoma 14.xPrivacy Bypass via Log LeakcriticalView or DownloadUNDERCODE2025-05-27
macOS<15.5Sandbox EscapecriticalView or DownloadUNDERCODE2025-05-27
Apple OS SuitewatchOS <11.5, macOS <14.7.6, tvOS <18.5, iOS/iPadOS <17.7.7/18.5Memory CorruptioncriticalView or DownloadUNDERCODE2025-05-27
macOSPre-Sequoia 15.5Information disclosuremediumView or DownloadUNDERCODE2025-05-27
macOSPre-Sequoia 15.5Sandbox EscapecriticalView or DownloadUNDERCODE2025-05-27
macOSPre-15.5Privilege EscalationcriticalView or DownloadUNDERCODE2025-05-12
iOS, iPadOS<18.5State management flawmediumView or DownloadUNDERCODE2025-05-27
Apple WebKitSafari <18.5, iOS/iPadOS <18.5, macOS <15.5Memory corruptioncriticalView or DownloadUNDERCODE2025-05-27
PHPGurukul CMS2.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-27
macOSPre-15.5Data access bypasscriticalView or DownloadUNDERCODE2025-05-27
macOS<15.5Information DisclosurecriticalView or DownloadUNDERCODE2025-05-27
DocArray≤ 0.40.1Prototype PollutioncriticalView or DownloadUNDERCODE2025-05-27
Python/pypickle≤1.1.5Privilege EscalationmoderateView or DownloadUNDERCODE2025-05-26
FunAudioLLM InspireMusic<= bf32364bcb0d1Unsafe deserializationcriticalView or DownloadUNDERCODE2025-05-27
Laravel Rest API< 2.13.0Validation BypassmoderateView or DownloadUNDERCODE2025-05-27
PyTorch2.6.0Memory corruptionmediumView or DownloadUNDERCODE2025-05-28
SourceCodester AVMS1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-28
WordPress Plugin≤5.2.0PHP Local File InclusioncriticalView or DownloadUNDERCODE2025-05-28
WordPress≤6.3.5Local File InclusioncriticalView or DownloadUNDERCODE2025-05-28
Rust Crate0.2.0Integer OverflowlowView or DownloadUNDERCODE2025-05-27
Django<8.4.1Token LeakcriticalView or DownloadUNDERCODE2025-05-27
StrapiLatestSSRFcriticalView or DownloadUNDERCODE2025-05-27
Rust crate0.2.2Unsafe drop()lowView or DownloadUNDERCODE2025-05-27
Rust `memory_pages`0.1.0Division by zerolowView or DownloadUNDERCODE2025-05-27
Supabase/auth-js< 2.69.1Path TraversalmediumView or DownloadUNDERCODE2025-05-27
Rust crate0.1.0Unsound unlocklowView or DownloadUNDERCODE2025-05-27
Fess<13.10Insecure Temp FilesmediumView or DownloadUNDERCODE2023-01-15
NETSCOUT nGeniusONE< 6.4.0 b2350Insecure PermissionscriticalView or DownloadUNDERCODE2025-05-28
NETSCOUT nGeniusONE< 6.4.0 b2350Authentication BypasscriticalView or DownloadUNDERCODE2025-05-27
NETSCOUT nGeniusONE<6.4.0 b2350Stored XSScriticalView or DownloadUNDERCODE2025-05-27
NETSCOUT nGeniusONE<6.4.0 b2350Arbitrary File CreationcriticalView or DownloadUNDERCODE2025-05-27
NETSCOUT nGeniusONE< 6.4.0 b2350Information DisclosuremediumView or DownloadUNDERCODE2025-05-27
NETSCOUT nGeniusONE< 6.4.0 b2350Broken AuthorizationcriticalView or DownloadUNDERCODE2025-05-28
NETSCOUT nGeniusONE<6.4.0 b2350Hardcoded CredentialscriticalView or DownloadUNDERCODE2025-05-27
Police Station Management System1.0Buffer OverflowcriticalView or DownloadUNDERCODE2025-05-27
Tenda FH4511.0.0.9Stack OverflowcriticalView or DownloadUNDERCODE2025-05-27
Tenda RX2 Pro16.03.30.14Unauthenticated config changecriticalView or DownloadUNDERCODE2025-05-27
Node.js (Marked)<0.3.17ReDoSmoderateView or DownloadUNDERCODE2025-05-23
Tenda RX2 Pro16.03.30.14RCE via UDPcriticalView or DownloadUNDERCODE2025-05-27
Tenda RX2 Pro16.03.30.14Weak CredentialscriticalView or DownloadUNDERCODE2025-05-27
macOSVentura <13.7.6, Sequoia <15.5, Sonoma <14.7.6Privilege EscalationcriticalView or DownloadUNDERCODE2025-05-27
Tenda AC715.03.06.44Buffer OverflowcriticalView or DownloadUNDERCODE2025-05-27
iOS/iPadOS<17.7.7, <18.5UI SpoofingmediumView or DownloadUNDERCODE2025-05-27
Radashi< 1.4.3Prototype PollutionmoderateView or DownloadUNDERCODE2025-05-27
Tenda RX2 Pro16.03.30.14Command InjectioncriticalView or DownloadUNDERCODE2025-05-27
Tenda RX2 Pro16.03.30.14Unauthenticated RCEcriticalView or DownloadUNDERCODE2025-05-27
Tenda RX2 Pro16.03.30.14Static AES reusecriticalView or DownloadUNDERCODE2025-05-27
Tenda AC9V15.03.06.42_multiCommand InjectioncriticalView or DownloadUNDERCODE2025-05-27
Tenda RX2 Pro16.03.30.14Network Isolation BypasscriticalView or DownloadUNDERCODE2025-05-27
SourceCodester Student Result Management1.0Path TraversalcriticalView or DownloadUNDERCODE2025-05-27
itsourcecode Placement Management1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-27
ITsourcecode PMS1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-27
Campcodes SIS1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-27
Tenda RX2 Pro16.03.30.14IV ReusecriticalView or DownloadUNDERCODE2025-05-27
Tenda RX2 Pro16.03.30.14Cleartext AES KeycriticalView or DownloadUNDERCODE2025-05-27
Tenda RX2 Pro16.03.30.14Cleartext credential transmissioncriticalView or DownloadUNDERCODE2025-05-27
Campcodes Sales1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-27
WordPress≤ 1.9.8Auth BypasscriticalView or DownloadUNDERCODE2025-03-13
WordPress≤ 1.9.8CSRFmediumView or DownloadUNDERCODE2025-05-25
WordPress Plugin≤ 4.4.10Stored XSScriticalView or DownloadUNDERCODE2025-05-25
SpringBoot-Manager3.0XSSmediumView or DownloadUNDERCODE2025-05-25
zj1983 zz<= 2024-8SQL InjectioncriticalView or DownloadUNDERCODE2025-05-25
WordPress≤1.0.4Stored XSShighView or DownloadUNDERCODE2025-05-25
zj1983 zz≤ 2024-8SQL InjectioncriticalView or DownloadUNDERCODE2025-05-25
WordPress≤3.4.25Missing capability checkmediumView or DownloadUNDERCODE2025-05-25
zj1983 zz≤ 2024-8SSRFcriticalView or DownloadUNDERCODE2025-05-25
zj1983 zz<= 2024-8Auth bypasscriticalView or DownloadUNDERCODE2025-05-25
zj1983 zz<= 2024-8SSRFcriticalView or DownloadUNDERCODE2025-05-25
zj1983 zz≤ 2024-8XSSmediumView or DownloadUNDERCODE2025-05-25
zj1983 zz≤ 2024-8Unrestricted uploadcriticalView or DownloadUNDERCODE2025-05-25
zzERP≤ 2024-8SSRFcriticalView or DownloadUNDERCODE2025-05-25
zj1983 zzUp to 2024-8SQL InjectioncriticalView or DownloadUNDERCODE2025-05-25
zj1983 zz<=2024-8SQL InjectioncriticalView or DownloadUNDERCODE2025-05-25
OpenVPN2.6.1–2.6.13DoS via replaycriticalView or DownloadUNDERCODE2025-05-23
Tenda AC715.03.06.44Stack overflowcriticalView or DownloadUNDERCODE2025-05-16
TOTOLINK N300RH6.1c.1390_B20191101Command InjectioncriticalView or DownloadUNDERCODE2025-05-18
samlify<2.10.0Signature WrappingcriticalView or DownloadUNDERCODE2025-05-19
Symfony UX Twig<2.25.1Attribute InjectioncriticalView or DownloadUNDERCODE2025-05-19
Node.js>=1.4.4-lts.1DoS via malformed requestcriticalView or DownloadUNDERCODE2025-05-19
Node.js (Multer)<2.0.0Memory LeakcriticalView or DownloadUNDERCODE2025-05-19
OpenPGP.jsv5.x, v6.xSignature SpoofingcriticalView or DownloadUNDERCODE2025-05-19
Hugging Facev4.48.3ReDoSmoderateView or DownloadUNDERCODE2025-05-19
Gardener<1.116.4, 1.117.0-1.117.4, 1.118.0-1.118.1Metadata injectioncriticalView or DownloadUNDERCODE2025-05-19
Gardener<1.116.4, 1.117.0-1.117.5, 1.118.0-1.118.2Privilege EscalationcriticalView or DownloadUNDERCODE2025-05-19
Gardener External DNS Management<= v1.60.0Privilege EscalationcriticalView or DownloadUNDERCODE2025-05-19
PyPI<78.1.1Path TraversalcriticalView or DownloadUNDERCODE2025-05-19
QQBotPrivilege EscalationcriticalView or DownloadUNDERCODE2025-05-19
LibreNMS25.4.0Stored XSScriticalh2stylecolorblueView or DownloadUNDERCODE2025-05-17
SMA100 SSLVPNNot specifiedPath TraversalcriticalView or DownloadUNDERCODE2025-05-19
TOTOLINK A950RGV4.1.2cu.5204_B20210112Command InjectioncriticalView or DownloadUNDERCODE2025-05-20
SMA100 SSLVPNPre-10.2.5Command InjectioncriticalView or DownloadUNDERCODE2025-05-19
SMA100Pre-10.2.1Path TraversalcriticalView or DownloadUNDERCODE2025-05-20
Microsoft Excel2019/2021/365Out-of-bounds readcriticalView or DownloadUNDERCODE2025-05-19
Microsoft SharePoint2019/OnlineRCE via DeserializationcriticalView or DownloadUNDERCODE2025-05-19
Microsoft Excel2019/2021/365Memory CorruptioncriticalView or DownloadUNDERCODE2025-05-19
Microsoft Office2019/2021/365Use-After-FreecriticalView or DownloadUNDERCODE2025-05-19
Microsoft Excel2019/365Heap overflowcriticalView or DownloadUNDERCODE2025-05-19
WordPress≤2.1Stored XSSmediumView or DownloadUNDERCODE2025-05-19
WordPress≤5.1.16Option DeletioncriticalView or DownloadUNDERCODE2025-05-19
OpenCTI6.4.8-6.4.9Access Control BypasscriticalView or DownloadUNDERCODE2025-05-19
Laravel-Auth0 SDK<7.17.0Brute-forceable auth tagscriticalView or DownloadUNDERCODE2025-05-17
Mattermost10.5.0–10.5.2Improper Access ControllowView or DownloadUNDERCODE2025-05-17
Auth0 WordPress Plugin<=5.2.1Session FixationcriticalView or DownloadUNDERCODE2025-05-17
Ollama Server0.5.11DoS via Array Index AbusehighView or DownloadUNDERCODE2025-05-17
Auth0 Symfony SDK<=5.3.1Authentication BypasscriticalView or DownloadUNDERCODE2025-05-17
Mattermost10.6.1, 10.5.2, 10.4.4, 9.11.11Improper Access ControlmoderateView or DownloadUNDERCODE2025-05-17
Mattermost10.5.0–10.5.2Group permission bypassmoderateView or DownloadUNDERCODE2025-05-15
SeaweedFS3.68SQL InjectionmoderateView or DownloadUNDERCODE2025-05-16
npm<5.9.2Incorrect Behavior OrdermoderateView or DownloadUNDERCODE2025-05-16
Auth0-PHP SDK8.0.0-BETA1 - 8.13.0Session ForgerycriticalView or DownloadUNDERCODE2025-05-16
Meteor<= 3.2.1ReDoSmoderateView or DownloadUNDERCODE2025-05-16
Flask-AppBuilder< 4.6.2Open RedirectmoderateView or DownloadUNDERCODE2025-05-16
Jenkins≤1.0Authentication BypasshighView or DownloadUNDERCODE2025-05-16
Jenkins Plugin≤4.0.1-286.v9e25a_740b_a_48Missing PermissionsmoderateView or DownloadUNDERCODE2025-05-16
Jenkins Plugin< 4.0.1-286.v9e25a740ba48CSRFmoderateView or DownloadUNDERCODE2025-05-16
Jenkins<= 2.7.3SSL/TLS Validation BypassmoderateView or DownloadUNDERCODE2025-05-16
Jenkins CloudBees Plugin≤ 374.v194b_d4f0c8c8Stored XSShighView or DownloadUNDERCODE2025-05-16
Jenkins<111.v29fd614b3617Token Validation Bypasscriticalh2stylecolorblueView or DownloadUNDERCODE2025-05-16
VyperPre-fixSide-effect elisionlowView or DownloadUNDERCODE2025-05-16
Tornado<6.5.0DoS via loggingcriticalView or DownloadUNDERCODE2025-05-16
Vyper<0.3.8Side-effect skiplowView or DownloadUNDERCODE2025-05-16
Rustcrossbeam-channel < 0.5.5Double FreemoderateView or DownloadUNDERCODE2025-05-15
Apache IoTDB0.10.0 - 1.3.3, 2.0.1-beta - 2.0.2Info Disclosure via LogsmoderateView or DownloadUNDERCODE2025-05-15
Apache IoTDB0.10.0-1.3.3Information disclosuremoderateView or DownloadUNDERCODE2025-05-15
WebDriverManager1.0.0 to 6.0.0XXEcriticalView or DownloadUNDERCODE2025-05-15
Bullfrog DNS<1.2.3Filtering bypassmoderateView or DownloadUNDERCODE2025-05-15
Apache IoTDB1.0.0-1.3.3RCE via UDFcriticalView or DownloadUNDERCODE2025-05-15
Label Studio<1.8.2Reflected XSSmediumView or DownloadUNDERCODE2023-04-15
Rust crateAll (< 0.4.0)Unsafe mutable staticshighView or DownloadUNDERCODE2025-05-15
motionEye<0.43.1b4RCEcriticalView or DownloadUNDERCODE2025-05-15
Reflex< 0.7.11State tamperingcriticalView or DownloadUNDERCODE2025-05-15
Yggdrasil<1.2.3Privilege EscalationhighView or DownloadUNDERCODE2025-05-15
Sulu CMS2.5.21-2.5.24, 2.6.5-2.6.8, 3.0.0-alpha1-3.0.0-alpha2XXE in SVG uploadcriticalView or DownloadUNDERCODE2025-05-15
Bootstrap Multiselect1.1.2CSRF → XSSmoderateView or DownloadUNDERCODE2025-05-15
Next.js12.x - 14.xCache Poisoning via Race ConditionlowView or DownloadUNDERCODE2025-05-15
Node.js (undici)<5.29.0, 6.0.0–6.21.2, 7.0.0–7.5.0Memory leak via TLScriticalView or DownloadUNDERCODE2025-05-15
Babylon Protocolx/finality moduleSignature replaycriticalView or DownloadUNDERCODE2025-05-15
Babylon BlockchainPre-patch releasesInteger OverflowhighView or DownloadUNDERCODE2025-05-15
KuiperStored XSScriticalView or DownloadUNDERCODE2025-05-14
SourceCodester Gym1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-14
SourceCodester Apartment Visitor Management System1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-14
SourceCodester Kortex Lite1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-14
SourceCodester Online Eyewear Shop1.0Directory Listing ExposuremediumView or DownloadUNDERCODE2025-05-14
SourceCodester1.0Authorization BypassmediumView or DownloadUNDERCODE2025-05-14
SourceCodester1.0Unrestricted File UploadcriticalView or DownloadUNDERCODE2025-05-14
SourceCodester Food Menu Manager1.0Unrestricted File UploadcriticalView or DownloadUNDERCODE2025-05-14
SourceCodester Pharmacy Management1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-14
SourceCodester Telecom Billing1.0Buffer OverflowcriticalView or DownloadUNDERCODE2025-05-14
vLLM0.5.2 - 0.8.4DoS/Data ExposurecriticalView or DownloadUNDERCODE2025-05-14
WordPress<12.3.1Privilege EscalationcriticalView or DownloadUNDERCODE2025-05-14
Web-Arena-X<= 0.2.0Code InjectioncriticalView or DownloadUNDERCODE2025-05-14
CodeAstro Membership1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-14
School Billing System1.0Stack OverflowcriticalView or DownloadUNDERCODE2025-05-14
Placement Management System1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-14
VMware Aria Operations8.x, 9.xInformation DisclosurecriticalView or DownloadUNDERCODE2025-05-14
OXID eShop<7.0.0Information DisclosurehighView or DownloadUNDERCODE2025-05-14
VMware Aria OperationsLogs (unspecified)Stored XSScriticalView or DownloadUNDERCODE2025-05-14
evmOS / Cosmos EVMPre-patch buildsPartial state executioncriticalView or DownloadUNDERCODE2025-05-14
VMware Aria OperationsLogs 8.12.xStored XSScriticalView or DownloadUNDERCODE2025-05-14
VMware Aria OperationsLogs (pre-8.12.2)Privilege EscalationcriticalView or DownloadUNDERCODE2025-05-14
VMware Aria OperationsLogs (pre-8.12.2)Credential DisclosurecriticalView or DownloadUNDERCODE2025-05-14
Payroll Management System1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-15
Life Insurance Management System1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-14
SiYuan Note3.1.18Arbitrary File DeletioncriticalView or DownloadUNDERCODE2025-05-14
Go middleware<1.2.0CSRF bypasscriticalView or DownloadUNDERCODE2025-05-14
Microsoft SharePointUnpatched versions prior to May 2025Deserialization RCEcriticalView or DownloadUNDERCODE2025-05-14
Node.js12.x, 14.x, 16.xHTTP/2 Heap OverflowcriticalView or DownloadUNDERCODE2021-09-29
Adobe InDesign≤ ID19.5.2, ID20.2NULL Pointer DereferencemediumView or DownloadUNDERCODE2025-05-14
Adobe Dreamweaver≤21.4Type ConfusioncriticalView or DownloadUNDERCODE2025-05-14
Adobe InDesign≤ID19.5.2, ≤ID20.2Out-of-bounds writecriticalView or DownloadUNDERCODE2025-05-14
Code-Projects Scheduling System1.0Stored XSSmediumView or DownloadUNDERCODE2025-05-14
Code-Projects Scheduling System1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-14
Online Class Scheduling System1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-14
OpenPubkey<0.10.0Auth BypasscriticalView or DownloadUNDERCODE2025-05-14
RuoYi≤4.8.0Insecure DeserializationcriticalView or DownloadUNDERCODE2025-05-13
ESAFENET CDGV5SQL InjectioncriticalView or DownloadUNDERCODE2025-05-13
Blood Bank Management1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-13
Blood Bank Management System1.0Directory Listing ExposurecriticalView or DownloadUNDERCODE2025-05-13
OPKSSH<0.5.0Auth BypasscriticalView or DownloadUNDERCODE2025-05-14
ESAFENET CDGV5XSSmediumView or DownloadUNDERCODE2025-05-13
.NET SDK8.0.xxx/9.0.xxxSpoofingcriticalView or DownloadUNDERCODE2025-05-14
D-Link routersDIR-890L/DIR-806A1Command injectioncriticalView or DownloadUNDERCODE2025-05-13
PHPGurukul Student Record System3.20SQL InjectioncriticalView or DownloadUNDERCODE2025-05-14
PHPGurukul Zoo2.1SQL InjectioncriticalView or DownloadUNDERCODE2025-05-13
SonicWall SMA1000Workplace InterfaceSSRFcriticalView or DownloadUNDERCODE2025-05-13
Flask3.1.0Key rotation flawmediumView or DownloadUNDERCODE2025-05-13
PHPGurukul SRS3.20SQL InjectioncriticalView or DownloadUNDERCODE2025-05-14
sudo-rs0.2.2, 0.2.5Privilege enumerationmediumView or DownloadUNDERCODE2025-05-13
Netgear JWNR2000v21.0.0.11Command InjectioncriticalView or DownloadUNDERCODE2025-05-14
Apache Parquet≤1.15.1RCEcriticalView or DownloadUNDERCODE2025-05-13
Umbraco.Forms<13.4.2, <15.1.2HTML InjectionlowView or DownloadUNDERCODE2025-05-13
Apache Superset<= 4.1.1Ownership takeovermoderateView or DownloadUNDERCODE2025-05-13
D-Link DIR-880L<= 104WWb01Command InjectioncriticalView or DownloadUNDERCODE2025-05-06
Netgear JWNR2000v21.0.0.11Buffer OverflowcriticalView or DownloadUNDERCODE2025-05-14
D-Link DIR-600L≤ 2.07B01Buffer OverflowcriticalView or DownloadUNDERCODE2025-05-13
Kirby CMS<3.9.8.3, <3.10.1.2, <4.7.1Path TraversalmediumView or DownloadUNDERCODE2024-04-15
Couchbase Server<7.6.4, <7.2.7 (Windows)Unauthorized File AccesscriticalView or DownloadUNDERCODE2025-05-13
Kirby CMS<3.9.8.3, <3.10.1.2, <4.7.1Path TraversalcriticalView or DownloadUNDERCODE2024-04-10
Netgear EX62001.0.3.94Buffer OverflowcriticalView or DownloadUNDERCODE2025-05-14
reNgine<2.5.0Command InjectioncriticalView or DownloadUNDERCODE2025-02-03
Tailoring Management System1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-14
TCMAN GIMv11Unrestricted File UploadcriticalView or DownloadUNDERCODE2025-05-13
Gym Management System1.0SQL Injectioncriticalh2stylecolorblueView or DownloadUNDERCODE2025-05-09
reNgine< 2.2.0Information DisclosurecriticalView or DownloadUNDERCODE2025-05-13
PHPGurukul CMS1.1SQL InjectioncriticalView or DownloadUNDERCODE2025-05-05
PHPGurukul CMS1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-05
Gym Management System1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-13
TCMAN GIMv11SQL InjectioncriticalView or DownloadUNDERCODE2025-05-13
PHPGurukul1.1SQL InjectioncriticalView or DownloadUNDERCODE2025-05-05
TeleMessage Archiving BackendThrough 2025-05-05Cleartext StoragecriticalView or DownloadUNDERCODE2025-05-14
D-Link DIR-619L2.04B04Buffer OverflowcriticalView or DownloadUNDERCODE2025-05-13
D-Link DIR-619L2.04B04Command InjectioncriticalView or DownloadUNDERCODE2025-05-13
H5P-Nodejs-library<9.3.3XSSmoderateView or DownloadUNDERCODE2025-05-12
LlamaIndex0.12.15Recursion DoShighView or DownloadUNDERCODE2025-05-12
GitHub1.13.2-1.13.5Code InjectionmoderateView or DownloadUNDERCODE2025-05-12
Rust crate<=0.2.0Race conditionlowView or DownloadUNDERCODE2025-05-09
Ring (Rust)<0.17.8AES Panic on OverflowmoderateView or DownloadUNDERCODE2025-05-12
OpenStack Ironic<24.1.3, 25.0.0-26.1.1, 27.0.0-29.0.1Path TraversallowView or DownloadUNDERCODE2025-05-12
Rust (trailer crate)≤ 0.1.2Zero-size allocation mishandlinglowView or DownloadUNDERCODE2025-05-12
code-server< v4.99.4SSRFcriticalView or DownloadUNDERCODE2023-11-30
libsql-sqlite3-parser≤ 0.13.0DoS crashlowView or DownloadUNDERCODE2025-05-12
Apache Commons<= 1.10Resource exhaustionlowView or DownloadUNDERCODE2025-05-12
Koillection1.6.10Stored XSSmoderateView or DownloadUNDERCODE2025-05-08
Eclipse Jetty12.0.0 - 12.0.16HTTP/2 OoM ExploitcriticalView or DownloadUNDERCODE2025-05-08
Eclipse Jetty9.4.0-9.4.56Request SmugglingcriticalView or DownloadUNDERCODE2025-05-08
JRuby-OpenSSL0.15.3Hostname verification bypassmoderateView or DownloadUNDERCODE2025-05-08
Django4.2-4.2.20, 5.1-5.1.8, 5.2-5.2.0DoS via `strip_tags()`moderateView or DownloadUNDERCODE2025-05-08
RustUnmaintainedBounds bypassmoderateView or DownloadUNDERCODE2025-05-08
Trix Editor< 2.1.15XSS via pastecriticalView or DownloadUNDERCODE2025-05-08
Ruby Rack< 3.0.9.1DoScriticalView or DownloadUNDERCODE2023-03-15
Easy Appointments1.5.1DoS via resource exhaustionmoderateView or DownloadUNDERCODE2025-05-08
Craft CMS<5.7.5, <4.15.3Session File InjectionmoderateView or DownloadUNDERCODE2025-05-08
Rack<2.2.8, 3.xSession fixationmediumView or DownloadUNDERCODE2024-03-15
Node.js≤4.6.3SAML Signature WrappingcriticalView or DownloadUNDERCODE2025-05-07
Graylog<=6.0.13, 6.1.0-6.1.9Stored XSShighView or DownloadUNDERCODE2025-05-07
Graylog<6.2.0Stored XSShighView or DownloadUNDERCODE2025-05-07
Redox OSPre-2025 patchesHeap overflowlowView or DownloadUNDERCODE2025-05-07
Node.js<=4.6.3SAML bypasshighView or DownloadUNDERCODE2025-05-07
Scanner Public APIUnspecifiedOut-of-Bounds ReadlowView or DownloadUNDERCODE2025-05-07
Apache ActiveMQ<6.1.6, <5.18.7, <5.17.7, <5.16.8Memory exhaustionmoderateView or DownloadUNDERCODE2025-05-07
Liferay Portal7.4.0–7.4.3.131Reflected XSSmoderateView or DownloadUNDERCODE2025-05-07
Cardano (Mithril)<0.12.2 (client), <0.7.44 (aggregator)Inconsistent Snapshot VerificationcriticalView or DownloadUNDERCODE2025-05-07
JBoss EAP< 3.7.11.FinalStored XSScriticalView or DownloadUNDERCODE2025-05-06
Mezzanine CMS6.0.0Stored XSSmoderateView or DownloadUNDERCODE2025-05-06
BRCCv1.2.0Incorrect Access ControlcriticalView or DownloadUNDERCODE2025-05-06
Linux KernelUp to 6.13.0-rc6+Use-After-FreecriticalView or DownloadUNDERCODE2025-05-06
Linux KernelPre-patch versions with IDPF driverNULL Pointer DereferencecriticalView or DownloadUNDERCODE2025-05-06
Linux KernelPre-patch versionsOut-of-bounds readcriticalView or DownloadUNDERCODE2025-05-06
Linux KernelPre-6.14Race ConditioncriticalView or DownloadUNDERCODE2025-05-06
Linux KernelPre-6.14.0-rc2NULL Pointer DereferencecriticalView or DownloadUNDERCODE2025-04-16
Linux KernelUp to 6.14.0-rc6+Use-After-FreecriticalView or DownloadUNDERCODE2025-04-16
Linux KernelUp to 5.15.xNULL DereferencemediumView or DownloadUNDERCODE2025-05-06
Linux KernelPre-patch versionsRace Condition (Use-after-free)criticalView or DownloadUNDERCODE2025-04-16
Goshs0.3.4 - 1.0.4Command ExecutioncriticalView or DownloadUNDERCODE2025-05-06
Terraform WinDNS<=1.0.4Command InjectionlowView or DownloadUNDERCODE2025-05-06
got.scraping< vulnerable versions >SSRF via redirectcriticalView or DownloadUNDERCODE2025-05-06
Tanton_engineUnmaintainedUnsound APImoderateView or DownloadUNDERCODE2025-05-06
vLLM<v0.8.0Insecure DeserializationcriticalView or DownloadUNDERCODE2025-05-06
ZITADEL<3.0.0, <2.71.9, <2.70.10Session FixationcriticalView or DownloadUNDERCODE2025-05-06
Umbraco CMS<10.8.10, 11.0.0-13.8.0User EnumerationmoderateView or DownloadUNDERCODE2025-05-06
Apache Parquet Java≤1.15.1RCE via schemahighView or DownloadUNDERCODE2025-05-06
WordPress≤ 2.2.0Unauthenticated user deletioncriticalView or DownloadUNDERCODE2025-05-06
WordPress≤ 2.3.9Missing AuthorizationcriticalView or DownloadUNDERCODE2025-05-06
WordPress≤ 5.1.3IDORcriticalView or DownloadUNDERCODE2025-05-01
WordPress≤0.2.5.1Arbitrary File UploadcriticalView or DownloadUNDERCODE2025-05-01
WordPress≤5.1.3IDORcriticalView or DownloadUNDERCODE2025-05-06
WordPress≤ 2.2.0Privilege EscalationcriticalView or DownloadUNDERCODE2025-05-01
WordPress≤4.17.4Privilege EscalationcriticalView or DownloadUNDERCODE2025-05-06
WordPress≤0.2.5.4CSRF→RCEcriticalView or DownloadUNDERCODE2025-05-01
WordPress<=5.1.3Stored XSSmediumView or DownloadUNDERCODE2025-05-06
WordPress≤1.5.8Stored XSSmediumView or DownloadUNDERCODE2025-05-06
OpenH264≤ 2.5.0Heap overflowcriticalView or DownloadUNDERCODE2025-05-06
WordPress≤1.0.8Stored XSShighView or DownloadUNDERCODE2025-05-06
WordPress≤5.4Stored XSScriticalView or DownloadUNDERCODE2025-05-06
WordPress≤2.2.1Stored XSSmediumView or DownloadUNDERCODE2025-05-06
WordPress≤5.10.29Stored XSShighh2stylecolorblueView or DownloadUNDERCODE2025-05-06
WordPress≤ 2.6.22Stored XSScriticalView or DownloadUNDERCODE2025-05-06
MediaTek ModemPre-MOLY01334347Certificate Validation BypasscriticalView or DownloadUNDERCODE2025-05-06
SCPPre-patch ALPS09625562Out-of-bounds writecriticalView or DownloadUNDERCODE2025-05-06
Modem BasebandMOLY01513293Information DisclosurecriticalView or DownloadUNDERCODE2025-05-06
Modem FirmwarePre-MOLY00650610Uncaught ExceptioncriticalView or DownloadUNDERCODE2025-05-06
WordPress≤1.1.1Stored XSSmediumView or DownloadUNDERCODE2025-05-06
AndroidMediaTek chipsetsInformation disclosuremediumView or DownloadUNDERCODE2025-05-06
MediaTek Thermal DriverPre-ALPS09698599Race Condition → OOB WritecriticalView or DownloadUNDERCODE2025-05-06
Linkerd< edge-25.2.1, 2.16., 2.17., 2.18.Resource exhaustionmoderateView or DownloadUNDERCODE2025-05-06
Inspektor Gadget0.31.0-0.40.0Policy BypassmoderateView or DownloadUNDERCODE2025-05-06
Langroid<0.53.4XXE InjectionhighView or DownloadUNDERCODE2025-05-05
league/commonmark1.5.0 - 2.6.xXSS bypasscriticalView or DownloadUNDERCODE2025-05-05
macOS/iOS/tvOS/visionOSSequoia 15.4, Ventura 13.7.5, Sonoma 14.7.5Type ConfusioncriticalView or DownloadUNDERCODE2025-05-05
Apple OS FamilyPre-Sequoia 15.4, Pre-Sonoma 14.7.5Integer OverflowmediumView or DownloadUNDERCODE2025-05-05
Apache Tomcat9.0.76–11.0.5Memory leakhighView or DownloadUNDERCODE2025-05-05
Apple OS StackiOS <18.4, macOS <15.4Null DereferencemediumView or DownloadUNDERCODE2025-05-05
Apache Tomcat9.0.0.M1-9.0.102Rule bypasscriticalView or DownloadUNDERCODE2025-05-05
Snipe-IT<8.1.0Incorrect AuthorizationmoderateView or DownloadUNDERCODE2025-05-05
OpenVMPre-0f94c8aInteger OverflowcriticalView or DownloadUNDERCODE2025-05-05
WSO2 API Manager4.2.0 and priorXXE InjectioncriticalView or DownloadUNDERCODE2025-05-05
Craft CMS4.0.0-RC1 - 5.6.14SSTI → RCEcriticalView or DownloadUNDERCODE2025-05-05
MobSF<= v4.3.2ZIP BombcriticalView or DownloadUNDERCODE2025-05-05
Adobe Media Encoder≤25.1, ≤24.6.4Out-of-bounds writecriticalView or DownloadUNDERCODE2025-05-05
Adobe Bridge14.1.5, 15.0.2Heap overflowcriticalView or DownloadUNDERCODE2025-05-05
Adobe Photoshop≤25.12.1, ≤26.4.1Heap OverflowcriticalView or DownloadUNDERCODE2025-05-05
Adobe Premiere Pro25.1, 24.6.4Heap OverflowcriticalView or DownloadUNDERCODE2025-05-05
Adobe Media Encoder25.1, 24.6.4Heap overflowcriticalView or DownloadUNDERCODE2025-05-05
KeystoneJS<6.5.0Filter bypassmediumView or DownloadUNDERCODE2025-05-05
Browser_use modulePre-patchWhitelist bypasscriticalView or DownloadUNDERCODE2025-05-05
Browser Use≤0.1.45URL parsing bypasscriticalView or DownloadUNDERCODE2025-05-03
Rust Crate<0.4.4Type ConfusionlowView or DownloadUNDERCODE2025-05-05
MisskeyAffects versions < X.X.XLogic BypassmediumView or DownloadUNDERCODE2025-05-05
Adobe ColdFusion2023.12/2021.18/2025.0Path TraversalcriticalView or DownloadUNDERCODE2025-05-05
GymXmjpa1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-01-12
liujianview gymxmjpa1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-01-12
Liujianview Gymxmjpa1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-01-12
Fanli2012 native-php-cms1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-05
MobSF<=4.3.2Stored XSShighView or DownloadUNDERCODE2025-05-05
Joomla< 3.7.5SVG sanitization bypassmediumView or DownloadUNDERCODE2023-02-28
KeycloakAffects multiple2FA BypassmoderateView or DownloadUNDERCODE2025-04-29
FeMiner wms1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-02
XWiki1.8.1 to 16.7.0Missing AuthorizationmoderateView or DownloadUNDERCODE2025-04-30
Cloudflare Workers< 0.0.5PKCE bypassmoderateView or DownloadUNDERCODE2025-05-04
KeycloakAffects v21.0.0 - v22.1.1Hostname verification bypasshighView or DownloadUNDERCODE2025-04-29
Cloudflare WorkersPre-fix commitRedirect URI BypasscriticalView or DownloadUNDERCODE2023-03-15
Cloudflare Workers<0.0.5PKCE BypasscriticalView or DownloadUNDERCODE2025-05-04
Open Policy Agent<1.4.0Code InjectioncriticalView or DownloadUNDERCODE2024-01-01
OpenFGA1.3.6 - 1.8.10Auth BypasscriticalView or DownloadUNDERCODE2025-04-30
XWiki8.2 - 8.8XSS via MarkdowncriticalView or DownloadUNDERCODE2025-05-04
Cloudflare WorkersMCP FrameworkPKCE BypassmoderateView or DownloadUNDERCODE2025-05-04
Hashicorp Vault< 1.19.3Information DisclosuremoderateView or DownloadUNDERCODE2025-05-04
ADOdb<5.22.9SQL InjectioncriticalView or DownloadUNDERCODE2025-05-04
Vercel Flags SDK≤3.2.0, ≤3.1.1Information DisclosuremediumView or DownloadUNDERCODE2025-05-04
Vite<=6.3.3, <=6.2.6, <=6.1.5, <=5.4.18, <=4.5.13Directory TraversalcriticalView or DownloadUNDERCODE2025-05-04
FeMiner WMS1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-05-02
Volcano SchedulerPre-patch versionsUnbounded response DoShighView or DownloadUNDERCODE2025-04-30
Rust crate<0.4.0Bounds bypassmoderateView or DownloadUNDERCODE2025-04-30
Jenkins/ssh-agent≤6.11.1SSH key reusecriticalView or DownloadUNDERCODE2025-04-10
ShowDoc< 2.8.7Unrestricted file uploadcriticalView or DownloadUNDERCODE2025-05-04
XWiki<15.10.9, <16.3.0RC1Authentication BypassmediumView or DownloadUNDERCODE2025-05-04
Hashicorp Vault1.10.0-1.19.0Auth BypassmoderateView or DownloadUNDERCODE2025-05-04
CryptoCoinJS base-x<=5.0.0, <=4.0.0, <=3.0.10Homograph bypasscriticalView or DownloadUNDERCODE2025-05-04
XWiki<15.10.14, <16.4.6, <16.10.0Information DisclosuremediumView or DownloadUNDERCODE2025-04-30
cFS/CryptoLib≤1.3.3Memory leakmediumView or DownloadUNDERCODE2025-04-30
OpenEMR<7.0.3.1OOB SSRFmediumView or DownloadUNDERCODE2025-04-30
XWiki Platform<15.10.14Access BypasscriticalView or DownloadUNDERCODE2025-03-19
XWiki5.0-16.7.1Information DisclosuremediumView or DownloadUNDERCODE2025-04-16
CryptoLib<=1.3.3Heap overflowcriticalView or DownloadUNDERCODE2025-03-17
WordPress≤7.8Stored XSScriticalView or DownloadUNDERCODE2025-04-22
XWiki1.8 - 15.10.15, 16.4.5, 16.10.0Blind SQL InjectioncriticalView or DownloadUNDERCODE2025-04-30
Weblate< 5.11Credential DisclosurecriticalView or DownloadUNDERCODE2025-04-15
Tenda AC9V15.03.05.14_multiStack OverflowcriticalView or DownloadUNDERCODE2025-04-23
OpenEMR<7.0.3Reflected XSSmediumView or DownloadUNDERCODE2025-04-30
Tenda AC9 RouterV15.03.05.14_multiStack OverflowcriticalView or DownloadUNDERCODE2025-04-23
Dify<0.6.12Access BypassmediumView or DownloadUNDERCODE2025-04-18
XWiki1.6-milestone-1 to 16.10.0Blind SQL InjectioncriticalView or DownloadUNDERCODE2025-04-23
Node.js12.x-16.xRCE via HTTP/2criticalView or DownloadUNDERCODE2021-09-29
Adobe Commerce≤ 2.4.8-beta2Privilege EscalationcriticalView or DownloadUNDERCODE2025-04-30
Dell SCG Appliance5.26Information ExposurehighView or DownloadUNDERCODE2025-04-30
WordPress≤ 45.10.0Stored XSScriticalView or DownloadUNDERCODE2025-04-30
WordPress≤1.6.3.2SQL InjectioncriticalView or DownloadUNDERCODE2025-04-30
WordPress≤2.2.2Stored XSScriticalView or DownloadUNDERCODE2025-04-30
AngularJSAll versionsSVG sanitization bypasslowView or DownloadUNDERCODE2025-04-30
Adobe Commerce<=2.4.8-beta2CSRF to DoSmediumView or DownloadUNDERCODE2025-04-30
CodeProjects ORMS1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-30
Apache OFBiz< 18.12.19Stored XSScriticalView or DownloadUNDERCODE2025-04-29
Fanli2012 native-php-cms1.0Default CredentialscriticalView or DownloadUNDERCODE2025-04-29
PCMan FTP Server2.0.7Buffer OverflowcriticalView or DownloadUNDERCODE2025-04-29
PHPGurukul Rail Pass1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-29
SourceCodester1.1SQL Injectioncriticalh2stylecolorblueView or DownloadUNDERCODE2025-04-30
WuzhiCMS4.1Code InjectioncriticalView or DownloadUNDERCODE2025-04-29
WordPress<2.94.9Stored XSSmediumh2stylecolorblueView or DownloadUNDERCODE2025-04-03
1000 Projects CMS1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-29
Apple OSmacOS Sequoia <15.4, Ventura <13.7.5, Sonoma <14.7.5Authentication BypasscriticalView or DownloadUNDERCODE2025-04-29
Apple OS stackiOS 18.3, macOS 13.7.5Null pointer dereferencemediumView or DownloadUNDERCODE2025-04-29
Oracle Argus Safety8.2.3CSRFmediumView or DownloadUNDERCODE2025-04-29
Apple OS (macOS/iOS/tvOS/visionOS)Sequoia 15.4, Ventura 13.7.5, Sonoma 14.7.5, iOS/iPadOS 17.7.6/18.4Local Network Information LeakcriticalView or DownloadUNDERCODE2025-04-29
macOS/tvOS/iOS/visionOSSequoia 15.4, Ventura 13.7.5, Sonoma 14.7.5, iOS/iPadOS 17.7.6/18.4DoS via network packetmediumView or DownloadUNDERCODE2025-04-29
Oracle Communications7.4.0-7.5.0Access Control BypassmediumView or DownloadUNDERCODE2025-04-29
Apple OSmacOS Sequoia 15.4, Ventura 13.7.5, Sonoma 14.7.5Use-after-freecriticalView or DownloadUNDERCODE2025-04-29
macOS / Apple OSSequoia 15.4, Ventura 13.7.5, Sonoma 14.7.5Unauthenticated AirPlay ExecutioncriticalView or DownloadUNDERCODE2025-04-29
Oracle Java SE8u441, 11.0.26, 17.0.14, 21.0.6, 24TLS/SSL Handshake BypasscriticalView or DownloadUNDERCODE2025-04-30
Oracle VM VirtualBox<7.0.24, <7.1.6Privilege EscalationhighView or DownloadUNDERCODE2025-04-30
Oracle E-Business Suite12.2.5-12.2.14DoS via HTTPhighView or DownloadUNDERCODE2025-04-29
Oracle Agile PLM9.3.6Unauthenticated Data AccesshighView or DownloadUNDERCODE2025-04-29
Oracle Java SE8u441, 11.0.26, 17.0.142D Memory CorruptionmediumView or DownloadUNDERCODE2025-04-30
Linux KernelPre-5.15.137 (patched in later versions)NULL Pointer DereferencemediumView or DownloadUNDERCODE2025-04-16
Linux Kernel< 6.8.3Race ConditioncriticalView or DownloadUNDERCODE2025-04-16
WordPress≤3.4Stored XSSmediumView or DownloadUNDERCODE2025-04-29
Linux Kernel<6.1.128NULL Pointer DereferencecriticalView or DownloadUNDERCODE2025-04-16
WordPress≤ 2.2Stored XSScriticalView or DownloadUNDERCODE2025-04-29
Linux KernelPre-6.8.3Stack CorruptioncriticalView or DownloadUNDERCODE2025-04-16
SourceCodester1.0OS Command InjectioncriticalView or DownloadUNDERCODE2025-04-29
Linux KernelPre-5.15.120Null Pointer DereferencecriticalView or DownloadUNDERCODE2025-04-29
Linux Kernel< 6.12.13Null Pointer DereferencecriticalView or DownloadUNDERCODE2025-04-29
Linux KernelPre-patch versions (specific TBD)Out-of-Bounds ReadcriticalView or DownloadUNDERCODE2025-04-16
Linux KernelPre-5.15.120NULL Pointer DereferencemediumView or DownloadUNDERCODE2025-04-16
WordPress< 3.8.6Stored XSShighView or DownloadUNDERCODE2025-04-30
Linux Kernelpre-5.15.90Null DereferencecriticalView or DownloadUNDERCODE2025-04-16
Linux Kernel5.15 - 6.8NULL Pointer Dereferencecriticalh2stylecolorblueView or DownloadUNDERCODE2025-04-18
TOTOLINK X18v9.1.0cu.2024_B20220329Command InjectioncriticalView or DownloadUNDERCODE2025-04-29
SourceCodester Church Management1.1SQL InjectioncriticalView or DownloadUNDERCODE2025-04-29
TOTOLINK A810RV4.1.2cu.5182_B20201026Pre-auth RCEcriticalView or DownloadUNDERCODE2025-04-15
Linux Kernelpre-fix versionsOOB Readcriticalh2stylecolorblueView or DownloadUNDERCODE2025-04-18
Linux KernelUp to 5.12.13Use-After-FreecriticalView or DownloadUNDERCODE2021-07-20
Trendnet TEW-929DRU1.0.0.10Stored XSSmediumView or DownloadUNDERCODE2025-04-30
WuzhiCMS4.1.0XSSmediumView or DownloadUNDERCODE2025-04-29
TOTOLINK A800RV4.1.2cu.5137_B20200730Buffer OverflowcriticalView or DownloadUNDERCODE2025-04-30
Linux KernelPre-6.12.0-rc4Inode Type ValidationcriticalView or DownloadUNDERCODE2025-04-18
TOTOLINK EX1200T4.1.2cu.5232_B20210713Pre-auth RCEcriticalh2stylecolorblueView or DownloadUNDERCODE2025-04-22
TOTOLINK EX1200T4.1.2cu.5232_B20210713Pre-auth RCEcriticalView or DownloadUNDERCODE2025-04-29
TOTOLINK routersA810R V4.1.2cu.5182RCEcriticalView or DownloadUNDERCODE2025-04-29
SourceCodester BEMS1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-30
KubernetesKyverno <1.10.2Policy BypasscriticalView or DownloadUNDERCODE2025-04-29
vLLM<= 0.4.1DoScriticalView or DownloadUNDERCODE2024-07-15
YesWiki4.5.3Reflected XSScriticalh2stylecolorblueView or DownloadUNDERCODE2025-04-29
vLLMPre-32b14baf8a1fInsecure DeserializationcriticalView or DownloadUNDERCODE2025-04-29
YesWiki<4.5.4XSSmediumView or DownloadUNDERCODE2025-04-29
Web ApplicationPre-patchUnauthenticated Backup AccesscriticalView or DownloadUNDERCODE2025-04-30
Linux KernelUp to 6.14.0-rc7NULL Pointer DereferencecriticalView or DownloadUNDERCODE2025-04-29
Apache Tomcat9.0.76-102Memory leakmoderateView or DownloadUNDERCODE2025-04-28
CodeZips Gym Managementv1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-29
CryptoLib≤1.3.3Heap Buffer OverflowcriticalView or DownloadUNDERCODE2025-04-29
vLLMMulti-node deploymentsZeroMQ data exposurehighView or DownloadUNDERCODE2025-04-29
Apache Tomcat9.0.76-9.0.102Rewrite bypasslowView or DownloadUNDERCODE2025-04-29
YesWiki<4.5.4Reflected XSSmediumView or DownloadUNDERCODE2025-04-29
Web Applicationv2.5.1Stored XSScriticalView or DownloadUNDERCODE2023-10-15
Linux KernelPre-patch versionsNULL ptr dereferencemediumView or DownloadUNDERCODE2025-04-29
Linux Kernel5.10+Array bounds violationmediumh2stylecolorblueView or DownloadUNDERCODE2025-04-18
YesWikiLatestArbitrary File Write → RCEcriticalView or DownloadUNDERCODE2025-04-29
AWorld OS<= 8c257626e648OS Command InjectioncriticalView or DownloadUNDERCODE2025-04-29
Open5GS2.7.2AMF state machine crashcriticalView or DownloadUNDERCODE2025-04-29
WordPress≤1.0CSRF→Stored XSSmediumView or DownloadUNDERCODE2025-04-29
Ethereum Smart Contract4.8.0 - 4.28.1Allowlist BypasscriticalView or DownloadUNDERCODE2025-04-29
OS4ED openSIS7.0 - 9.1SQL InjectioncriticalView or DownloadUNDERCODE2025-04-29
Linux KernelPre-patch versionsOut-of-bounds stack accessmediumView or DownloadUNDERCODE2025-04-29
Jenkins<= 2.503 / <= 2.492.2 (LTS)Missing permission checkcriticalView or DownloadUNDERCODE2025-04-29
XWiki Platform15.9-16.2Rights BypasscriticalView or DownloadUNDERCODE2025-04-29
Node.js2.1.0-3.5.2Filename Guessinglowh2stylecolorblueView or DownloadUNDERCODE2025-04-29
OS4ED openSIS7.0 to 9.1SQL InjectioncriticalView or DownloadUNDERCODE2025-04-29
Linux Kernel< 6.8.3OOB ReadmediumView or DownloadUNDERCODE2025-04-29
BL-AC2100<=V1.0.4RCEcriticalView or DownloadUNDERCODE2025-04-29
BL-AC2100≤ V1.0.4RCEcriticalView or DownloadUNDERCODE2025-04-29
Jenkins≤ 2.503 / ≤ 2.492.2 (LTS)Missing Permission CheckmediumView or DownloadUNDERCODE2025-04-29
Jenkins<= 2.5.3Sandbox bypasscriticalView or DownloadUNDERCODE2025-04-29
XWiki Platform13.5-rc-1 to 15.10.12Open RedirectmoderateView or DownloadUNDERCODE2025-04-29
XWiki<15.10.13, <16.4.4Privilege EscalationmediumView or DownloadUNDERCODE2025-04-29
XWiki15.10.0-16.7.0Cache-clearing bypasslowView or DownloadUNDERCODE2025-04-29
Craft CMS3.0.0-5.6.16Remote Code ExecutioncriticalView or DownloadUNDERCODE2025-04-28
n8n<1.32.2MIME confusioncriticalView or DownloadUNDERCODE2023-10-31
Spring Boot<=2.7.24.2, 3.1.0-3.1.15.2, 3.2.0-3.2.13.2, 3.3.0-3.3.10, 3.4.0-3.4.4Security BypasshighView or DownloadUNDERCODE2025-04-28
Apereo CAS<= 5.2.6Code InjectioncriticalView or DownloadUNDERCODE2025-04-28
Snowflake Go Driver1.7.0 - 1.13.2TOCTOU race conditionmediumView or DownloadUNDERCODE2025-04-28
Snowflake Connector2.1.2 - 4.4.0TOCTOU race conditionmediumView or DownloadUNDERCODE2025-04-28
PHPGurukulPre-School EnrollmentDirectory TraversalcriticalView or DownloadUNDERCODE2025-04-28
Adobe InDesignID20.1, ID19.5.2 (earlier)Heap OverflowcriticalView or DownloadUNDERCODE2025-04-28
Adobe InDesignID20.1, ID19.5.2Out-of-bounds writecriticalView or DownloadUNDERCODE2025-04-28
Substance3D Designer≤ 14.1Out-of-bounds writecriticalView or DownloadUNDERCODE2025-04-28
Substance3D Designer≤ 14.1Heap OverflowcriticalView or DownloadUNDERCODE2025-04-28
Adobe InDesignID20.1, ID19.5.2 (and earlier)Out-of-bounds writecriticalView or DownloadUNDERCODE2025-04-28
Linux KernelPre-patch versionsOut-of-bounds stack readmediumView or DownloadUNDERCODE2025-04-18
Linux KernelPre-6.8Use-After-FreecriticalView or DownloadUNDERCODE2025-04-25
Linux KernelPre-5.15.120Use-After-FreecriticalView or DownloadUNDERCODE2025-04-25
Linux KernelPre-6.14.0-rc4Use-After-Freecriticalh2stylecolorblueView or DownloadUNDERCODE2025-04-16
Linux KernelPre-5.15.123Use-After-FreecriticalView or DownloadUNDERCODE2025-04-25
Linux KernelPre-patch ksmbdUse-After-FreecriticalView or DownloadUNDERCODE2025-04-25
Moodle<4.1.18, 4.3.0-beta to <4.3.12, 4.4.0-beta to <4.4.8, 4.5.0-beta to <4.5.4IDORmoderateView or DownloadUNDERCODE2025-04-25
Moodle<4.1.18, 4.3.0-4.3.11, 4.4.0-4.4.7, 4.5.0-4.5.3Reflected XSSmoderateView or DownloadUNDERCODE2025-04-25
Moodle LMS<4.1.18, 4.3.0-4.3.11, 4.4.0-4.4.7, 4.5.0-4.5.3Remote Code ExecutionhighView or DownloadUNDERCODE2025-04-25
Erick xmallv1.1 and priorPrivilege EscalationcriticalView or DownloadUNDERCODE2025-04-25
Twonav2.1.18-20241105Information DisclosuremediumView or DownloadUNDERCODE2025-04-25
Moodle LMS<4.1.18, 4.3.0-4.3.11, 4.4.0-4.4.7, 4.5.0-4.5.3CSRF tour duplicationlowView or DownloadUNDERCODE2025-04-25
Moodle<4.1.18, 4.3.0-4.3.11, 4.4.0-4.4.7, 4.5.0-4.5.3CSRF token leaklowView or DownloadUNDERCODE2025-04-25
MyBB1.8.38Information DisclosuremediumView or DownloadUNDERCODE2025-04-25
DragonflyDB<1.27.0DoS via Redis commandmediumView or DownloadUNDERCODE2025-04-25
Moodle<4.1.18, 4.3.0-4.3.11, 4.4.0-4.4.7, 4.5.0-4.5.3IDORmoderateView or DownloadUNDERCODE2025-04-25
JetBrains RubyMine< 2025.1Remote Code ExecutioncriticalView or DownloadUNDERCODE2025-04-25
JEEWMS3.7Zip Slip → RCEcriticalView or DownloadUNDERCODE2025-04-25
Moodle LMS<4.3.0Unauthenticated data exposurehighView or DownloadUNDERCODE2025-04-25
GraphQL Armor<1.7.2Cost Limit BypasscriticalView or DownloadUNDERCODE2025-04-25
Rancher<2.11.1, <2.10.5, <2.9.9Privilege EscalationcriticalView or DownloadUNDERCODE2023-01-01
Steve<v0.2.1, v0.3.3, v0.4.4, v0.5.13TLS bypasscriticalView or DownloadUNDERCODE2025-04-25
Fleet< v0.10.12MitM via SSHcriticalView or DownloadUNDERCODE2025-04-25
Craft CMS3.0.0-RC1 to 5.6.16Remote Code ExecutioncriticalView or DownloadUNDERCODE2025-04-25
code-projects1.0Stored XSScriticalView or DownloadUNDERCODE2025-04-24
GNU Mailman (cPanel/WHM)2.1.39Directory TraversalcriticalView or DownloadUNDERCODE2025-04-24
cPanel/WHMGNU Mailman 2.1.39Command InjectioncriticalView or DownloadUNDERCODE2025-04-24
React-Router7.5.0SSRFcriticalView or DownloadUNDERCODE2024-03-15
React-Router7.5.0Cache PoisoningcriticalView or DownloadUNDERCODE2024-04-25
Mattermost10.4.x ≤ 10.4.2, 10.5.x ≤ 10.5.0, 9.11.x ≤ 9.11.10Improper Input ValidationmoderateView or DownloadUNDERCODE2025-04-24
Infodraw MRS7.1.0.0Directory TraversalcriticalView or DownloadUNDERCODE2025-04-24
h11≤ 0.14.0Request SmugglingcriticalView or DownloadUNDERCODE2025-01-09
SourceCodester Pharmacy System1.0Stored XSSmediumView or DownloadUNDERCODE2025-04-24
SourceCodester1.0Stored XSSmediumView or DownloadUNDERCODE2025-04-24
Mattermost10.4.0-10.4.2Improper Access ControllowView or DownloadUNDERCODE2025-04-24
Mattermost10.4.0-10.4.2DoS via task actionsmoderateView or DownloadUNDERCODE2025-04-24
Python<0.0.25DNS ExfiltrationmoderateView or DownloadUNDERCODE2025-04-24
TP-Link M70001.0.7SQL InjectioncriticalView or DownloadUNDERCODE2025-04-24
TP-Link M72001.0.7SQL Injectioncriticalh2stylecolorblueView or DownloadUNDERCODE2025-04-24
Seven Bears CMS2023SSRFmediumView or DownloadUNDERCODE2025-04-24
Codezips Gym Management1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-23
LMDeploy<= 0.7.1Deserialization RCEcriticalView or DownloadUNDERCODE2025-04-03
PCMan FTP2.0.7Buffer OverflowcriticalView or DownloadUNDERCODE2025-04-23
pgAdmin<= 9.1Stored XSSmediumView or DownloadUNDERCODE2025-04-23
TP-Link EAP1201.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-24
TP-Link TL-WR840N1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-24
PbootCMS3.2.5SSRFmediumView or DownloadUNDERCODE2025-04-23
NodeBB≤4.0.4Stored XSScriticalView or DownloadUNDERCODE2025-04-23
BaseWeb JSite1.0Stored XSSmediumView or DownloadUNDERCODE2025-04-23
SourceCodester1.0Unrestricted UploadcriticalView or DownloadUNDERCODE2025-04-23
SourceCodester CMS1.0Stored XSScriticalView or DownloadUNDERCODE2025-04-23
Nagios Log Server2024R1.3.1Stored XSScriticalView or DownloadUNDERCODE2025-04-23
WordPress≤ 3.1.1PHP Object InjectioncriticalView or DownloadUNDERCODE2025-04-23
SourceCodester CMS1.0Unrestricted File UploadcriticalView or DownloadUNDERCODE2025-04-23
WordPress≤ 3.1.1Arbitrary Shortcode ExecutioncriticalView or DownloadUNDERCODE2025-04-24
WordPress≤ 3.1.1Reflected XSSmediumView or DownloadUNDERCODE2025-04-23
Adobe ColdFusion2023.12, 2021.18, 2025.0Improper Input ValidationcriticalView or DownloadUNDERCODE2025-04-23
Shopware<6.5.8.13SQL InjectioncriticalView or DownloadUNDERCODE2025-04-23
JetBrains Toolbox< 2.6Unencrypted SSH transmissioncriticalView or DownloadUNDERCODE2025-04-23
JetBrains Toolbox App< 2.6Missing SSH host verificationcriticalView or DownloadUNDERCODE2025-04-17
LMDeploy<= 0.7.1Code InjectioncriticalView or DownloadUNDERCODE2025-04-23
Tencent SuperSonic≤ 0.9.8Code InjectioncriticalView or DownloadUNDERCODE2025-04-23
Online Lawyer Management System1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-23
AdminTwo1.0Stored XSSmediumView or DownloadUNDERCODE2025-04-23
ZZCMS2025XSSmediumView or DownloadUNDERCODE2025-04-23
Library Management System1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-23
uTLS<1.7.0TLS downgrade bypassmoderateView or DownloadUNDERCODE2025-04-23
XWiki<16.10.1, <16.4.6, <15.10.16HQL InjectioncriticalView or DownloadUNDERCODE2025-04-23
Laravel Starter11.11.0Stored XSSmoderateView or DownloadUNDERCODE2025-04-22
CUBA Platform<7.2.7Stored XSSmoderateView or DownloadUNDERCODE2025-04-22
Jmix Framework1.0.0-1.6.1, 2.0.0-2.3.0DoS via file uploadmoderateView or DownloadUNDERCODE2025-04-22
Jmix<1.6.2, <2.4.0Content-Type ManipulationmediumView or DownloadUNDERCODE2023-10-15
CUBA Platform<1.1.1XSSmoderateh2stylecolorblueView or DownloadUNDERCODE2025-04-22
Jmix LocalFS1.0.0 - 1.6.1, 2.0.0 - 2.3.9Path TraversalmoderateView or DownloadUNDERCODE2025-04-22
Wazuhv4.9.0RCE via deserializationcriticalView or DownloadUNDERCODE2025-04-22
OctoPrint<=1.10.3Auth bypassmediumView or DownloadUNDERCODE2025-04-22
Crawl4AI<=0.4.247SSRFmoderateView or DownloadUNDERCODE2025-04-21
libxml2<2.13.8, <2.14.2Heap buffer under-readlowView or DownloadUNDERCODE2025-03-15
Alkacon OpenCMSv17.0Stored XSSmoderateView or DownloadUNDERCODE2025-04-21
GoBGP< 3.35.0FlowSpec parser crashmoderateView or DownloadUNDERCODE2025-04-21
GoBGP< 3.35.0Null pointer dereferencehighView or DownloadUNDERCODE2025-04-21
GoBGP< 3.35.0Input length validationmoderateView or DownloadUNDERCODE2025-04-21
one-api≤ 0.6.10Stored XSSmoderateView or DownloadUNDERCODE2025-04-19
OpenCMS17.0Stored XSSmoderateView or DownloadUNDERCODE2025-04-21
QMarkdown (quasar-ui-qmarkdown)< 2.0.5XSS via headersmoderateView or DownloadUNDERCODE2025-04-21
Ciliumv1.15.0-v1.17.2Race ConditioncriticalView or DownloadUNDERCODE2025-04-21
MCMS5.4.3Arbitrary File UploadcriticalView or DownloadUNDERCODE2025-04-21
Amazon.IonDotnet<=1.3.0Infinite Loop DoSmediumView or DownloadUNDERCODE2025-04-21
Traefik<2.10.0Path Traversal BypasscriticalView or DownloadUNDERCODE2025-04-21
Traefik< 1.23.8HTTP Request SmugglingcriticalView or DownloadUNDERCODE2025-04-18
WindowsMMC 5.0+Security BypasscriticalView or DownloadUNDERCODE2025-04-17
libming0.4.8Memory LeakmediumView or DownloadUNDERCODE2025-04-17
libming0.4.8Memory leakmediumView or DownloadUNDERCODE2025-04-17
Windows10/11, Server 2019/2022Use-After-Free (UAF)criticalView or DownloadUNDERCODE2025-04-17
Rasa Pro3.9.0–3.12.5Missing AuthenticationmoderateView or DownloadUNDERCODE2025-04-17
libming0.4.8Memory leakcriticalView or DownloadUNDERCODE2025-02-20
Adobe Commerce≤2.4.8-beta1Access BypasscriticalView or DownloadUNDERCODE2025-04-18
Adobe Commerce≤ 2.4.8-beta1Authorization BypassmediumView or DownloadUNDERCODE2025-04-18
Adobe Commerce≤2.4.8-beta1Path TraversalcriticalView or DownloadUNDERCODE2025-03-17
Jenkins≤4.0.0-282.v5096a_c2db_275Plaintext API Key StoragemediumView or DownloadUNDERCODE2025-04-17
Netis WF-24041.1.124ENDefault passwordcriticalView or DownloadUNDERCODE2025-04-17
Jenkins≤1.0.6Plaintext API Key StoragemediumView or DownloadUNDERCODE2025-04-17
Jenkins≤ 0.1.1Sensitive Data ExposuremediumView or DownloadUNDERCODE2025-04-17
HDF5≤1.14.6Null dereferencemediumView or DownloadUNDERCODE2025-04-17
Jenkins≤1.4.6CSRFmediumView or DownloadUNDERCODE2025-04-17
Jenkinsmonitor-remote-job Plugin 1.0Plaintext Password StoragecriticalView or DownloadUNDERCODE2025-04-17
Netis WF-24041.1.124ENUART debug abusecriticalView or DownloadUNDERCODE2025-04-17
HDF5≤1.14.6Heap overflowmediumView or DownloadUNDERCODE2025-04-17
Assimp5.4.3Out-of-bounds readcriticalView or DownloadUNDERCODE2025-04-17
HDF5≤1.14.6Double FreemediumView or DownloadUNDERCODE2025-04-17
go-git< v5.13DoS via crafted Git responsescriticalView or DownloadUNDERCODE2025-04-16
Online Book Shop1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-16
Facebook Platform-Client-Side Verification BypassMediumView or DownloadUNDERCODE2025-04-17
XWiki Platform5.0 - 16.7.1Information DisclosuremoderateView or DownloadUNDERCODE2025-04-16
Backstage<0.6.0Policy info leakmoderateView or DownloadUNDERCODE2025-04-16
Node.js<2.0.9, 3.x<3.0.5Improper Body ParsingmoderateView or DownloadUNDERCODE2025-04-16
Adobe Commerce≤ 2.4.8-beta1Incorrect AuthorizationcriticalView or DownloadUNDERCODE2025-04-16
Adobe Commerce≤ 2.4.8-beta1Improper Access ControlmediumView or DownloadUNDERCODE2025-04-16
Node.js< 2.0.8, 3.0.0-3.0.3Double writemoderateView or DownloadUNDERCODE2025-04-16
Adobe Commerce≤2.4.8-beta1TOCTOU bypasscriticalView or DownloadUNDERCODE2025-04-15
Mattermost<2.1.0 / 10.5.1Timing AttackmoderateView or DownloadUNDERCODE2025-04-16
Mattermost10.5.0-10.5.1Incorrect AuthorizationlowView or DownloadUNDERCODE2025-04-16
Kubernetes (Kyverno)<1.10.2SSRFcriticalView or DownloadUNDERCODE2025-04-15
PwnDoc<1.2.0Path Traversal→RCEcriticalView or DownloadUNDERCODE2025-04-15
PwnDoc<1.2.0Path Traversal → RCEcriticalView or DownloadUNDERCODE2025-04-15
Adobe After Effects≤25.1, ≤24.6.4OOB ReadcriticalView or DownloadUNDERCODE2025-04-15
Adobe Animate≤24.0.7, ≤23.0.10OOB ReadcriticalView or DownloadUNDERCODE2025-04-15
Adobe Animate≤24.0.7, ≤23.0.10Out-of-Bounds ReadcriticalView or DownloadUNDERCODE2025-04-15
Adobe ColdFusion2023.12/2021.18/2025.0Insecure DeserializationcriticalView or DownloadUNDERCODE2025-04-15
07FLYCMS1.3.9CSRF → RCEcriticalView or DownloadUNDERCODE2025-04-15
WordPress Plugin≤ 25.1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-15
Adobe ColdFusion2023.12, 2021.18, 2025.0RCE via Input ValidationcriticalView or DownloadUNDERCODE2025-04-15
TRENDnet routers1.2.7/1.3.0.106Null pointer dereferencemediumView or DownloadUNDERCODE2025-04-15
CodeAstro Car Rental1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-03
PyTorch2.6.0+cu124DoSmediumView or DownloadUNDERCODE2025-04-15
MannaAndPoem OpenManus<= 2025.3.13Improper Access ControlmediumView or DownloadUNDERCODE2025-04-15
Bluestar Micro Mall1.0Unrestricted File UploadcriticalView or DownloadUNDERCODE2025-04-15
Linux KernelUp to 6.13.0-rc7Race ConditionmediumView or DownloadUNDERCODE2025-04-15
Linux KernelPre-patch versions with PowerVR DRM driverDeadlock in fence releasecriticalView or DownloadUNDERCODE2025-04-15
Linux KernelPre-patch versionsUse-After-Free (UAF)criticalView or DownloadUNDERCODE2025-04-15
libheif1.19.7Buffer OverflowcriticalView or DownloadUNDERCODE2025-04-15
Linuxlibbpf 1.5.0Buffer OverflowcriticalView or DownloadUNDERCODE2025-04-15
Zammad6.4.x <6.4.22FA bypasscriticalView or DownloadUNDERCODE2025-04-15
Zammad6.4.x (<6.4.2)Information ExposuremediumView or DownloadUNDERCODE2025-04-05
Drupal8.0.0–11.1.2Stored XSScriticalView or DownloadUNDERCODE2025-04-15
StudentServlet-JSPRolling releaseXSSmediumView or DownloadUNDERCODE2025-04-15
Drupal AI<1.0.5Command InjectioncriticalView or DownloadUNDERCODE2025-04-15
jQuery-Validation<1.20.0XSS via `showLabel()`moderateView or DownloadUNDERCODE2025-04-15
macOSVentura <13.7.5, Sequoia <15.4, Sonoma <14.7.5Privacy bypasscriticalView or DownloadUNDERCODE2025-04-15
PbootCMS3.2.9Stored XSScriticalView or DownloadUNDERCODE2025-04-15
BlueCMS1.6Arbitrary File DeletioncriticalView or DownloadUNDERCODE2025-04-15
Adobe ColdFusion2023.12/2021.18/2025.0Deserialization RCEcriticalView or DownloadUNDERCODE2025-04-15
Weblate(Affected versions)Credential Leak via URLcriticalView or DownloadUNDERCODE2025-04-04
Adobe ColdFusion2023.12, 2021.18, 2025.0Improper AuthenticationcriticalView or DownloadUNDERCODE2025-04-15
Projectworlds Online Booking1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-15
Adobe ColdFusion2023.12, 2021.18, 2025.0Deserialization RCEcriticalView or DownloadUNDERCODE2025-04-15
ProjectWorlds Online Doctor1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-15
Apache Camel4.8.0-4.8.5, 4.10.0-4.10.2Header InjectioncriticalView or DownloadUNDERCODE2025-04-15
D-LINK DI-810016.07.26A1Buffer OverflowcriticalView or DownloadUNDERCODE2025-04-15
Online Doctor Appointment Booking System1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-15
Online Doctor Booking1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-15
jsonschema2pojo<= 1.2.2Buffer OverflowmoderateView or DownloadUNDERCODE2025-04-14
Mattermost10.5.0-10.5.1, 9.11.0-9.11.9Auth bypassmoderateView or DownloadUNDERCODE2025-04-14
Pleezer<0.16.0Zombie process leakmediumView or DownloadUNDERCODE2025-04-14
CefSharp/Chrome< 134.0.6998.177Sandbox EscapehighView or DownloadUNDERCODE2025-04-12
Jupyter Remote Desktop3.0.0+Network ExposurecriticalView or DownloadUNDERCODE2025-04-12
Formie<2.1.44Stored XSSmediumView or DownloadUNDERCODE2025-04-11
Mattermost9.11.0-9.11.8Improper Access ControllowView or DownloadUNDERCODE2025-04-11
SurrealDB<2.0.5, <2.1.5, <2.2.2SurrealQL InjectioncriticalView or DownloadUNDERCODE2024-03-15
SurrealDB<2.0.5, <2.1.5, <2.2.2SSRF bypassmediumView or DownloadUNDERCODE2025-04-11
SurrealDB<2.0.5, <2.1.5, <2.2.2DoS via CPU exhaustionhighView or DownloadUNDERCODE2025-04-11
SurrealDB<2.0.5, <2.1.5, <2.2.2Memory exhaustionhighView or DownloadUNDERCODE2025-04-11
Vite (Node/Bun)<5.0.0Directory TraversalcriticalView or DownloadUNDERCODE2023-08-22
SurrealDB<2.2.2, <2.1.5, <2.0.5Null Byte DoScriticalView or DownloadUNDERCODE2025-04-10
SurrealDB< 2.1.5Arbitrary File ReadlowView or DownloadUNDERCODE2025-04-10
Linux KernelQAIC driver (pre-patch)Integer OverflowcriticalView or DownloadUNDERCODE2025-04-10
Linux KernelPre-patch versionsInteger OverflowcriticalView or DownloadUNDERCODE2025-04-10
Linux KernelPre-5.15.120Out-of-Bound ReadmediumView or DownloadUNDERCODE2025-04-10
Linux Kernel<6.8.3Memory leakhighView or DownloadUNDERCODE2025-04-10
Linux KernelPre-5.15.120Race ConditioncriticalView or DownloadUNDERCODE2025-04-10
Linux KernelPre-patch versionsIPv6 memory leakmediumView or DownloadUNDERCODE2025-04-10
Linux KernelUp to 6.13.3NULL Pointer DereferencecriticalView or DownloadUNDERCODE2025-04-10
Linux Kernelv5.10-v6.6Race ConditioncriticalView or DownloadUNDERCODE2025-04-10
WeGIA< 3.2.6Auth BypasscriticalView or DownloadUNDERCODE2025-04-10
WordPress≤2.6.22Stored XSSmediumView or DownloadUNDERCODE2025-04-10
WeGIA<3.2.6Stored XSSmediumView or DownloadUNDERCODE2025-04-10
WeGIA<3.2.8SQL InjectioncriticalView or DownloadUNDERCODE2025-04-10
WeGIA<3.2.8Stored XSSmediumView or DownloadUNDERCODE2025-04-10
HCL DevOps DeployPre-10.1.2Authentication BypasscriticalView or DownloadUNDERCODE2025-04-10
Rust0.5.12-0.5.14Double-freemoderateView or DownloadUNDERCODE2025-04-10
WordPress≤1.5.142Stored XSSmediumView or DownloadUNDERCODE2025-04-10
Umbraco CMS9.x, 10.xStored XSScriticalView or DownloadUNDERCODE2023-05-15
Apache POI<5.4.0Improper Input ValidationmoderateView or DownloadUNDERCODE2025-04-10
Helm<3.17.3Stack OverflowcriticalView or DownloadUNDERCODE2025-04-10
Helm<3.17.3Memory exhaustioncriticalView or DownloadUNDERCODE2024-04-10
Linux KernelPre-5.15.120Race ConditionmediumView or DownloadUNDERCODE2025-04-10
Linux KernelBCM2711 devicesPower domain conflictmediumView or DownloadUNDERCODE2025-04-10
Apache Pulsar<3.0.11, <3.3.6, <4.0.4Info leak via logsmoderateView or DownloadUNDERCODE2025-04-10
Ibexa CMSPre-patchXXE InjectioncriticalView or DownloadUNDERCODE2025-04-10
Tenda AC15v15.03.05.19Command InjectioncriticalView or DownloadUNDERCODE2025-04-10
MRCMS3.1.2XSSmediumView or DownloadUNDERCODE2025-04-09
MRCMS3.1.2Path TraversalcriticalView or DownloadUNDERCODE2025-04-09
MRCMS3.1.2Stored XSSmediumView or DownloadUNDERCODE2025-04-09
WordPress<= 12.4.05SQL InjectioncriticalView or DownloadUNDERCODE2025-04-09
SourceCodester Online Medicine Ordering System1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-09
Tenda AC9v15.03.05.19Command InjectioncriticalView or DownloadUNDERCODE2025-04-09
RE11S Routerv1.11Command InjectioncriticalView or DownloadUNDERCODE2025-04-10
RE11Sv1.11Stack OverflowcriticalView or DownloadUNDERCODE2025-04-09
Tenda AC9v15.03.05.19Stack OverflowcriticalView or DownloadUNDERCODE2025-04-09
RE11S Routerv1.11Stack OverflowcriticalView or DownloadUNDERCODE2025-04-09
YzmCMS7.1XSSmediumView or DownloadUNDERCODE2025-04-09
MySQL Server8.0.39, 8.4.2, 9.0.1 (and prior)Thread Pooling DoShighView or DownloadUNDERCODE2025-04-09
Joomla1.0.0-1.4.3SQL InjectioncriticalView or DownloadUNDERCODE2025-04-09
Device AuthorityNot specifiedPermission BypasscriticalView or DownloadUNDERCODE2025-04-09
MySQL Server8.0.40, 8.4.3, 9.1.0Information DisclosurelowView or DownloadUNDERCODE2025-04-09
RuoYi4.8.0Privilege EscalationcriticalView or DownloadUNDERCODE2025-04-09
SourceCodester1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-09
Awesome Surveys≤2.0.10Stored XSScriticalView or DownloadUNDERCODE2025-04-09
XgrammarPre-fix commitsUnbounded cache DoScriticalView or DownloadUNDERCODE2025-04-09
WordPress≤ 1.6Stored XSSmediumView or DownloadUNDERCODE2025-04-09
Elasticsearch7.17.0 - 8.15.0DoS via recursionmoderateView or DownloadUNDERCODE2025-04-09
WordPress≤ 2.0Reflected XSSmediumView or DownloadUNDERCODE2025-04-09
Joomla Framework1.0.0-2.2.0, 3.0.0-3.4.0SQL InjectionmoderateView or DownloadUNDERCODE2025-04-09
wallabag<2.6.11CSRFmediumView or DownloadUNDERCODE2025-04-09
WordPress Plugins≤1.6Auth BypasscriticalView or DownloadUNDERCODE2025-04-09
Skrill Official≤1.0.65CSRFmediumView or DownloadUNDERCODE2025-04-09
Elasticsearch7.17.0-8.15.0Stack OverflowmoderateView or DownloadUNDERCODE2025-04-09
Tendermint-rs<= v0.40.2Validator spoofingcriticalView or DownloadUNDERCODE2025-04-09
DotNetNuke.Core<9.4.0SSRF BypassmoderateView or DownloadUNDERCODE2025-04-09
Koa<2.16.1, <3.0.0-alpha.5Open RedirectcriticalView or DownloadUNDERCODE2021-08-09
bep/imagemeta< v0.11.0Unbounded memory allocationmediumView or DownloadUNDERCODE2025-04-09
BentoML<1.0.8Insecure DeserializationcriticalView or DownloadUNDERCODE2025-04-09
`bep/imagemeta``<0.10.0``EXIF DoS`criticalView or DownloadUNDERCODE2025-04-09
MySQL8.0.40, 8.4.3, 9.1.0DoSmediumView or DownloadUNDERCODE2025-04-08
MySQL Server8.0.40, 8.4.3, 9.1.0InnoDB DoSmediumView or DownloadUNDERCODE2025-04-08
MySQL Server8.0.39, 8.4.2, 9.0.1DoS via Performance SchemamediumView or DownloadUNDERCODE2025-04-08
MySQL Server8.0.39, 8.4.2, 9.0.1DDL Locking IssuemediumView or DownloadUNDERCODE2025-04-08
MySQL<=8.0.40/8.4.3/9.1.0Parser DoSmediumView or DownloadUNDERCODE2025-04-08
Online Lawyer Management1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-08
MySQL Server8.0.39, 8.4.2, 9.0.1Optimizer DoSmediumView or DownloadUNDERCODE2025-04-08
MySQL<=9.1.0Privilege EscalationmediumView or DownloadUNDERCODE2025-04-08
MySQL Server8.0.40, 8.4.3, 9.1.0InnoDB Locking RacemediumView or DownloadUNDERCODE2025-04-08
MySQL Server8.0.40, 8.4.3, 9.1.0Privilege escalationlowView or DownloadUNDERCODE2025-04-08
MySQL Server<= 8.0.40, <= 8.4.3, <= 9.1.0Packaging flawmediumView or DownloadUNDERCODE2025-04-08
MySQL Server8.0.40, 8.4.3, 9.1.0 (and prior)InnoDB DoSmediumView or DownloadUNDERCODE2025-04-08
MySQL≤9.1.0Privilege EscalationmediumView or DownloadUNDERCODE2025-04-08
SeaCMSv13.3SQL InjectioncriticalView or DownloadUNDERCODE2025-04-08
MySQL≤ 9.1.0DoSmediumView or DownloadUNDERCODE2025-04-08
Product Management System1.0Stack-based buffer overflowcriticalView or DownloadUNDERCODE2025-04-08
LNbitsPre-1.12.0SSRF via LNURLcriticalView or DownloadUNDERCODE2025-04-06
iteaj iboot1.1.3Stored XSSmediumView or DownloadUNDERCODE2025-04-08
Consumer Comanda Mobile≤14.9.3.2/15.0.0.8Cleartext Credential TransmissionmediumView or DownloadUNDERCODE2025-04-08
Kentico Xperience< 13.0.178Arbitrary File UploadcriticalView or DownloadUNDERCODE2025-04-08
iTeaj iBoot IoT Gateway1.1.3Stored XSSmediumView or DownloadUNDERCODE2025-04-08
iBoot IoT Gateway1.1.3Improper Access ControlmediumView or DownloadUNDERCODE2025-04-08
Kenj_Frog financial system1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-08
Blood Bank Management System1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-08
Patient Record Management System1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-08
Projectworlds Online Doctor Booking1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-08
Patient Record Management1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-08
Code-Projects HMS1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-08
IKUN_Library1.0Improper Access ControlmediumView or DownloadUNDERCODE2025-04-08
SourceCodester Online Eyewear Shop1.0Improper Access ControlmediumView or DownloadUNDERCODE2025-04-08
WhatsApp (Windows)<2.2450.6Spoofing → RCEcriticalView or DownloadUNDERCODE2025-04-08
SourceCodester Online Eyewear Shop1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-08
SourceCodester Online Eyewear Shop1.0Stored XSSmediumView or DownloadUNDERCODE2025-04-08
Shopware<6.6.10.3, <6.5.8.17Broken ACLmoderateView or DownloadUNDERCODE2025-04-08
Linux KernelPre-5.15.123Race ConditioncriticalView or DownloadUNDERCODE2025-04-08
Shopware<6.6.10.3, <6.5.8.17Email EnumerationmediumView or DownloadUNDERCODE2025-04-08
Admin Panel<v2.5.1HTML InjectionmediumView or DownloadUNDERCODE2025-04-08
Google Chrome< 133.0.6943.53Use-after-freehighView or DownloadUNDERCODE2025-04-08
Google Chrome< 133.0.6943.53Use-After-FreehighView or DownloadUNDERCODE2025-04-08
WordPress<3.95.0Stored XSShighView or DownloadUNDERCODE2025-04-08
Online Exam Mastering System1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-03-17
Node.js asn1.js<1.0.4Integer encoding flawmediumView or DownloadUNDERCODE2022-03-15
WordPress≤1.1Stored XSScriticalView or DownloadUNDERCODE2025-04-07
Langflow<1.3.0Code InjectioncriticalView or DownloadUNDERCODE2025-04-07
Tokio1.44.0-1.44.1Race conditionlowView or DownloadUNDERCODE2025-04-07
TOTOLINK EX1800T≤9.1.0cu.2112_B20220316Stack overflowcriticalView or DownloadUNDERCODE2025-04-07
Real Estate Property Management1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-03-17
PythonAll (with pickle)RCE via timeitcriticalView or DownloadUNDERCODE2025-04-07
Apollo Router<1.61.2, <2.1.1DoS via fragment reusehighView or DownloadUNDERCODE2025-04-07
Google Chrome<133.0.6943.98Use-After-FreehighView or DownloadUNDERCODE2025-04-07
Flowise<1.3.8SQL InjectioncriticalView or DownloadUNDERCODE2025-04-07
Google Chrome< 133.0.6943.126Heap Buffer OverflowhighView or DownloadUNDERCODE2025-04-07
Python (NumPy/pickle)Affects picklescan < v0.3.0DNS exfiltration via picklecriticalView or DownloadUNDERCODE2025-04-07
Apollo Router<1.61.2, <2.1.1DoS via fragment expansioncriticalView or DownloadUNDERCODE2025-04-07
Apollo Router<1.61.2, <2.1.1Integer OverflowcriticalView or DownloadUNDERCODE2025-04-07
Node.js<3.3.3Prototype PollutionmoderateView or DownloadUNDERCODE2025-04-07
Google Chrome< 133.0.6943.126Use-After-FreemediumView or DownloadUNDERCODE2025-04-07
Apollo Gateway<2.10.1DoS via fragmentshighView or DownloadUNDERCODE2025-04-07
Apollo Compiler<1.27.0DoS via fragmentshighView or DownloadUNDERCODE2025-04-07
Apollo Gateway<2.10.1DoS via query planningcriticalView or DownloadUNDERCODE2025-04-07
Emlog Pro2.5.3Arbitrary File UploadcriticalView or DownloadUNDERCODE2025-04-07
Google Chrome (Android)< 133.0.6943.126Heap buffer overflowhighView or DownloadUNDERCODE2025-04-07
Node.js2.2.0Prototype PollutioncriticalView or DownloadUNDERCODE2023-01-15
Apollo Router<1.61.2, <2.1.1DoScriticalView or DownloadUNDERCODE2025-04-07
Pythonpickle moduleUnsafe deserializationhighView or DownloadUNDERCODE2025-04-07
macOSVentura <13.7.5, Sequoia <15.4, Sonoma <14.7.5Arbitrary file accesscriticalView or DownloadUNDERCODE2025-04-07
Nimrod0.8SQL InjectioncriticalView or DownloadUNDERCODE2025-04-07
PHPGurukul e-Diary1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-07
Apple OS stackPre-visionOS 2.4Out-of-bounds readcriticalView or DownloadUNDERCODE2025-04-07
Tenda RX316.03.13.11Stack overflowcriticalView or DownloadUNDERCODE2025-04-07
Online Restaurant Management System1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-08
Nimrod0.8Unrestricted uploadcriticalView or DownloadUNDERCODE2025-04-07
TinyWebServer≤1.0Buffer OverflowcriticalView or DownloadUNDERCODE2025-04-07
Tenda AC120615.03.06.23Buffer OverflowcriticalView or DownloadUNDERCODE2025-04-07
Apple OS EcosystemvisionOS <2.4, macOS <Ventura 13.7.5Memory CorruptioncriticalView or DownloadUNDERCODE2025-04-07
Apple OS stackvisionOS <2.4, macOS <Ventura 13.7.5, tvOS <18.4, iOS/iPadOS <17.7.6/18.4Out-of-bounds readcriticalView or DownloadUNDERCODE2025-04-07
macOSVentura/Sequoia/SonomaFile Permission BypasscriticalView or DownloadUNDERCODE2025-04-07
TinyWebServer≤1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-07
Online Restaurant Management1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-07
tarteaucitron.js<25fcf82CSS InjectionmoderateView or DownloadUNDERCODE2025-04-07
Jujutsu≤0.28.0SHA-1 collisioncriticalView or DownloadUNDERCODE2025-03-15
Graylog6.1.0-6.1.8Auth bypassmoderateView or DownloadUNDERCODE2025-04-07
tarteaucitron.js<2fa1e01URL scheme injectionmoderateView or DownloadUNDERCODE2025-04-07
Leantime≤ 3.2.1Stored XSScriticalView or DownloadUNDERCODE2025-03-28
ITSourcecode Simple ChatBox≤ 1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-07
Apple WebKitSafari <18.4, iOS/iPadOS <17.7.6/18.4, macOS <15.4Privacy BypasscriticalView or DownloadUNDERCODE2025-04-07
macOSVentura 13.7.5, Sequoia 15.4, Sonoma 14.7.5Data exposuremediumView or DownloadUNDERCODE2025-04-07
ShopXOv6.4.0SSRFcriticalView or DownloadUNDERCODE2025-04-07
OneNav1.1.0SSRFcriticalView or DownloadUNDERCODE2025-04-07
Apple OS SuitevisionOS <2.4, iOS <18.4, iPadOS <18.4, macOS <15.4Sensitive Data ExposurecriticalView or DownloadUNDERCODE2025-04-07
iOS/iPadOS<18.4, <17.7.6Authentication bypasscriticalView or DownloadUNDERCODE2025-04-07
Apple Safari< 18.4Use-After-FreecriticalView or DownloadUNDERCODE2025-04-07
HotelDruid≤3.0.7Weak Password PolicymediumView or DownloadUNDERCODE2025-04-07
maccms10v2025.1000.4047SSRFcriticalView or DownloadUNDERCODE2025-04-07
Apple OS SuitevisionOS <2.4, tvOS <18.4, iPadOS <17.7.6, iOS <18.4, macOS <15.4App EnumerationmediumView or DownloadUNDERCODE2025-04-07
Tenda FH12021.2.0.14(408)Improper access controlcriticalView or DownloadUNDERCODE2025-04-07
Apple OS (macOS/iOS/visionOS)Pre-Ventura 13.7.5, Pre-Sequoia 15.4Sandbox Escape via Path HandlingcriticalView or DownloadUNDERCODE2025-04-07
ShopXOv6.4.0SSRF/XSScriticalView or DownloadUNDERCODE2025-04-07
MacCMS10v2025.1000.4047SSRFcriticalView or DownloadUNDERCODE2025-04-07
Tenda FH12021.2.0.14(408)Improper Access ControlcriticalView or DownloadUNDERCODE2025-04-07
rust-opensslUse-After-FreemoderateView or DownloadUNDERCODE2025-04-05
React Draft WysiwygAll versionsXSS via EmbeddedlowView or DownloadUNDERCODE2025-04-04
Node.js0.0.0-0.4.2Prototype PollutionmoderateView or DownloadUNDERCODE2025-04-04
macOS<15.4Privacy BypassmediumView or DownloadUNDERCODE2025-04-04
Xcode< 16.3Information DisclosurecriticalView or DownloadUNDERCODE2025-04-04
macOS<15.4Device enumerationmediumView or DownloadUNDERCODE2025-04-04
macOS<15.4Library InjectioncriticalView or DownloadUNDERCODE2025-04-04
macOS<15.4FS modificationcriticalView or DownloadUNDERCODE2025-04-04
Apple WebKitSafari ≤18.4Memory CorruptioncriticalView or DownloadUNDERCODE2025-04-04
Node.js0.0.0 - 1.1.5Buffer OverflowhighView or DownloadUNDERCODE2025-04-04
macOS<15.4Privacy bypasscriticalView or DownloadUNDERCODE2025-04-04
macOS<15.4Password bypasscriticalView or DownloadUNDERCODE2025-04-04
macOS<15.4Data exposurecriticalView or DownloadUNDERCODE2025-04-04
macOS<15.4Memory corruptioncriticalView or DownloadUNDERCODE2025-04-04
macOSVentura 13.x, Sequoia 15.x, Sonoma 14.xOut-of-bounds readcriticalView or DownloadUNDERCODE2025-04-04
macOSVentura 13.7.5, Sequoia 15.4, Sonoma 14.7.5Privilege EscalationcriticalView or DownloadUNDERCODE2025-04-04
macOSVentura/Sequoia/SonomaBuffer OverflowcriticalView or DownloadUNDERCODE2025-04-04
Apple iOS/macOS< iPadOS 17.7.4Location bypassmediumView or DownloadUNDERCODE2025-04-04
Apple EcosystemvisionOS <2.4, macOS <13.7.5DoS via inputcriticalView or DownloadUNDERCODE2025-04-04
macOS<15.4Sandbox EscapecriticalView or DownloadUNDERCODE2025-04-04
macOSVentura <13.7.5FS modification bypasscriticalView or DownloadUNDERCODE2025-03-31
macOSVentura <13.7.5, Sequoia <15.4, Sonoma <14.7.5Kernel OOB WritecriticalView or DownloadUNDERCODE2025-04-04
iOS/iPadOS<18.4Lock screen bypasscriticalView or DownloadUNDERCODE2025-03-31
macOSVentura <13.7.5, Sequoia <15.4, Sonoma <14.7.5Privilege EscalationcriticalView or DownloadUNDERCODE2025-04-04
macOS/iPadOSVentura 13.7.5, Sonoma 14.7.5, Sequoia 15.4File access bypasscriticalView or DownloadUNDERCODE2025-04-04
Apple Safari/iOS/iPadOS/macOS<18.4Address bar spoofingmediumView or DownloadUNDERCODE2025-04-04
Apple OS StackVentura 13.7.5, iOS 18.4, Sequoia 15.4Sensitive Data ExposurecriticalView or DownloadUNDERCODE2025-04-04
Apple OS stackPre-Sonoma 14.7.5, pre-Sequoia 15.4Data container escapecriticalView or DownloadUNDERCODE2025-03-31
Apple OS stackvisionOS <2.4, iOS <18.4, macOS <Ventura 13.7.5Path traversal → data leakcriticalView or DownloadUNDERCODE2025-04-04
macOSVentura <13.7.5, Sequoia <15.4, Sonoma <14.7.5Data access bypasscriticalView or DownloadUNDERCODE2025-04-04
Apple OS<13.7.5/17.7.6/18.4Sandbox EscapecriticalView or DownloadUNDERCODE2025-03-31
Apple OS SuitevisionOS <2.4, macOS <13.7.5/14.7.5/15.4, iOS/iPadOS <18.4Symlink privilege bypasscriticalView or DownloadUNDERCODE2025-04-04
macOS<15.4Code-signing bypasscriticalView or DownloadUNDERCODE2025-04-04
Dreamer CMS4.1.3Stored XSSmediumView or DownloadUNDERCODE2025-04-04
macOSVentura <13.7.5, Sequoia <15.4, Sonoma <14.7.5Race ConditioncriticalView or DownloadUNDERCODE2025-04-04
macOS<15.4Symlink bypasscriticalView or DownloadUNDERCODE2025-03-31
Apple OSVentura 13.7.5, Sequoia 15.4Privilege escalationcriticalView or DownloadUNDERCODE2025-03-31
macOSSequoia <15.4, Sonoma <14.7.5Sandbox EscapecriticalView or DownloadUNDERCODE2025-03-31
Apple OS StackvisionOS <2.4, macOS <13.7.5Memory CorruptioncriticalView or DownloadUNDERCODE2025-04-04
BentoMLv1.4.2RCE via deserializationcriticalView or DownloadUNDERCODE2025-04-04
WordPress≤ 12.4.05Missing AuthorizationcriticalView or DownloadUNDERCODE2025-04-04
XWiki<8.6.5XXE InjectioncriticalView or DownloadUNDERCODE2020-05-07
MinIO< 0.0.0-20250403145552Incomplete signature validationhighView or DownloadUNDERCODE2025-04-04
Vite4.0.0-6.2.4Directory TraversalcriticalView or DownloadUNDERCODE2025-04-04
Concrete CMS<9.4.0RC2, <8.5.20XSS/CSRFmoderateView or DownloadUNDERCODE2025-04-04
pgAdmin 4<9.2Remote Code ExecutioncriticalView or DownloadUNDERCODE2025-04-04
pgAdmin<= 9.1XSScriticalView or DownloadUNDERCODE2025-04-04
API Platform< 2.7.8Security BypasscriticalView or DownloadUNDERCODE2025-04-04
LMDeploy<= 0.7.1Unsafe DeserializationmoderateView or DownloadUNDERCODE2025-04-04
GraphQL (API Platform)< 60747ccSecurity BypasscriticalView or DownloadUNDERCODE2025-04-04
generator-jhipster-entity-auditUnsafe ReflectioncriticalView or DownloadUNDERCODE2025-04-04
Miniflux< 2.2.7XSSmediumView or DownloadUNDERCODE2024-03-15
Sante PACS ServerNot specifiedPath TraversalcriticalView or DownloadUNDERCODE2025-04-03
Sante PACS ServerNot specifiedStack overflowcriticalView or DownloadUNDERCODE2025-04-03
Froxlor<2.2.6Email duplicationmediumView or DownloadUNDERCODE2025-04-04
Firefox iOS< 134URL SpoofingmediumView or DownloadUNDERCODE2025-04-03
Firefox for iOS< 134URL hostname spoofingmediumView or DownloadUNDERCODE2025-01-10
FS S3150-8T2F SwitchFirmware 220d_118101Stored XSSmediumView or DownloadUNDERCODE2025-04-03
D-Link DIR-823X240126, 240802Command InjectioncriticalView or DownloadUNDERCODE2025-04-03
Ollama<=0.3.14DoS via GGUFcriticalView or DownloadUNDERCODE2025-04-03
Sunshine Photo Cart≤ 3.4.10Object InjectioncriticalView or DownloadUNDERCODE2025-04-03
MODX CMS<3.1.0Stored XSS via SVGcriticalView or DownloadUNDERCODE2025-04-04
Inova Logic CM3.1.757.1Privilege EscalationcriticalView or DownloadUNDERCODE2025-04-03
Jira Data Center<4.1.69-dcStored XSSmediumView or DownloadUNDERCODE2025-04-03
Code-Projects Chat System1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-03
Code-Projects Chat1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-04-03
`alizeait/unflatto``<=1.0.2`Prototype PollutionhighView or DownloadUNDERCODE2025-04-01
Rancher< v2.8.14, < v2.9.8, < v2.10.4Privilege EscalationcriticalView or DownloadUNDERCODE2025-04-01
jooby-pac4j<2.17.0, 3.0.0-3.6.9RCE via deserializationcriticalView or DownloadUNDERCODE2025-04-01
ShopXOv6.4.0SSRF via Image UploadmoderateView or DownloadUNDERCODE2025-03-29
ShopXOv6.4.0SSRF/XSSmoderateView or DownloadUNDERCODE2025-04-01
AWS CDK<=2.187.0Secret leakagecriticalView or DownloadUNDERCODE2025-03-31
gifplayer< 0.3.7XSSmoderateView or DownloadUNDERCODE2025-03-31
AWS SAM CLI<= v1.133.0Symlink cache exposuremediumView or DownloadUNDERCODE2025-03-31
AWS SAM CLI<= v1.132.0Symlink escapecriticalView or DownloadUNDERCODE2025-04-01
Netty QUIC< 0.0.71.FinalHash DoSmoderateView or DownloadUNDERCODE2025-03-31
Adobe Illustrator≤29.2.1, ≤28.7.4NULL Pointer DereferencemediumView or DownloadUNDERCODE2025-03-11
Adobe Illustrator≤29.2.1, ≤28.7.4Buffer OverflowcriticalView or DownloadUNDERCODE2025-03-11
Adobe Illustrator≤29.2.1, ≤28.7.4Untrusted Search PathcriticalView or DownloadUNDERCODE2025-03-11
Apache HTTP Server2.4.49Path Traversal → RCEcriticalView or DownloadUNDERCODE2021-10-05
MobSFPre-commit ae34f7cSSRF via DNS RebindingcriticalView or DownloadUNDERCODE2025-03-31
Vite4.0.0-6.2.3FS deny bypassmediumView or DownloadUNDERCODE2025-03-31
Leantime≤3.2.1Stored XSSmoderateView or DownloadUNDERCODE2025-03-28
Node.js<=1.0.2Prototype PollutionhighView or DownloadUNDERCODE2025-03-31
Solon≤ 3.1.0Path TraversalmoderateView or DownloadUNDERCODE2025-03-31
Redoc<= 2.0.0Prototype PollutionhighView or DownloadUNDERCODE2025-03-31
Infinispan<= 15.0.5.FinalOOM via REST APImoderateView or DownloadUNDERCODE2025-03-31
depath/cool-pathv1.0.6/v1.1.2Prototype PollutionhighView or DownloadUNDERCODE2025-03-31
Uptime Kuma<1.23.0ReDoScriticalView or DownloadUNDERCODE2024-06-15
ConcreteCMS<= 9.3.9Stored XSSmoderateh2stylecolorblueView or DownloadUNDERCODE2025-03-31
Rust cratearray-init-cursorDouble-freelowView or DownloadUNDERCODE2025-03-31
Beego<2.0.3XSShighh2stylecolorblueView or DownloadUNDERCODE2023-03-15
Firefox for iOS< 136URL spoofing via redirectmediumView or DownloadUNDERCODE2025-03-28
Nethermind Juno< 0.12.5Integer OverflowhighView or DownloadUNDERCODE2025-03-29
DataEase<2.10.6Arbitrary File Read/DeserializationcriticalView or DownloadUNDERCODE2025-03-28
Wangmarketv4.10-v5.0CSRFcriticalView or DownloadUNDERCODE2025-03-28
Wangmarketv4.10-v5.0CSRFmediumView or DownloadUNDERCODE2025-03-28
TUF (tough)< 0.20.0Incorrect delegation handlingcriticalView or DownloadUNDERCODE2025-03-29
Vyper<0.4.1Iterator side-effectscriticalView or DownloadUNDERCODE2025-03-28
TUF Client<0.20.0Metadata RollbackcriticalView or DownloadUNDERCODE2025-03-29
PHPGurukul3.3SQL InjectioncriticalView or DownloadUNDERCODE2025-03-28
WordPress≤2.2.16Unauthorized user deletioncriticalView or DownloadUNDERCODE2025-03-28
Node.js<18.16.1, <20.3.1HTTP SmugglingcriticalView or DownloadUNDERCODE2023-06-22
Firefox, Thunderbird< 136Buffer OverflowcriticalView or DownloadUNDERCODE2025-03-28
WordPress≤0.9CSRFmediumView or DownloadUNDERCODE2025-03-28
Vyper<0.4.1DynArray BypasscriticalView or DownloadUNDERCODE2025-03-28
PHPGurukul3.3HTML InjectionmediumView or DownloadUNDERCODE2025-03-28
Vyper<0.4.1Precision ErrormediumView or DownloadUNDERCODE2025-03-28
Code-projects Online SchedulingV1.0Stored XSSmediumView or DownloadUNDERCODE2025-03-28
TUF Repository< 0.20.0Cyclical DelegationcriticalView or DownloadUNDERCODE2025-03-29
WordPress≤ 2.2.16SQL InjectioncriticalView or DownloadUNDERCODE2025-03-28
Firefox/Firefox ESR/Thunderbird122–136 / <128.8Out-of-bounds accesscriticalView or DownloadUNDERCODE2025-03-28
Node.js<1.16.4, 2.0.0-2.1.1, 3.0.0-3.0.6Path TraversalhighView or DownloadUNDERCODE2025-03-27
Stencil<2.3.0Zip SlipmediumView or DownloadUNDERCODE2023-01-15
PHPGurukul Land Record1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-03-28
SeaCMSv13.3RCEcriticalView or DownloadUNDERCODE2025-03-28
Seacms<=13.3SQL InjectioncriticalView or DownloadUNDERCODE2025-03-28
SeaCMS<=13.3SQL InjectioncriticalView or DownloadUNDERCODE2025-03-28
SeaCMSv13.3Remote Code ExecutioncriticalView or DownloadUNDERCODE2025-03-28
Seacms<13.3SQL InjectioncriticalView or DownloadUNDERCODE2025-03-28
Devolutions Server<=2024.3.12Auth bypasscriticalView or DownloadUNDERCODE2025-03-28
Nginx1.25.0-1.25.3HTTP SmugglingcriticalView or DownloadUNDERCODE2023-12-14
Devolutions Server≤ 2024.3.13SSH password exposuremediumView or DownloadUNDERCODE2025-03-28
Node.js12.x, 14.x, 16.xHTTP/2 RCEcriticalView or DownloadUNDERCODE2021-09-29
PublifyStored XSSmediumView or DownloadUNDERCODE2023-01-15
WordPress≤ 2.6.2Arbitrary File DownloadcriticalView or DownloadUNDERCODE2025-03-28
WordPress≤ 0.8.2Reflected XSSmediumView or DownloadUNDERCODE2025-03-28
WordPress≤ 3.1.8Reflected XSSmediumView or DownloadUNDERCODE2025-03-28
WordPress≤ 3.1.8LFIcriticalView or DownloadUNDERCODE2025-03-28
TUF (tough)< 0.20.0Metadata RollbackmediumView or DownloadUNDERCODE2025-03-28
TUF<0.20.0Metadata RollbackcriticalView or DownloadUNDERCODE2025-03-28
AimHub3.25.0DoS via APImediumView or DownloadUNDERCODE2025-03-28
Lunary-AI≤1.6.7Stored XSScriticalView or DownloadUNDERCODE2025-03-28
GitHub.com<1.0.1Path TraversalmoderateView or DownloadUNDERCODE2025-03-28
Apache HTTP Server2.4.49Path Traversal/RCEcriticalView or DownloadUNDERCODE2021-10-05
Cisco ISE3.2, 3.1API auth bypasscriticalh2stylecolorblueView or DownloadUNDERCODE2025-03-28
Cisco ISE3.2, 3.1Stored XSScriticalView or DownloadUNDERCODE2025-03-28
Ollama≤0.3.14Null DereferencecriticalView or DownloadUNDERCODE2025-03-28
WordPress≤ 2.1.7Privilege EscalationcriticalView or DownloadUNDERCODE2025-03-28
Dell Avamar19.4+Token ReusecriticalView or DownloadUNDERCODE2025-03-28
Cisco ISE3.1, 3.2Insecure DeserializationcriticalView or DownloadUNDERCODE2025-03-28
WordPress≤ 2.1.7PHP Object InjectioncriticalView or DownloadUNDERCODE2025-03-28
Node.js12.x - 16.xHTTP/2 RCEcriticalView or DownloadUNDERCODE2021-09-29
Synapse≤1.127.0DoS via malformed eventscriticalView or DownloadUNDERCODE2025-03-27
Pitchfork< 0.11.0HTTP Response SplittingcriticalView or DownloadUNDERCODE2025-03-27
Apache Kylin5.0.0 - 5.0.1SSRFlowView or DownloadUNDERCODE2025-03-27
Mesop<=0.14.0Class PollutioncriticalView or DownloadUNDERCODE2023-11-15
Vega/Vega-lite<5.32.0Prototype Pollution → XSScriticalView or DownloadUNDERCODE2025-03-27
Apache Kylin4.0.0 - 5.0.1Code InjectionlowView or DownloadUNDERCODE2025-03-27
Node.js12.x, 14.x, 16.xRCE via HTTP/2criticalView or DownloadUNDERCODE2021-09-29
MLflow<2.19.0Missing Password EnforcementcriticalView or DownloadUNDERCODE2025-03-27
Dell Chassis Management Controller< 2.40.200.202101130302 (FX2), < 3.41.200.202209300499 (VRTX)Stack-based Buffer OverflowcriticalView or DownloadUNDERCODE2025-03-27
Mattermost10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8MFA BypasscriticalView or DownloadUNDERCODE2025-03-27
Mattermost10.4.x <= 10.4.2Command InjectioncriticalView or DownloadUNDERCODE2025-03-27
Mattermost<=10.4.2, <=10.3.3, <=9.11.8Improper Access ControlmediumView or DownloadUNDERCODE2025-03-27
Mattermost9.11.x <= 9.11.8Privilege EscalationmediumView or DownloadUNDERCODE2025-03-27
OpenSlides<4.2.5Timing attackmediumView or DownloadUNDERCODE2025-03-27
xmedcon0.25.0Integer UnderflowmediumView or DownloadUNDERCODE2025-03-27
OpenSlides<4.2.5Stored XSScriticalView or DownloadUNDERCODE2025-03-27
Vega≤5.30.0Arbitrary JS ExecutioncriticalView or DownloadUNDERCODE2025-03-27
OpenSlides<4.2.5Directory TraversalcriticalView or DownloadUNDERCODE2025-03-27
Mattermost<=10.4.2, <=10.3.3MFA BypasscriticalView or DownloadUNDERCODE2025-03-27
WordPress≤ 3.2.1Unauthenticated feature disablemediumView or DownloadUNDERCODE2025-03-26
Westboy CicadasCMS1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-03-26
WordPress≤5.9.4.5PHP Object InjectionmediumView or DownloadUNDERCODE2025-03-26
WordPress≤5.9.4.7SQL InjectioncriticalView or DownloadUNDERCODE2025-03-26
WordPress≤ 5.9.4.4Missing AuthorizationmediumView or DownloadUNDERCODE2025-03-26
Django<5.3.3XSSlowView or DownloadUNDERCODE2025-03-26
xmas-elf<1.2.0OOB ReadmoderateView or DownloadUNDERCODE2025-03-26
Directus<= 10.11.3Information DisclosurecriticalView or DownloadUNDERCODE2024-06-15
OpenDaylight SFCSodium-SR4 and belowPrivilege EscalationcriticalView or DownloadUNDERCODE2025-03-26
WordPress≤ 2.8.3Stored XSSmediumView or DownloadUNDERCODE2025-03-26
Tenda W18Ev16.01.0.11Stack OverflowcriticalView or DownloadUNDERCODE2025-03-26
Snail-Job1.4.0RCE via DeserializationcriticalView or DownloadUNDERCODE2025-03-26
D-Link DAP-16201.03Stack overflowcriticalView or DownloadUNDERCODE2025-03-26
Westboy CicadasCMS1.0Stored XSSmediumView or DownloadUNDERCODE2025-03-26
Ollama<=0.3.14Resource AllocationhighView or DownloadUNDERCODE2025-03-24
Aimhubio3.25.0Denial of ServicehighView or DownloadUNDERCODE2025-03-22
Aim (aimhubio/aim)3.25.0Uncontrolled Resource ConsumptionhighView or DownloadUNDERCODE2025-03-22
MLflow2.17.0 - 2.20.1CSRF in SignupmoderateView or DownloadUNDERCODE2025-03-21
MLflow2.18Weak Password RequirementslowView or DownloadUNDERCODE2025-03-21
Mattermost<= 10.4.2, <= 10.3.3, <= 9.11.8Improper Access ControlmoderateView or DownloadUNDERCODE2025-03-21
go-httpbinAll versions prior to patchCross-Site Scripting (XSS)criticalView or DownloadUNDERCODE2025-03-21
PipeCDv0.49Privilege EscalationhighView or DownloadUNDERCODE2025-03-21
Go (Golang)Pre-patch versionsDoS via memory exhaustioncriticalView or DownloadUNDERCODE2025-03-21
Mattermost10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8Command Execution in Archived ChannelsmoderateView or DownloadUNDERCODE2025-03-21
Mattermost10.4.0 - 10.4.2, 10.3.0 - 10.3.3, 9.11.0 - 9.11.8, 10.5.0MFA BypasshighView or DownloadUNDERCODE2025-03-21
Mattermost10.4.0 - 10.4.2, 10.3.0 - 10.3.3, 9.11.0 - 9.11.8MFA BypassmoderateView or DownloadUNDERCODE2025-03-21
Mattermost10.4.0 - 10.4.2, 10.3.0 - 10.3.3, 9.11.0 - 9.11.8, 10.5.0Improper Access ControlmoderateView or DownloadUNDERCODE2025-03-21
Linux Kernelnilfs2 file systemUse-After-FreecriticalView or DownloadUNDERCODE2025-02-27
Linux KernelUp to 6.13.0-rc3Use-After-FreecriticalView or DownloadUNDERCODE2025-02-27
Parse Server<4.10.0Authentication BypasscriticalView or DownloadUNDERCODE2025-03-21
AWS CDK CLI>=2.172.0, <2.178.2Credential ExposurecriticalView or DownloadUNDERCODE2025-03-21
Kubernetes1.3.0 to 1.32.3Race ConditionlowView or DownloadUNDERCODE2025-03-21
Liferay Portal/DXP7.4.0 - 7.4.3.126, 2024.Q3.0 - 2024.Q2.12, 2024.Q1.1 - 2024.Q1.12, 2023.Q4.0 - 2023.Q4.10, 2023.Q3.1 - 2023.Q3.10Data ExposuremoderateView or DownloadUNDERCODE2025-03-21
DataEase< 2.10.6Arbitrary File Read/DeserializationcriticalView or DownloadUNDERCODE2025-03-13
DataEase< 2.10.6Authentication BypasscriticalView or DownloadUNDERCODE2025-03-13
Linux KernelPre-commit 68f83057b913Use-After-FreecriticalView or DownloadUNDERCODE2025-02-26
Linux KernelUp to 6.12.0-rc6Use-After-FreecriticalView or DownloadUNDERCODE2025-02-26
Linux KernelUp to 5.15.xUse-After-Free (UAF)criticalView or DownloadUNDERCODE2025-02-26
WordPress1.1.9 and earlierUnauthorized AccesscriticalView or DownloadUNDERCODE2025-03-14
WordPress1.6.11 and belowPrivilege EscalationcriticalView or DownloadUNDERCODE2025-03-14
Envoy Proxy<1.30.10, 1.31.0-1.31.5, 1.32.0-1.32.3, 1.33.0Denial of ServicecriticalView or DownloadUNDERCODE2025-03-21
Redlib< v0.36.0Decompression BombcriticalView or DownloadUNDERCODE2025-03-21
InvokeAI5.3.1 - 5.4.2Remote Code ExecutioncriticalView or DownloadUNDERCODE2025-03-21
LibcontainerPre-fix versionsCapabilities ElevationmoderateView or DownloadUNDERCODE2025-03-21
Next.js11.1.4 - 13.5.6, 14.0 - 14.2.24, 15.0 - 15.2.2Authorization BypasscriticalView or DownloadUNDERCODE2025-03-21
WordPress1.7.6 and earlierSQL InjectioncriticalView or DownloadUNDERCODE2025-03-14
Rembg2.0.57 and earlierCORS MisconfigurationcriticalView or DownloadUNDERCODE2025-03-03
Kedro0.19.8Remote Code ExecutioncriticalView or DownloadUNDERCODE2025-03-21
LocalAIv2.21.1Cross-Site Scripting (XSS)moderateView or DownloadUNDERCODE2025-03-21
ZenML0.66.0Unauthenticated DoShighView or DownloadUNDERCODE2025-03-21
vLLM0.6.0Deserialization RCEcriticalView or DownloadUNDERCODE2025-03-21
Composiov0.4.4SSRFmoderateView or DownloadUNDERCODE2025-03-21
vLLM0.6.0Remote Code ExecutioncriticalView or DownloadUNDERCODE2025-03-21
Quivrv0.0.298Unauthenticated DoShighView or DownloadUNDERCODE2025-03-21
MLflow2.15.1Path TraversalhighView or DownloadUNDERCODE2025-03-21
Composiov0.4.2SSRFmoderateView or DownloadUNDERCODE2025-03-21
LiteLLMv1.52.1API Key LeakagehighView or DownloadUNDERCODE2025-03-20
AimCommit bb76afePath TraversalcriticalView or DownloadUNDERCODE2025-03-20
LiteLLMmain-latestImproper AuthorizationhighView or DownloadUNDERCODE2025-03-20
AgentScopePrior to fixPath TraversalcriticalView or DownloadUNDERCODE2025-03-20
AgentScopev.0.0.4Path TraversalhighView or DownloadUNDERCODE2025-03-20
AgentScopeLatest commit 21161feStored XSSmoderateView or DownloadUNDERCODE2025-03-20
AgentScopev0.0.4Improper CORS ConfigurationhighView or DownloadUNDERCODE2025-03-20
LiteLLM<1.44.12API Key LeakagehighView or DownloadUNDERCODE2025-03-20
LiteLLMv1.44.5Denial of Service (DoS)highView or DownloadUNDERCODE2025-03-20
AgentScope0.0.4Directory TraversalhighView or DownloadUNDERCODE2025-03-20
Gradiogit commit 98cbcaeReDoS via crafted HTTP requesthighView or DownloadUNDERCODE2025-03-20
Gradiogit 98cbcaePath TraversalhighView or DownloadUNDERCODE2025-03-20
Prefect< 3.0.3CORS MisconfigurationhighView or DownloadUNDERCODE2025-03-20
Gradiogit 98cbcaeZip Bomb DoShighView or DownloadUNDERCODE2025-03-20
H2O3.46.0Denial of Service (DoS)highView or DownloadUNDERCODE2025-03-20
LiteLLM1.40.12Remote Code Execution (RCE)criticalView or DownloadUNDERCODE2025-03-20
H2O3.46.0.2Denial of Service (DoS)highView or DownloadUNDERCODE2025-03-20
H2O3.46.1Denial of Service (DoS)highView or DownloadUNDERCODE2025-03-20
H2O3.46.0Arbitrary File OverwritehighView or DownloadUNDERCODE2025-03-20
H2O3.46.0Arbitrary File EncryptionmoderateView or DownloadUNDERCODE2025-03-20
H2O3.46.0.1Denial of Service (DoS)highView or DownloadUNDERCODE2025-03-20
H2O3.46.0.1DoS, File WritehighView or DownloadUNDERCODE2025-03-20
Aim3.23.0Denial of Service (DoS)highView or DownloadUNDERCODE2025-03-20
H2O3.46.0.4Deserialization RCEcriticalView or DownloadUNDERCODE2025-03-20
Horovod<= v0.28.1Command InjectioncriticalView or DownloadUNDERCODE2025-03-20
Dask<=2024.8.2Command InjectioncriticalView or DownloadUNDERCODE2025-03-20
LiteLLMCommit 26c03c9Denial of Service (DoS)highView or DownloadUNDERCODE2025-03-20
kcp<0.26.3, <0.27.0Unauthorized Object ManipulationcriticalView or DownloadUNDERCODE2025-03-20
Coraza WAFv3Rule BypasscriticalView or DownloadUNDERCODE2025-03-20
Redisgo-redis (pre-patch versions)Connection TimeoutcriticalView or DownloadUNDERCODE2025-03-20
Apache Seata2.0.0 - 2.2.0Data AmplificationlowView or DownloadUNDERCODE2025-03-20
Spring Security5.7.0 - 6.4.3Password Length BypasshighView or DownloadUNDERCODE2025-03-20
Apache Seata2.0.0 to 2.2.0Deserialization of Untrusted DatalowView or DownloadUNDERCODE2025-03-20
Liferay Portal/DXP7.4.3.82-7.4.3.128, 2024.Q3.0, 2024.Q2.0-2024.Q2.13, 2024.Q1.1-2024.Q1.12, 2023.Q4.0-2023.Q4.10, 2023.Q3.1-2023.Q3.10XSSmoderateView or DownloadUNDERCODE2025-03-20
OpenShift ConsolePre-4.12.0Path TraversalmoderateView or DownloadUNDERCODE2025-03-20
WordPress2.1.13 and earlierUnauthorized Data AccesscriticalView or DownloadUNDERCODE2025-03-12
OpenShift Hivev1.0.0Uncontrolled Resource ConsumptionmoderateView or DownloadUNDERCODE2025-03-20
Jenkins< 1.0.31.v4aInformation DisclosuremoderateView or DownloadUNDERCODE2025-03-20
WordPress1.0.7 and earlierReflected XSScriticalView or DownloadUNDERCODE2025-03-03
WordPressUp to 2.1.8Stored XSScriticalView or DownloadUNDERCODE2025-02-17
WordPress1.3.8 and priorDOM-based XSScriticalView or DownloadUNDERCODE2025-01-09
JenkinsAnchorChain Plugin 1.0Stored XSShighView or DownloadUNDERCODE2025-03-19
Mattermost9.11.x <= 9.11.8Authorization BypassmoderateView or DownloadUNDERCODE2025-03-19
WordPress<= 1.3.6.5Local File InclusioncriticalView or DownloadUNDERCODE2025-03-11
WordPress<= 4.2.2CSRFcriticalView or DownloadUNDERCODE2025-03-06
WOLF1.0.8.5Path TraversalcriticalView or DownloadUNDERCODE2025-02-03
WordPress<= 4.1.25Stored XSScriticalView or DownloadUNDERCODE2025-01-18
GitHub Actionstj-actions/changed-files < 46Information DisclosurecriticalView or DownloadUNDERCODE2025-03-15
FortiOS, FortiProxy7.0.0 - 7.0.16, 7.2.0 - 7.2.12Authentication BypasscriticalView or DownloadUNDERCODE2025-02-11
RealMag777 BEAR1.1.4.4 and earlierStored XSScriticalView or DownloadUNDERCODE2025-02-17
WordPress<= 1.27.6Path TraversalcriticalView or DownloadUNDERCODE2025-02-06
WikiManager REST API5.4-rc-1 to 16.10.0Privilege EscalationcriticalView or DownloadUNDERCODE2025-03-19
XWiki>= 1.9M1, < 15.10.14Information DisclosurecriticalView or DownloadUNDERCODE2025-03-19
XWiki6.1-rc-1 to 15.10.13, 16.0.0-rc-1 to 16.4.5, 16.5.0-rc-1 to 16.10.0-rc-1Authorization BypasscriticalView or DownloadUNDERCODE2025-03-19
Nuxt.jsAll versionsCache PoisoningcriticalView or DownloadUNDERCODE2025-03-19
WordPress1.27.4 and earlierStored XSScriticalView or DownloadUNDERCODE2025-01-15
CodeBard Help Desk1.1.2 and earlierReflected XSScriticalView or DownloadUNDERCODE2025-01-15
OpenAPI3.0.0Zip Bomb ExploitcriticalView or DownloadUNDERCODE2025-03-19
Sylius<1.6.2, <1.7.2, <2.0.2Payment ManipulationcriticalView or DownloadUNDERCODE2025-03-19
Picklescan< 0.0.23ZIP Archive ManipulationmediumView or DownloadUNDERCODE2025-03-10
PyTorchPickleScan < 0.0.23Arbitrary Code ExecutionmediumView or DownloadUNDERCODE2025-03-10
GitHub Actionsreviewdog/action-setup@v1Secret ExposurecriticalView or DownloadUNDERCODE2025-03-19
vLLMPre-vllm-project/vllm14228Unsafe DeserializationcriticalView or DownloadUNDERCODE2025-03-19
Apache AirflowBefore 6.2.0SQL InjectionmoderateView or DownloadUNDERCODE2025-03-19
Node.jsfast-jwt (affected versions)JWT Issuer Claim ValidationcriticalView or DownloadUNDERCODE2025-03-19
ZipList RecipeUp to 3.1CSRFmediumView or DownloadUNDERCODE2025-03-11
ZTE GoldenDB6.1.03 - 6.1.03.04Privilege EscalationcriticalView or DownloadUNDERCODE2025-03-11
ZTE GoldenDB6.1.03 - 6.1.03.07Privilege EscalationcriticalView or DownloadUNDERCODE2025-03-11
CodeVibrant1.0.5 and earlierCSRFcriticalView or DownloadUNDERCODE2025-03-11
ZTE GoldenDB6.1.03 - 6.1.03.05Privilege EscalationcriticalView or DownloadUNDERCODE2025-03-11
WordPress1.0 and earlierCSRFmediumView or DownloadUNDERCODE2025-03-11
WordPress1.2.2 and earlierCSRFcriticalView or DownloadUNDERCODE2025-03-11
WordPress0.1.0 and earlierCSRF to Stored XSScriticalView or DownloadUNDERCODE2025-03-11
Login Logger1.2.1 and earlierCSRFmediumView or DownloadUNDERCODE2025-03-11
WordPressUp to 2.1CSRF to Stored XSScriticalView or DownloadUNDERCODE2025-03-11
ZTE GoldenDB6.1.03 - 6.1.03.04Input Validation BypasscriticalView or DownloadUNDERCODE2025-03-11
Delete Original Image0.4 and earlierCSRFmediumView or DownloadUNDERCODE2025-03-11
Rankchecker.io Integration1.0.9 and earlierCSRF with Stored XSScriticalView or DownloadUNDERCODE2025-03-11
Mojave InverterAll versionsSensitive Info DisclosurecriticalView or DownloadUNDERCODE2025-02-13
TYPO36.0.0 - 9.2.0XSSmoderateView or DownloadUNDERCODE2025-03-19
CosmWasmPrior to v2.2.0Capability BypassmoderateView or DownloadUNDERCODE2025-03-18
Stesvis Frontpage1.0.2 and earlierCSRFcriticalView or DownloadUNDERCODE2025-03-11
Wire< 5.2.0Uncontrolled RecursionmoderateView or DownloadUNDERCODE2025-03-18
jsPDF<3.0.1DoS via CPU exhaustioncriticalView or DownloadUNDERCODE2025-03-18
Contao4.0.0 - 4.13.53, 5.3.0 - 5.3.29, 5.4.0 - 5.5.5XSS via SVGcriticalView or DownloadUNDERCODE2025-03-18
amoCRM WebForm1.1 and earlierDOM-Based XSScriticalView or DownloadUNDERCODE2025-03-11
Apache HTTP Server2.4.49Path TraversalcriticalView or DownloadUNDERCODE2021-10-05
Apache Tomcat11.0.0-M1 to 11.0.2, 10.1.0-M1 to 10.1.34, 9.0.0.M1 to 9.0.98Path EquivalencecriticalView or DownloadUNDERCODE2025-03-10
Sylius<1.6.1, <1.7.1, <2.0.1Payment ManipulationcriticalView or DownloadUNDERCODE2025-03-17
containerd< 1.7.0, 1.6.0Integer OverflowmoderateView or DownloadUNDERCODE2025-03-17
OpenShift HiveMulticluster Engine (MCE), Advanced Cluster Management (ACM)Credential ExposurehighView or DownloadUNDERCODE2025-03-17
Expr<1.17.0Memory ExhaustioncriticalView or DownloadUNDERCODE2025-03-17
BuildKit< v0.21.3Information DisclosurecriticalView or DownloadUNDERCODE2025-03-17
Mattermost Desktop App<=5.10.0Code InjectionlowView or DownloadUNDERCODE2025-03-17
KubernetesBare Metal Operator (BMO)Secret LeakagecriticalView or DownloadUNDERCODE2025-03-17
Tenda AC9v1.0 V15.03.05.14_multiStack OverflowcriticalView or DownloadUNDERCODE2025-03-14
Tenda AC6v15.03.05.16Buffer OverflowcriticalView or DownloadUNDERCODE2025-03-14
Enituretechnology Small Package QuotesUp to 2.4.9Reflected XSScriticalView or DownloadUNDERCODE2025-03-03
Bee Layer Slider1.1 and earlierStored XSScriticalView or DownloadUNDERCODE2025-03-11
Ark Theme Core1.70.0 and earlierCode InjectioncriticalView or DownloadUNDERCODE2025-03-03
Tenda AC8V4V16.03.34.06Stack OverflowcriticalView or DownloadUNDERCODE2025-02-20
Node.js3.0.0Prototype PollutionhighView or DownloadUNDERCODE2025-03-16
GitHub Actionstj-actions/changed-files <= 45.0.7Information DisclosurehighView or DownloadUNDERCODE2025-03-15
Qiskit< 13Arbitrary Code ExecutioncriticalView or DownloadUNDERCODE2025-03-14
JS Html Sanitizer< 2.0.3XSS BypassmoderateView or DownloadUNDERCODE2025-03-14
feldman_vss<1.0.0Timing Side-ChannelcriticalView or DownloadUNDERCODE2025-03-14
Pythonfeldman_vss.pyFault InjectioncriticalView or DownloadUNDERCODE2025-03-14
Flowise1.8.2Path Traversal to RCEcriticalView or DownloadUNDERCODE2025-03-14
Azle0.27.0, 0.28.0, 0.29.0Infinite LoopcriticalView or DownloadUNDERCODE2025-03-14
KubernetesVersions using in-tree gitRepo volumeLocal repository accessmoderateView or DownloadUNDERCODE2025-03-14
xml-crypto<= 6.0.0Signature BypasscriticalView or DownloadUNDERCODE2025-03-14
Flowisev1.0.0Arbitrary File UploadcriticalView or DownloadUNDERCODE2025-03-13
Linux KernelUp to 5.15.90Use-After-FreecriticalView or DownloadUNDERCODE2025-02-26
Linux KernelPre-5.15.90Use-After-FreecriticalView or DownloadUNDERCODE2025-02-26
Kubernetes<1.29.13, 1.30.0-1.30.9, 1.31.0-1.31.5, 1.32.0-1.32.1Command InjectionmoderateView or DownloadUNDERCODE2025-03-13
Windows NTFSAll versions up to patchInformation DisclosurecriticalView or DownloadUNDERCODE2025-03-11
MODXPrior to 3.1.0Cross-Site Scripting (XSS)lowView or DownloadUNDERCODE2025-03-13
WindowsWin32 Kernel SubsystemUse-after-freecriticalView or DownloadUNDERCODE2025-03-11
Snowflake JDBC3.0.13 - 3.23.0Information DisclosuremediumView or DownloadUNDERCODE2025-03-13
Assimp5.4.3Heap-based Buffer OverflowcriticalView or DownloadUNDERCODE2025-03-10
HDF51.14.6Heap-based Buffer OverflowcriticalView or DownloadUNDERCODE2025-03-10
UnifiedTransform2.0Incorrect Access ControlcriticalView or DownloadUNDERCODE2025-03-10
Microsoft EdgeChromium-basedUI SpoofingcriticalView or DownloadUNDERCODE2025-03-07
Ed25519-Java0.3.0 and earlierSignature MalleabilitymoderateView or DownloadUNDERCODE2025-03-13
XPixelGroup BasicSR1.4.2 and priorCommand InjectionmoderateView or DownloadUNDERCODE2025-03-13
Cosmos SDKPre-v3.1.8Chain HaltcriticalView or DownloadUNDERCODE2025-01-01
Apache HTTP Server2.4.49, 2.4.50Path Traversal to RCEcriticalView or DownloadUNDERCODE2025-03-13
WordPressJavo Core <= 3.0.0.080Privilege EscalationcriticalView or DownloadUNDERCODE2025-03-08
WordPressUp to 16.26.10Information ExposurecriticalView or DownloadUNDERCODE2025-03-08
IBM Aspera Shares1.9.9 - 1.10.0 PL7XXE InjectioncriticalView or DownloadUNDERCODE2025-03-07
DenoAll versionsSession HijackingcriticalView or DownloadUNDERCODE2025-03-12
Golang (golang.org/x/net)Pre-2025 patchesProxy Bypass via IPv6 Zone IDsmoderateView or DownloadUNDERCODE2025-03-12
Apache NiFi1.13.0 - 2.2.0Information DisclosuremoderateView or DownloadUNDERCODE2025-03-12
Apache Felix< 1.2.2XSSmoderateView or DownloadUNDERCODE2025-03-12
Plenti<= 0.7.16Code InjectionmoderateView or DownloadUNDERCODE2025-03-12
Ruby SAML>= 1.13.0, < 1.18.0; < 1.12.4Authentication BypasscriticalView or DownloadUNDERCODE2025-03-12
SmallRye Fault Tolerance< 6.9.0Out-of-Memory (OOM)highView or DownloadUNDERCODE2025-03-12
Apache Camel4.9.0-4.10.2, 4.0.0-4.8.5, 3.10.0-3.22.4Header InjectioncriticalView or DownloadUNDERCODE2025-02-15
Ruby SAML< 1.12.4, >= 1.13.0, < 1.18.0Authentication BypasshighView or DownloadUNDERCODE2025-03-12
Omniauth-saml< 1.10.6, 2.0.0-2.1.2, 2.2.0-2.2.2Signature Wrapping AttackcriticalView or DownloadUNDERCODE2025-03-12
GraphQL-Ruby1.11.5-2.4.13Remote Code ExecutioncriticalView or DownloadUNDERCODE2025-03-12
IBC-Go>= v7Non-deterministic JSON UnmarshallingcriticalView or DownloadUNDERCODE2025-03-12
Cosmos SDK<= v0.47.16, <= 0.50.12Denial of ServicecriticalView or DownloadUNDERCODE2025-03-12
WordPress1.0.9 and earlierUnauthorized Data AccesscriticalView or DownloadUNDERCODE2025-03-07
WordPressUp to 16.26.10SQL InjectioncriticalView or DownloadUNDERCODE2025-03-08
Laravel< 3.4.17File Validation BypassmoderateView or DownloadUNDERCODE2025-03-12
Espressif ESP32All firmware versionsHidden HCI Command ExecutioncriticalView or DownloadUNDERCODE2025-03-08
Ruby2.10.0, 2.10.1Out-of-bounds ReadcriticalView or DownloadUNDERCODE2025-03-12
JoomlaJUX Real Estate 3.4.0Cross-Site Scripting (XSS)mediumView or DownloadUNDERCODE2025-03-09
WordPress<= 5.3.1Stored XSScriticalView or DownloadUNDERCODE2025-03-08
cheqd-node< v3.1.7Non-deterministic JSON UnmarshallingcriticalView or DownloadUNDERCODE2025-03-11
JoomlaJUX Real Estate 3.4.0SQL InjectioncriticalView or DownloadUNDERCODE2025-03-09
Rembg2.0.57 and earlierSSRFmoderateView or DownloadUNDERCODE2025-03-11
PimcorePre-11.0.0SQL InjectioncriticalView or DownloadUNDERCODE2025-03-11
Rembg2.0.57 and earlierCORS MisconfigurationhighView or DownloadUNDERCODE2025-03-11
Facebookincubator/below< 0.9.0Privilege EscalationhighView or DownloadUNDERCODE2025-03-11
WordPress<= 1.39.2Stored XSScriticalView or DownloadUNDERCODE2025-02-27
OpenXEUp to 1.12Cross-Site Scripting (XSS)mediumView or DownloadUNDERCODE2025-03-09
FTCMS2.1Cross-Site Scripting (XSS)mediumView or DownloadUNDERCODE2025-03-09
FTCMS2.1SQL InjectioncriticalView or DownloadUNDERCODE2025-03-09
XunRuiCMSUp to 4.6.3Cross-Site Scripting (XSS)mediumView or DownloadUNDERCODE2025-03-09
Customer Account PortalUnspecifiedHTML InjectionmediumView or DownloadUNDERCODE2025-03-11
Babel<7.26.10, <8.0.0-alpha.17Quadratic ComplexitycriticalView or DownloadUNDERCODE2025-03-11
FroxlorPre-2.0.10Account DuplicationmediumView or DownloadUNDERCODE2023-10-15
Keras< 3.9Arbitrary Code ExecutioncriticalView or DownloadUNDERCODE2025-03-11
GNU Binutils2.43Memory LeakcriticalView or DownloadUNDERCODE2025-02-10
CodeBard Help Desk1.1.2 and earlierStored XSScriticalView or DownloadUNDERCODE2025-01-31
SimpleSAMLphpv4Signature ConfusioncriticalView or DownloadUNDERCODE2025-03-11
ASP.NET Core9.0.2, 8.0.13, 2.3.0Elevation of PrivilegecriticalView or DownloadUNDERCODE2025-03-11
OpenHarmonyv5.0.2 and priorArbitrary Code ExecutioncriticalView or DownloadUNDERCODE2025-03-03
WordPress1.1.9 and earlierStored XSScriticalView or DownloadUNDERCODE2025-02-27
WordPress1.7.2 and earlierAuthentication BypasscriticalView or DownloadUNDERCODE2025-02-27
WordPress1.6.3 and earlierArbitrary File DeletioncriticalView or DownloadUNDERCODE2025-02-27
WordPress1.0.1 and earlierStored XSScriticalView or DownloadUNDERCODE2025-02-27
KerasAll versions prior to 3.0.0Arbitrary Code ExecutioncriticalView or DownloadUNDERCODE2025-03-11
MockoonLatest (mockoon-cli)Path Traversal & LFIcriticalView or DownloadUNDERCODE2025-03-11
WordPress<= 3.3.5Stored XSScriticalView or DownloadUNDERCODE2025-02-27
Umbraco CMS<= 10.8.8, >= 11.0.0-rc1, <= 13.7.0Unauthorized Content Access/DeletionmoderateView or DownloadUNDERCODE2025-03-11
Umbraco CMS14.3.2, 15.0.0-rc1 to 15.2.2Improper API Access ControlmoderateView or DownloadUNDERCODE2025-03-11
KubernetesRatify (pre-patch)Authentication BypasscriticalView or DownloadUNDERCODE2025-03-11
Rack<2.2.6Directory TraversalcriticalView or DownloadUNDERCODE2025-03-10
Apache Tomcat11.0.0-M1 to 11.0.2RCE/Info DisclosurehighView or DownloadUNDERCODE2025-03-10
Concrete CMS9.0.0 - 9.3.9Stored XSSmoderateView or DownloadUNDERCODE2025-03-10
Nomad<1.9.7, <1.8.11, <1.7.19Information ExposuremoderateView or DownloadUNDERCODE2025-03-10
Vela Server< 0.25.3, >= 0.26.0, < 0.26.2Insufficient Webhook Payload VerificationcriticalView or DownloadUNDERCODE2025-03-10
Keycloak>= 26.1.0, < 26.1.3; < 26.0.10Improper AuthorizationmoderateView or DownloadUNDERCODE2025-03-10
Keycloak>= 26.1.0, < 26.1.3; < 26.0.10Authentication BypassmoderateView or DownloadUNDERCODE2025-03-10
Apache Camel3.10.0-3.22.3, 4.2.0-4.8.4, 4.9.0-4.10.1Bypass/InjectioncriticalView or DownloadUNDERCODE2025-03-10
Laravel Framework11.9.0 to 11.35.1Reflected XSSmoderateView or DownloadUNDERCODE2025-03-10
PHP<5.25.2DoS via `explode()`lowView or DownloadUNDERCODE2025-03-10
Laravel Framework11.9.0 - 11.35.1Reflected XSSmoderateView or DownloadUNDERCODE2025-03-10
EkuiperPre-1.8.0Stored XSScriticalView or DownloadUNDERCODE2025-03-10
WordPress1.3.52 and earlierStored XSScriticalView or DownloadUNDERCODE2025-01-24
WordPress1.6.10 and earlierRemote File InclusioncriticalView or DownloadUNDERCODE2025-01-27
LocalS3All versionsXXE InjectioncriticalView or DownloadUNDERCODE2025-03-10
WordPressn/a - 2.7.1Missing AuthorizationcriticalView or DownloadUNDERCODE2025-01-24
PyTorchN/AArbitrary Code ExecutioncriticalView or DownloadUNDERCODE2025-03-10
TOTOLINK X189.1.0cu.2024_B20220329Stack-based buffer overflowcriticalView or DownloadUNDERCODE2025-02-16
TOTOLINK X189.1.0cu.2024_B20220329OS Command InjectioncriticalView or DownloadUNDERCODE2025-02-16
Apache Struts2.3.5 - 2.3.31, 2.5 - 2.5.10Remote Code ExecutioncriticalView or DownloadUNDERCODE2025-03-10
Oxidized Web< 0.15.0Unauthenticated RCEcriticalView or DownloadUNDERCODE2025-03-02
WeGIA< 3.2.16Denial of ServicecriticalView or DownloadUNDERCODE2025-03-03
GRUB2All versions with squash4 moduleHeap-based Buffer OverflowcriticalView or DownloadUNDERCODE2025-03-03
Protobuf CrateAffected versionsStack OverflowmoderateView or DownloadUNDERCODE2025-03-07
Node.js@intlify/message-resolver 9.1, @intlify/vue-i18n-core 9.2+Prototype PollutioncriticalView or DownloadUNDERCODE2025-03-07
XWiki Confluence Migrator Pro<= 1.11.6Information ExposurehighView or DownloadUNDERCODE2025-03-07
Ring (Cryptography Library)Pre-patch versionsInteger OverflowmediumView or DownloadUNDERCODE2025-03-07
XWiki Confluence Migrator Pro>= 1.0, < 1.2.0Remote Code ExecutioncriticalView or DownloadUNDERCODE2025-03-07
WinDbgAffected versionsRemote Code ExecutioncriticalView or DownloadUNDERCODE2025-03-06
WordPress<= 2.7.6Stored XSScriticalView or DownloadUNDERCODE2025-02-28
OpenTelemetry .NET1.10.0 to 1.11.1Denial of Service (DoS)criticalView or DownloadUNDERCODE2025-03-06
Jenkins< 2.492.2, >= 2.493, < 2.500Information DisclosuremoderateView or DownloadUNDERCODE2025-03-06
Ray<2.43.0Sensitive Info LoggingmoderateView or DownloadUNDERCODE2025-03-06
Envoy Gateway<1.2.7, <1.3.1Log InjectioncriticalView or DownloadUNDERCODE2025-03-06
Jenkins<= 2.499, <= 2.492.1CSRFmoderateView or DownloadUNDERCODE2025-03-06
WordPress<= 1.6.8.1Reflected XSScriticalView or DownloadUNDERCODE2025-02-28
Fleet< 4.64.2SAML Authentication BypasscriticalView or DownloadUNDERCODE2025-03-06
Jenkins< 2.492.2, >= 2.493, < 2.500Open RedirectmoderateView or DownloadUNDERCODE2025-03-06
NocoDBPre-2025 patchesReflected XSScriticalView or DownloadUNDERCODE2025-03-06
WordPress1.3.3 and earlierStored XSScriticalView or DownloadUNDERCODE2025-01-24
WordPress1.1.7 and belowStored XSScriticalView or DownloadUNDERCODE2025-02-28
Microsoft EdgeChromium-basedSecurity Feature BypasscriticalView or DownloadUNDERCODE2025-02-14
OpenZiti< 3.7.1SSRFcriticalView or DownloadUNDERCODE2025-03-03
OpenZiti< 3.7.1Unauthenticated File UploadcriticalView or DownloadUNDERCODE2025-03-03
ShishuoCMS1.1CSRFmediumView or DownloadUNDERCODE2025-03-03
Jinja2Pre-3.1.3Sandbox EscapecriticalView or DownloadUNDERCODE2024-01-15
ShishuoCMS1.1Cross-Site Scripting (XSS)mediumView or DownloadUNDERCODE2025-03-03
Eclipse OMR0.4.0 and earlierNULL Pointer DereferencemediumView or DownloadUNDERCODE2025-02-21
DGLPre-patch versionsRemote Code ExecutioncriticalView or DownloadUNDERCODE2025-03-05
Eclipse OMR0.2.0 to 0.4.0Buffer OverflowcriticalView or DownloadUNDERCODE2025-02-21
Laravel>= 12.0.0, < 12.1.1; < 11.44.1File Validation BypasscriticalView or DownloadUNDERCODE2025-03-05
WordPress<= 4.2.9Unauthorized AccesscriticalView or DownloadUNDERCODE2025-03-04
Redaxo5.18.2Arbitrary File UploadcriticalView or DownloadUNDERCODE2025-03-05
Adobe Commerce2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11Incorrect AuthorizationcriticalView or DownloadUNDERCODE2025-02-11
Linux KernelUp to 6.13.0-rc4Memory LeakcriticalView or DownloadUNDERCODE2025-02-26
OpenDJ9.2Denial-of-Service (DoS)criticalView or DownloadUNDERCODE2025-03-05
Adobe Commerce2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11Improper AuthorizationcriticalView or DownloadUNDERCODE2025-02-11
Linux KernelLoongArch-based systemsOut-of-Bounds (OoB) AccesscriticalView or DownloadUNDERCODE2025-02-26
Linux Kernel< 6.14.0-rc1Null Pointer DereferencecriticalView or DownloadUNDERCODE2025-02-26
Linux Kernelam65-cpsw Ethernet DriverMemory LeakcriticalView or DownloadUNDERCODE2025-02-26
Adobe Commerce2.4.4-p11 and earlierStored XSScriticalView or DownloadUNDERCODE2025-03-05
FlowiseAIv2.2.6Arbitrary File UploadhighView or DownloadUNDERCODE2025-03-05
VMware ESXi, WorkstationMultiple versions affectedTOCTOU leading to out-of-bounds writecriticalView or DownloadUNDERCODE2025-03-04
VMware ESXi, Workstation, FusionMultiple versions affectedInformation DisclosurecriticalView or DownloadUNDERCODE2025-03-04
i-Drive i11, i12Up to 20250227Improper Access ControlcriticalView or DownloadUNDERCODE2025-03-03
PHPGurukul1.0SQL InjectioncriticalView or DownloadUNDERCODE2025-03-03
NGINX Unit< 1.34.2Infinite LoopmediumView or DownloadUNDERCODE2025-03-03
RubyCGI gem < 0.4.2Denial of Service (DoS)criticalView or DownloadUNDERCODE2025-03-03
WordPress1.8.4.1 and earlierArbitrary File UploadcriticalView or DownloadUNDERCODE2025-03-04
ShishuoCMS1.1Unrestricted File UploadcriticalView or DownloadUNDERCODE2025-03-03
Matrix-Appservice-IRCUp to 3.0.3Arbitrary Command ExecutionCriticalView or DownloadUNDERCODE2025-03-04
OpenHarmonyv5.0.2 and priorUse-After-FreeCriticalView or DownloadUNDERCODE2025-03-04
mySCADA myPROVulnerable versions not specifiedCSRFMediumView or DownloadUNDERCODE2025-03-04
Dingtian DT-R0 SeriesAll versions prior to 2.5.1Authentication BypassCriticalView or DownloadUNDERCODE2025-03-04
mySCADA myPROVulnerable versionsOS Command InjectionCriticalView or DownloadUNDERCODE2025-03-04
mySCADA myPRO ManagerNot specifiedAuthentication BypassCriticalView or DownloadUNDERCODE2025-03-04
WordPress1.5.1 and earlierStored XSSCriticalView or DownloadUNDERCODE2025-03-04
CampCodes1.0Unrestricted File UploadCriticalView or DownloadUNDERCODE2025-03-04
Adobe Commerce2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11Incorrect AuthorizationCriticalView or DownloadUNDERCODE2025-03-04
Pinecone SimulatorUp to commit matrix-org/pinecone@ea4c337Stored XSSModerateView or DownloadUNDERCODE2025-03-04
ZITADEL<2.71.0IDORCriticalView or DownloadUNDERCODE2025-03-04
macOSVentura 13.7.3, Sequoia 15.3, Sonoma 14.7.3Code-Signing BypassCriticalView or DownloadUNDERCODE2025-03-04
macOSVentura 13.7.3, Sequoia 15.3, Sonoma 14.7.3Code-Signing BypassCriticalView or DownloadUNDERCODE2025-03-04
macOSSequoia (< 15.3)Sandbox EscapeCriticalView or DownloadUNDERCODE2025-03-04
GNU BinutilsUp to 2.43Stack-based Buffer OverflowMediumView or DownloadUNDERCODE2025-03-04
macOSVentura 13.7.3, Sequoia 15.3, Sonoma 14.7.3File ParsingCriticalView or DownloadUNDERCODE2025-03-04
Apache Struts2.3.5 to 2.3.31, 2.5 to 2.5.10Remote Code ExecutionCriticalView or DownloadUNDERCODE2025-03-04
Rack<2.2.4Log InjectionMediumView or DownloadUNDERCODE2025-03-04
GLPI<10.0.18Reflected XSSCriticalView or DownloadUNDERCODE2025-03-04
macOSVentura 13.7.3, Sequoia 15.3, Sonoma 14.7.3File ParsingCriticalView or DownloadUNDERCODE2025-03-04
Apple visionOS, Safari, iOS, iPadOS, macOS, watchOS, tvOSvisionOS < 2.3, Safari < 18.3, iOS < 18.3, iPadOS < 18.3, macOS < 15.3, watchOS < 11.3, tvOS < 18.3Denial-of-ServiceCriticalView or DownloadUNDERCODE2025-03-04
macOSVentura 13.7.3, Sequoia 15.3, Sonoma 14.7.3Information LeakCriticalView or DownloadUNDERCODE2025-03-04
macOSVentura 13.7.3, Sequoia 15.3, Sonoma 14.7.3Memory CorruptionCriticalView or DownloadUNDERCODE2025-03-04
Apple DevicesiPadOS 17.7.4, macOS Ventura 13.7.3, iOS 18.3Out-of-Bounds ReadCriticalView or DownloadUNDERCODE2025-03-04
Q-Free MaxTime<= 2.11.0Missing AuthorizationMediumView or DownloadUNDERCODE2025-03-03
tsupv8.3.4DOM ClobberingLowView or DownloadUNDERCODE2025-03-03
Q-Free MaxTime<= 2.11.0Missing AuthorizationCriticalView or DownloadUNDERCODE2025-03-03
Q-Free MaxTime<= 2.11.0Missing AuthorizationCriticalView or DownloadUNDERCODE2025-03-03
Q-Free MaxTime<= 2.11.0Missing AuthorizationCriticalView or DownloadUNDERCODE2025-03-03
Q-Free MaxTime<= 2.11.0Missing AuthorizationCriticalView or DownloadUNDERCODE2025-03-03
Picklescan< 0.0.22RCE BypassModerateView or DownloadUNDERCODE2025-03-03
Q-Free MaxTime<= 2.11.0Missing AuthorizationCriticalView or DownloadUNDERCODE2025-03-03
WordPressUp to 4.7.6Stored XSSCriticalView or DownloadUNDERCODE2025-03-03
CodeCheckerUp to 6.24.5Open RedirectModerateView or DownloadUNDERCODE2025-03-03
OPC UA .NET Standard Stack< 1.5.374.158Authentication BypassModerateView or DownloadUNDERCODE2025-03-03
MinIOPrior to fix in commit 91e1487Authentication BypassCriticalView or DownloadUNDERCODE2025-03-03
OPC UA .NET Standard Stack< 1.5.374.158Authentication BypassModerateView or DownloadUNDERCODE2025-03-03
Ruby URI Gem< 0.11.3, 0.12.0-0.12.3, 0.13.0-0.13.1, 1.0.0-1.0.2Userinfo LeakageHighView or DownloadUNDERCODE2025-03-03
SeaJS2.2.3Cross-site Scripting (XSS)LowView or DownloadUNDERCODE2025-03-03
Apache Ranger< 2.6.0Improper NeutralizationLowView or DownloadUNDERCODE2025-03-03
Mavo0.3.2DOM ClobberingModerateView or DownloadUNDERCODE2025-03-03
Ruby CGI Gem<= 0.3.5, 0.3.6, 0.4.0, 0.4.1Denial of Service (DoS)HighView or DownloadUNDERCODE2025-03-03
Ruby CGI Gem<= 0.3.5, 0.3.6, 0.4.0, 0.4.1Denial of Service (DoS)HighView or DownloadUNDERCODE2025-03-03
Stage.js0.8.10 and earlierDOM Clobbering leading to XSSModerateView or DownloadUNDERCODE2025-03-03
ASCON Cryptographic LibraryPre-patch versionsIncorrect Tag VerificationCriticalView or DownloadUNDERCODE2025-03-03
Oxidized Web< 0.15.0Unauthenticated RCECriticalView or DownloadUNDERCODE2025-03-03
Apache StreamPipes< 0.97.0Improper Privilege ManagementModerateView or DownloadUNDERCODE2025-03-03
Ruby CGI Gem<= 0.3.5, 0.3.6, 0.4.0, 0.4.1Denial of Service (DoS)HighView or DownloadUNDERCODE2025-03-03
PyTorchAll versionsArbitrary Code ExecutionCriticalView or DownloadUNDERCODE2025-01-01
PythonAll versions using pickleUnsafe DeserializationCriticalView or DownloadUNDERCODE2025-03-03
ManifestAll versionsWeak password hashingCriticalView or DownloadUNDERCODE2025-03-03
WSO2MultipleIncorrect AuthorizationModerateView or DownloadUNDERCODE2025-03-03
CampCodes1.0Cross-Site Scripting (XSS)MediumView or DownloadUNDERCODE2025-03-03
WordPress<= 1.7.1006CSRFCriticalView or DownloadUNDERCODE2025-03-03
Code-Projects Chat System1.0SQL InjectionCriticalView or DownloadUNDERCODE2025-03-03
GNU Binutils2.43/2.44Memory CorruptionCriticalView or DownloadUNDERCODE2025-03-03
SourceCodester Contact Manager1.0SQL InjectionCriticalView or DownloadUNDERCODE2025-03-03
GNU Binutils2.43Memory CorruptionCriticalView or DownloadUNDERCODE2025-03-03
SourceCodester Employee Management System1.0Default Credentials ExploitCriticalView or DownloadUNDERCODE2025-03-03
CampCodes School Management Software1.0Cross-Site Scripting (XSS)MediumView or DownloadUNDERCODE2025-03-03
Flask-AppBuilder<= 4.5.3User EnumerationLowView or DownloadUNDERCODE2025-03-03
Adobe InDesignID20.0, ID19.5.1 and earlierInteger UnderflowCriticalView or DownloadUNDERCODE2025-03-03
Adobe InCopy20.0, 19.5.1, and earlierInteger UnderflowCriticalView or DownloadUNDERCODE2025-03-03
Apache HTTP Server2.4.49Path TraversalCriticalView or DownloadUNDERCODE2021-10-05
Adobe InDesignID20.0, ID19.5.1Heap-based Buffer OverflowCriticalView or DownloadUNDERCODE2025-03-03
Rancher
v2.8.0 - v2.10.2
Authentication Bypass
Critical
View or DownloadUNDERCODE2025-03-03
Moodle4.5.0-betaIDORView or DownloadUNDERCODE2025-02-24
Button Block1.1.5Missing AuthorizationCriticalView or DownloadUNDERCODE2025-02-25
Moodle4.5.0-betaPermission BypassModerateView or DownloadUNDERCODE2025-02-24
tarteaucitronjs<1.17.0XSSLowView or DownloadUNDERCODE2025-02-24
Mattermost<10.4.2Arbitrary File ReadCriticalView or DownloadUNDERCODE2025-02-24
WordPress2.36Information ExposureMediumView or DownloadUNDERCODE2025-02-24
Real Estate Property Management System1.0SQL InjectionCriticalView or DownloadUNDERCODE2025-02-24
WordPress3.4.0Stored XSSCriticalView or DownloadUNDERCODE2025-02-24
WordPress8.3.0Unauthorized Settings ChangeCriticalView or DownloadUNDERCODE2025-02-24
Linux KernelOpen vSwitchInfinite LoopCriticalView or DownloadUNDERCODE2025-02-21
Codezips Gym Management System1.0SQL InjectionCriticalView or DownloadUNDERCODE2025-02-20
WordPress2.11.9XSSCriticalView or DownloadUNDERCODE2025-02-20
Progress® Telerik® Report ServerPrior to 11.0.25.211Information DisclosureMediumView or DownloadUNDERCODE2025-02-20
XWiki15.10.11Remote Code ExecutionCriticalView or DownloadUNDERCODE2025-02-20
Namada-apps1.1.0Excessive ComputationCriticalView or DownloadUNDERCODE2025-02-20
Namada-apps1.1.0Integer overflowCriticalView or DownloadUNDERCODE2025-02-20
Craft4, 5RCEHighView or DownloadUNDERCODE2025-02-20
Sliver1.5.42SSRFCriticalView or DownloadUNDERCODE2025-02-19
Sante PACS Server-Memory CorruptionCriticalView or DownloadUNDERCODE2025-02-19
MinttyN/AHeap-based Buffer OverflowCriticalView or DownloadUNDERCODE2025-02-18
LogsignUnified SecOps PlatformAuthentication BypassCriticalView or DownloadUNDERCODE2025-02-18
cie-aspnetcoreN/AAuthentication BypassCriticalView or DownloadUNDERCODE2025-02-18
spid-aspnetcoreN/ASAML Authentication BypassView or DownloadUNDERCODE2025-02-18
cie-aspnetcoreN/ASignature ValidationCriticalView or DownloadUNDERCODE2025-02-18
spid-aspnetcoreN/ASignature ValidationCriticalView or DownloadUNDERCODE2025-02-18
SonicWallSSLVPNImproper AuthenticationCriticalView or DownloadUNDERCODE2025-02-18
TP-Link TL-WR841ND V11V11Buffer OverflowCriticalView or DownloadUNDERCODE2025-02-18
Node.jsN/AReDoSCriticalView or DownloadUNDERCODE2025-02-14
npm@octokit/plugin-paginate-restReDoSView or DownloadUNDERCODE2025-02-14
npm@octokit/endpointReDoSCriticalView or DownloadUNDERCODE2025-02-14
@octokit/request-errorN/AReDoSCriticalView or DownloadUNDERCODE2025-02-14
DOMPurify<3.2.4XSSModerateView or DownloadUNDERCODE2025-02-14
Fyrox0.28.1Memory exposureLowView or DownloadUNDERCODE2025-02-14
GitHubv2.67.0Incorrect exit statusCriticalView or DownloadUNDERCODE2025-02-14
Label Studio<1.16.0Path TraversalCriticalView or DownloadUNDERCODE2025-02-14
Label StudioN/AXSSCriticalView or DownloadUNDERCODE2025-02-14
WeGIA3.2.6Stored XSSMediumView or DownloadUNDERCODE2025-02-13
WeGIA3.2.6XSSMediumView or DownloadUNDERCODE2025-02-13
WeGIA3.2.6XSSView or DownloadUNDERCODE2025-02-13
WeGIA3.2.10Open RedirectMediumView or DownloadUNDERCODE2025-02-13
WeGIA3.2.12SQL InjectionCriticalView or DownloadUNDERCODE2025-02-13
WeGIA3.2.12SQL InjectionCriticalView or DownloadUNDERCODE2025-02-13
WeGIA3.2.12SQL InjectionCriticalView or DownloadUNDERCODE2025-02-13
WeGIA3.2.12SQL InjectionView or DownloadUNDERCODE2025-02-13
WeGIA3.2.12SQL InjectionView or DownloadUNDERCODE2025-02-13
WeGIA3.2.6XSSMediumView or DownloadUNDERCODE2025-02-13
WeGIA3.2.6Stored XSSMediumView or DownloadUNDERCODE2025-02-13
WeGIA3.2.7XSSMediumView or DownloadUNDERCODE2025-02-13
HypercubeUnpatchedRemote Code ExecutionView or DownloadUNDERCODE2025-02-12
PDF-XChange EditorN/AOut-Of-Bounds ReadCriticalView or DownloadUNDERCODE2025-02-12
PDF-XChange EditorN/AHeap-based Buffer OverflowCriticalView or DownloadUNDERCODE2025-02-12
PDF-XChange Editor-Out-Of-Bounds ReadCriticalView or DownloadUNDERCODE2025-02-12
PDF-XChange Editor-Out-Of-Bounds ReadCriticalView or DownloadUNDERCODE2025-02-12
Trimble Cityworks<15.8.9, <23.10DeserializationCriticalView or DownloadUNDERCODE2025-02-12
PDF-XChange EditorN/AUse-After-FreeCriticalView or DownloadUNDERCODE2025-02-12
npmparse-durationReDoSCriticalView or DownloadUNDERCODE2025-02-12
EllipticN/APrivate Key ExtractionCriticalView or DownloadUNDERCODE2025-02-12
Koa2.15.4ReDoSCriticalView or DownloadUNDERCODE2025-02-12
WindowsStoragePrivilege ElevationCriticalView or DownloadUNDERCODE2025-02-12
Magento2.4.7-beta1Improper AuthorizationCriticalView or DownloadUNDERCODE2025-02-12
iOS18.3.1AuthorizationCriticalView or DownloadUNDERCODE2025-02-12
Mitel SIP PhonesR6.4.0.HF1Argument InjectionCriticalView or DownloadUNDERCODE2025-02-12
Samsung Android12.0, 13.0, 14.0UnspecifiedCriticalView or DownloadUNDERCODE2025-02-12
GeoNetwork4.4.0-4.4.5, <4.2.10Information DisclosureModerateView or DownloadUNDERCODE2025-02-11
Microsoft EdgeChromium-basedRemote Code ExecutionHighView or DownloadUNDERCODE2025-02-11
Microsoft EdgeChromium-basedRemote Code ExecutionMediumView or DownloadUNDERCODE2025-02-11
Microsoft EdgeChromium-basedRemote Code ExecutionMediumView or DownloadUNDERCODE2025-02-11
Microsoft EdgeChromium-basedSpoofingMediumView or DownloadUNDERCODE2025-02-11
Microsoft EdgeChromium-basedSpoofingMediumView or DownloadUNDERCODE2025-02-11
pgAgent<4.2.3Directory TraversalMediumView or DownloadUNDERCODE2025-02-11
WooCommerce4.7.1Stored XSSCriticalView or DownloadUNDERCODE2025-02-11
WooCommerce3.8.7Missing AuthorizationCriticalView or DownloadUNDERCODE2025-02-11
WordPress1.8.17.0XSSCriticalView or DownloadUNDERCODE2025-02-11
WP Mailster1.8.15.0XSSCriticalView or DownloadUNDERCODE2025-02-11
WordPress3.3.4Stored XSSCriticalView or DownloadUNDERCODE2025-02-11
AshAuthentication4.4.9Token ReuseView or DownloadUNDERCODE2025-02-11
WindowsunknownElevation of PrivilegeView or DownloadUNDERCODE2025-02-11
WindowsMultiplePrivilege EscalationHighView or DownloadUNDERCODE2025-02-11
Zyxel VMG4325-B10A1.00(AAFR.4)C0_20170615Command InjectionView or DownloadUNDERCODE2025-02-11
Apache CXF<3.5.10, <3.6.5, <4.0.6Denial of ServiceMediumView or DownloadUNDERCODE2025-02-11
LinuxKernelRace ConditionCriticalView or DownloadUNDERCODE2025-02-11
Linux Kernelgpio-xilinx driverSpinlock issueCriticalView or DownloadUNDERCODE2025-02-11
Photoshop25.12, 26.1Uncontrolled Search PathHighView or DownloadUNDERCODE2025-02-11
grcov-Out of Bounds WriteModerateView or DownloadUNDERCODE2025-02-10
NettyN/ADenial of ServiceView or DownloadUNDERCODE2025-02-10
Hickory DNSN/ADNSSEC ValidationView or DownloadUNDERCODE2025-02-10
Net-IMAP<0.4.19, <0.5.6Memory ExhaustionCriticalView or DownloadUNDERCODE2025-02-10
esbuild-CORS MisconfigurationCriticalView or DownloadUNDERCODE2025-02-10
SourceCodester1.0SQL InjectionCriticalView or DownloadUNDERCODE2025-02-10
SourceCodester1.0Improper Access ControlsCriticalView or DownloadUNDERCODE2025-02-10
SourceCodester1.0XSSMediumView or DownloadUNDERCODE2025-02-10
Dell Networking SwitchesEnterprise SONiC OSInformation ExposureHighView or DownloadUNDERCODE2025-02-07
Dell PowerProtect DDDDOS 8.3.0.0CryptographicCriticalView or DownloadUNDERCODE2025-02-07
xml2rfc<= 3.26.0XXE InjectionView or DownloadUNDERCODE2025-02-07
WindowsSecure Kernel ModeElevation of PrivilegeHighView or DownloadUNDERCODE2025-02-07
Microsoft EdgeChromium-basedUI MisrepresentationMediumView or DownloadUNDERCODE2025-02-07
@rpldy/uploader1.8.1Prototype PollutionHighView or DownloadUNDERCODE2025-02-06
Firefox< 135Memory CorruptionCriticalView or DownloadUNDERCODE2025-02-06
Thunderbird< 128.7Code ExecutionMediumView or DownloadUNDERCODE2025-02-06
Firefox< 135Memory CorruptionCriticalView or DownloadUNDERCODE2025-02-06
Firefox<135Certificate ValidationCriticalView or DownloadUNDERCODE2025-02-06
Firefox<135Use-After-FreeCriticalView or DownloadUNDERCODE2025-02-06
Firefox< 135, < 115.20, < 128.7Use-After-FreeCriticalView or DownloadUNDERCODE2025-02-06
Thunderbird< 128.7, < 135Incorrect sender addressMediumView or DownloadUNDERCODE2025-02-06
WhoDBN/AParameter InjectionView or DownloadUNDERCODE2025-02-06
WhoDBN/APath TraversalCriticalView or DownloadUNDERCODE2025-02-06
MDC (Nuxt-Modules)LatestXSSCriticalView or DownloadUNDERCODE2025-02-06
rtmpdumpabandonedmultiplecriticalView or DownloadUNDERCODE2025-02-06
7-ZipN/AMotW BypassView or DownloadUNDERCODE2025-02-06
Microsoft OutlookMultipleRemote Code ExecutionCriticalView or DownloadUNDERCODE2025-02-06
PlentiV8GO (V8 11.1.278)Remote Code ExecutionCriticalView or DownloadUNDERCODE2023-01-25
MobSF< 4.3.1DoSView or DownloadUNDERCODE2025-02-05
Contrastv1.4.1Seed verificationCriticalView or DownloadUNDERCODE2025-02-05
.NET and Visual StudioN/ARemote Code ExecutionHighView or DownloadUNDERCODE2025-02-05
MobSF< 4.3.1Stored XSSView or DownloadUNDERCODE2025-02-05
Microsoft Power Automate-Remote Code ExecutionHighView or DownloadUNDERCODE2025-02-05
CKAN2.10.7, 2.11.2Arbitrary File UploadView or DownloadUNDERCODE2025-02-05
GeoTools31.1, 30.3, 30.2, 29.2, 28.2, 27.5, 27.4, 26.7, 26.4, 25.2, 24.0RCEView or DownloadUNDERCODE2025-02-05
Marblerunv1.7.0ImpersonationView or DownloadUNDERCODE2025-02-04
WordPress2.0.4Stored XSSCriticalView or DownloadUNDERCODE2025-02-04
wasmvm1.5.8, 2.0.6, 2.1.5, 2.2.2Block production slowdownView or DownloadUNDERCODE2025-02-04
PRTG Network Monitor<18.2.40.1683Local File InclusionCriticalView or DownloadUNDERCODE2025-02-04
LinuxKernelNull-ptr-derefCriticalView or DownloadUNDERCODE2025-02-03
Linux Kernel32-bitTruncation ErrorCriticalView or DownloadUNDERCODE2025-02-03
SecMem-Out of Bounds WriteCriticalView or DownloadUNDERCODE2025-02-03
Modem-Out-of-bounds writeCriticalView or DownloadUNDERCODE2025-02-03
WLAN AP DriverN/AOut-of-Bounds WriteCriticalView or DownloadUNDERCODE2025-02-03
Network Hardware-Denial of ServiceCriticalView or DownloadUNDERCODE2025-02-03
TShockLatestBan BypassCriticalView or DownloadUNDERCODE2025-02-03
CometBFTv0.38.16, v1.0.0Blocksync DisruptionMediumView or DownloadUNDERCODE2025-02-03
WordPress3.0.1SQL InjectionCriticalView or DownloadUNDERCODE2025-01-31
WordPress2.7.2.1Stored XSSCriticalView or DownloadUNDERCODE2025-01-31
Wildfly27.0.1.FinalRBAC bypassView or DownloadUNDERCODE2025-01-31
iPadOS17.7.4, 2.3, 18.3, Sequoia 15.3, 11.3FingerprintingView or DownloadUNDERCODE2025-01-31
JetBrains YouTrack<2024.3.55417Token ExposureCriticalView or DownloadUNDERCODE2025-01-30
JetBrains TeamCity<2024.12.1Unauthorized decryptionCriticalView or DownloadUNDERCODE2025-01-30
macOS, iOS, iPadOS15.3, 18.3PrivacyMediumView or DownloadUNDERCODE2025-01-30
macOSSequoia 15.3, Sonoma 14.7.3File ParsingCriticalView or DownloadUNDERCODE2025-01-30
iOS18.3Symlink HandlingCriticalView or DownloadUNDERCODE2025-01-30
ApplemacOS Sequoia 15.3, tvOS 18.3, watchOS 11.3, iOS 18.3, iPadOS 18.3Privilege EscalationCriticalView or DownloadUNDERCODE2025-01-30
macOSVentura 13.7.3, Sequoia 15.3, Sonoma 14.7.3Race conditionCriticalView or DownloadUNDERCODE2025-01-30
AppleMultipleMemory HandlingCriticalView or DownloadUNDERCODE2025-01-30
macOSSequoia 15.3Data accessCriticalView or DownloadUNDERCODE2025-01-30
macOSSequoia 15.3Buffer OverflowCriticalView or DownloadUNDERCODE2025-01-30
macOSSequoia 15.3Memory CorruptionCriticalView or DownloadUNDERCODE2025-01-30
WordPress3.7.8DOM-Based XSSCriticalView or DownloadUNDERCODE2025-01-30
DevDojo Voyager1.8.0Path TraversalHighView or DownloadUNDERCODE2025-01-30
Kubewarden1.21.0PolicyReport ManipulationView or DownloadUNDERCODE2025-01-30
fast-faultUnpatchedSegmentation FaultModerateView or DownloadUNDERCODE2025-01-30
Apache Hive<4.0.0Timing DiscrepancyModerateView or DownloadUNDERCODE2025-01-28
MicrosoftSecure BootBypassMediumView or DownloadUNDERCODE2025-01-27
WindowsCOM ServerInformation DisclosureMediumView or DownloadUNDERCODE2025-01-27
Active DirectoryFederation ServerSpoofingMediumView or DownloadUNDERCODE2025-01-27
WindowsConnected Devices Platform ServiceDenial of ServiceHighView or DownloadUNDERCODE2025-01-27
MicrosoftSecure BootBypassMediumView or DownloadUNDERCODE2025-01-27
MicrosoftSecure BootBypassMediumView or DownloadUNDERCODE2025-01-27
Visual StudioN/ARemote Code ExecutionHighView or DownloadUNDERCODE2025-01-27
Apache CocoonAll versionsIncorrect PRNG Seed UsageLowView or DownloadUNDERCODE2025-01-27
WindowsTelephony ServiceRemote Code ExecutionHighView or DownloadUNDERCODE2025-01-24
WindowsTelephony ServiceRemote Code ExecutionHighView or DownloadUNDERCODE2025-01-24
WordPress1.8.96PHP Object InjectionCriticalView or DownloadUNDERCODE2025-01-24
MavenN/ACredential LeakCriticalView or DownloadUNDERCODE2025-01-24
HL7/fhir-ig-publisher1.7.4XXEHighView or DownloadUNDERCODE2025-01-24
DirectusNot specifiedXSSCriticalView or DownloadUNDERCODE2025-01-23
astevalN/ACode ExecutionView or DownloadUNDERCODE2025-01-23
Silverpeas CoreXSSView or DownloadUNDERCODE2025-01-23
Jenkins<=1.6Missing checksModerateView or DownloadUNDERCODE2025-01-22
Jenkins2.8.0-2.10.2Cache ConfusionModerateView or DownloadUNDERCODE2025-01-22
Keycloak<= 26.1.0Authentication BypassModerateView or DownloadUNDERCODE2025-01-22
Ciliumv1.14-v1.16DoSCriticalView or DownloadUNDERCODE2025-01-22
WindowsDigital MediaElevation of PrivilegeMediumView or DownloadUNDERCODE2025-01-22
WindowsKernelMemory DisclosureMediumView or DownloadUNDERCODE2025-01-22
Microsoft-Security Feature BypassMediumView or DownloadUNDERCODE2025-01-22
WindowsDigital MediaElevation of PrivilegeMediumView or DownloadUNDERCODE2025-01-22
Microsoft-Security Feature BypassMediumView or DownloadUNDERCODE2025-01-22
WindowsKernelMemory DisclosureMediumView or DownloadUNDERCODE2025-01-22
WindowsKernelMemory DisclosureMediumView or DownloadUNDERCODE2025-01-22
Internet ExplorerN/ARemote Code ExecutionHighView or DownloadUNDERCODE2025-01-22
WindowsKernelMemory DisclosureMediumView or DownloadUNDERCODE2025-01-22
gix-worktree-stateAffected versionsPermission bypassCriticalView or DownloadUNDERCODE2025-01-22
MathLiveN/AXSSCriticalView or DownloadUNDERCODE2025-01-22
CodeCheckerv6.58CSRFView or DownloadUNDERCODE2025-01-22
YesWiki<= 4.4.5DOM-Based XSSCriticalView or DownloadUNDERCODE2025-01-22
YesWiki<= 4.4.5Arbitrary File DeletionCriticalView or DownloadUNDERCODE2025-01-22
YesWiki4.4.5Stored XSSCriticalView or DownloadUNDERCODE2025-01-22
DuckDBPre-fixUnauthorized AccessView or DownloadUNDERCODE2025-01-22
Buildah1.38.0-1.38.1Build breakoutHighView or DownloadUNDERCODE2025-01-20
Node.js4.5.0-5.28.5RandomnessModerateView or DownloadUNDERCODE2025-01-22
compose-gov2.10-v2.4.0Resource ConsumptionView or DownloadUNDERCODE2025-01-22
FedifyN/AWebfinger MechanismCriticalView or DownloadUNDERCODE2025-01-21
Substance3D Designer14.0Out-of-bounds writeHighView or DownloadUNDERCODE2025-01-21
Substance3D Designer14.0Heap-based Buffer OverflowHighView or DownloadUNDERCODE2025-01-21
Substance3D Designer14.0Out-of-bounds writeHighView or DownloadUNDERCODE2025-01-21
Substance3D Designer14.0Heap-based Buffer OverflowHighView or DownloadUNDERCODE2025-01-21
Zot-AuthorizationView or DownloadUNDERCODE2025-01-17
AWS CDKv2.177.0Bypass TLS VerificationView or DownloadUNDERCODE2025-02-22
Microsoft AutoUpdateN/AElevation of PrivilegeHighView or DownloadUNDERCODE2025-01-17
Substance3D Stager3.0.4Heap-based Buffer OverflowHighView or DownloadUNDERCODE2025-01-17
Substance3D Stager3.0.4Out-of-bounds writeView or DownloadUNDERCODE2025-01-17
Substance3D Stager3.0.4Out-of-bounds writeView or DownloadUNDERCODE2025-01-17
WindowsVBS EnclavePrivilege EscalationCriticalView or DownloadUNDERCODE2025-01-17
WordPress2.10.43Stored XSSCriticalView or DownloadUNDERCODE2025-01-16
Google Chrome<132.0.6834.83Out of bounds readHighView or DownloadUNDERCODE2025-01-16
matrix-media-repo<1.3.5Unauthenticated writesModerateView or DownloadUNDERCODE2025-01-16
HAL Console< 3.7.7.FinalXSSModerateView or DownloadUNDERCODE2025-01-16
Windows Hyper-VNT Kernel Integration VSPElevation of PrivilegeHighView or DownloadUNDERCODE2025-01-15
SP1v4.0.0Validation MissingCriticalView or DownloadUNDERCODE2025-01-15
Zoom
N/A
Leaked Meeting Links
Medium
View or DownloadUNDERCODE2025-01-15
LodestarUnstableDecoding FailureCriticalView or DownloadUNDERCODE2025-01-14
LodestarUnstableChecksum VerificationCriticalView or DownloadUNDERCODE2025-01-14
.NET8.0, 9.0Remote Code ExecutionView or DownloadUNDERCODE2025-01-14
Windows Hyper-VunknownElevation of PrivilegeHighView or DownloadUNDERCODE2025-01-14
Ivanti9.1-22.7Unauthorized AccessCriticalView or DownloadUNDERCODE2025-01-14
Swift ASN.1GitHub ReviewedParsing CrashLowView or DownloadUNDERCODE2025-01-14
Vyper0.3.10, 0.4.0Precompile Success FlagMediumView or DownloadUNDERCODE2025-01-14
XWiki15.10.9+, 16.2.0+Script ExecutionCriticalView or DownloadUNDERCODE2025-01-14
TYPO311.5.42 ELTSCSRFView or DownloadUNDERCODE2025-01-14
Jte
<= 3.1.15
XSS
Critical
View or DownloadUNDERCODE2025-01-13
Jte<= 3.1.15XSSView or DownloadUNDERCODE2025-01-13
Keycloak< 26.0.8Environment Variable ExposureModerateView or DownloadUNDERCODE2025-01-13
notation-goN/ACRL Cache HandlingView or DownloadUNDERCODE2025-01-13
Microweber2.0.9XSSModerateView or DownloadUNDERCODE2025-01-13
Privileged Remote Access3.1Command InjectionView or DownloadUNDERCODE2025-01-13
Qlik Sense EnterprisePre-August 2023 Patch 2Remote Code ExecutionCriticalView or DownloadUNDERCODE2025-01-13
Code-projects1.0SQL InjectionView or DownloadUNDERCODE2025-01-10
Travel Management System1.0SQL InjectionCriticalView or DownloadUNDERCODE2025-01-10
Vaultwardenv1.32.5Reflected XSSLowView or DownloadUNDERCODE2025-01-09
GitHubv0.5.0-v0.5.21JWK Set CacheCriticalView or DownloadUNDERCODE2025-01-09
Ivanti22.7R2.5Buffer OverflowCriticalView or DownloadUNDERCODE2025-01-08
Mitel MiCollab9.8 SP2Local File ReadView or DownloadUNDERCODE2025-01-07
Oracle WebLogic Server10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0Remote Code ExecutionCriticalView or DownloadUNDERCODE2025-01-07
DenoLatestAuthorization header leakCriticalView or DownloadUNDERCODE2025-01-06
NiceGUI-Authentication BypassHighView or DownloadUNDERCODE2025-01-06
go-git<v5.13DoSHighView or DownloadUNDERCODE2025-01-06
go-gitv4 to v5.12Argument InjectionLowView or DownloadUNDERCODE2025-01-06
Phpspreadsheet3.6.0XSSMediumView or DownloadUNDERCODE2025-01-03
Phpspreadsheet3.6.0XSSView or DownloadUNDERCODE2025-01-03
Phpspreadsheet3.6.0XSSCriticalView or DownloadUNDERCODE2024-12-19
Trix editorversions prior to 2.1.11XSSCriticalView or DownloadUNDERCODE2025-01-03
phpMyFAQHTML InjectionCriticalView or DownloadUNDERCODE2025-01-02
NarayanaView or DownloadUNDERCODE2025-01-02
Google ChromeiOS prior to 131.0.6778.69Insufficient policy enforcement in NavigationView or DownloadUNDERCODE2024-11-12
Google Chromeprior to 131.0.6778.69MediumView or DownloadUNDERCODE2025-01-02
Letta (formerly MemGPT)v0.3.17Incorrect Access ControlHighView or DownloadUNDERCODE2025-01-02
ChromePrior to 129.0.6668.100DetailDescriptionType ConfusionHighView or DownloadUNDERCODE2024-10-08
Versions before 129.0.6668.100DetailDescriptionType ConfusionView or DownloadUNDERCODE2024-10-08
Google ChromeN/AInsufficient data validationMediumView or DownloadUNDERCODE2025-01-02
Google ChromeBefore 126.0.6478.54Inappropriate implementation in V8LowView or DownloadUNDERCODE2025-01-02
GLPI10.0.8 to before 10.0.13 (when debug mode is enabled)Reflected XSS (Cross-Site Scripting)Medium (CVSS score: 5.3)View or DownloadUNDERCODE2025-01-02
GLPIAll versions before 10.0.13SQL InjectionCriticalView or DownloadUNDERCODE2025-01-02
GLPIBefore 10.0.13Arbitrary Object InstantiationMediumView or DownloadUNDERCODE2024-03-18
Google ChromeiOS versions prior to 130.0.6723.58Use after freeView or DownloadUNDERCODE2025-01-02
Google ChromePrior to 130.0.6723.58Use after freeMediumView or DownloadUNDERCODE2025-01-02
Type Confusion (CVE-2024-9859)HighView or DownloadUNDERCODE2025-01-02
Linux KernelAllImproper Handling of Unknown Packet TypesLow (Note: Severity ratings are subjective and may vary depending on the source)View or DownloadUNDERCODE2024-05-19
SourceCodester FAQ Management System1.0Cross-site scripting (XSS)View or DownloadUNDERCODE2024-12-31
EmbedPress – Embed PDF, YouTube, Google Docs, Vimeo, Wistia Videos, Audios, Maps & Any Documents in Gutenberg & Elementor plugin for WordPressup to, and including, 3.9.8Stored Cross-Site Scripting (XSS)View or DownloadUNDERCODE2024-12-31
DetailDescriptionRecipes1.5.10SSRFNot mentionedView or DownloadUNDERCODE2024-12-31
Wordpress pluginup to 3.9.8Stored Cross-Site Scripting (XSS)View or DownloadUNDERCODE2024-12-31
Improper Error HandlingView or DownloadUNDERCODE2024-12-31
WordPressUp to 4.4.2SQL InjectionN/AView or DownloadUNDERCODE2024-02-13
Medium (CVSS Score: 4.3)View or DownloadUNDERCODE2024-12-31
WordPress RSS Aggregator by Feedzy PluginUp to 4.4.2Unauthorized modification of dataCriticalView or DownloadUNDERCODE2024-12-31
Apache SupersetN/AImproper validation of SQL statementsMediumView or DownloadUNDERCODE2024-02-28
Kirby CMSNot applicableArbitrary JavaScript Code ExecutionMediumView or DownloadUNDERCODE2024-12-31
TemmokuMVCUp to 2.3DeserializationCriticalView or DownloadUNDERCODE2024-12-31
Focus for iOS< 12.3Universal Cross-Site Scripting (UXSS)View or DownloadUNDERCODE2024-02-22
Suite CRM7.14.2Local File Inclusion (LFI)View or DownloadUNDERCODE2024-12-31
Linux KernelNULL Pointer DereferenceMediumView or DownloadUNDERCODE2024-12-30
Linux KernelAllMemory LeakMediumView or DownloadUNDERCODE2024-12-30
Linux kernel6.9.0-rc2-custom-00781-gd5ab772d32f7Use-after-freeView or DownloadUNDERCODE2024-12-30
Linux kernelDouble freeView or DownloadUNDERCODE2024-12-30
Linux KernelNull Pointer DereferenceLowView or DownloadUNDERCODE2024-12-30
Linux KernelAll versions before the fixUse-after-Free (UAF) in cifs_stats_proc_write()High (CVSS score not available)View or DownloadUNDERCODE2024-12-30
Linux kernelAll versions before the fixNull pointer dereferenceMedium (尚未評估)View or DownloadUNDERCODE2024-12-30
Linux kernelDouble freeView or DownloadUNDERCODE2024-12-30
Linux KernelNot specifiedmptcp: prevent BPF accessing lowat from a subflow socket (CVE-2024-35894)MediumView or DownloadUNDERCODE2024-12-30
Linux KernelUse-After-Free (UAF)CriticalView or DownloadUNDERCODE2024-12-30
Linux KernelAllNULL-pointer dereferenceLowView or DownloadUNDERCODE2024-05-17
netfilter: validate user input for expected length

View or DownloadUNDERCODE2024-12-30
RustNot SpecifiedUse of Insecure Cryptographic AlgorithmsLowView or DownloadUNDERCODE2024-12-30
LGSL6.2.1Reflected XSSModerateView or DownloadUNDERCODE2024-12-30
Password PusherAll versionsSession HijackingCriticalView or DownloadUNDERCODE2024-12-30
StripeNot mentionedInsecure Direct Object Reference (IDOR)HighView or DownloadUNDERCODE2024-12-30
Linux KernelUse After Free (UAF)View or DownloadUNDERCODE2024-12-30
Linux KernelUse-After-Free (UAF)Low (CVSS: 3.1)View or DownloadUNDERCODE2024-12-30
Adobe ColdFusion2023.6, 2021.12 and earlierImproper Access ControlCritical (CVSS score: 7.5)View or DownloadUNDERCODE2024-12-30
Critical (CVSS score: 9.8)View or DownloadUNDERCODE2024-12-30
Apple Safari, iOS, iPadOS, macOS, and visionOSCode ExecutionCritical (CVSS score: 8.8)View or DownloadUNDERCODE2024-12-30
Oracle Agile PLM Framework9.3.6Unauthenticated Remote File DisclosureHigh (CVSS: 7.5)View or DownloadUNDERCODE2024-12-30
TCPDF< 6.8.0Incorrect ComparisonModerateView or DownloadUNDERCODE2024-12-27
GStreamerN/AStack-based buffer overflowCriticalView or DownloadUNDERCODE2024-12-27
TCPDF< 6.8.0Missing Certificate ValidationView or DownloadUNDERCODE2024-12-27
SONiCElevation of PrivilegeView or DownloadUNDERCODE2024-12-27
WindowsN/AElevation of PrivilegeHIGHView or DownloadUNDERCODE2024-12-27
UnknownView or DownloadUNDERCODE2024-12-27
Visual Studio CodeElevation of PrivilegeView or DownloadUNDERCODE2024-12-27
WindowsNot MentionedElevation of PrivilegeView or DownloadUNDERCODE2024-12-27
QuincyDHCP design flaw (CVE-2024-3661)ModerateView or DownloadUNDERCODE2024-12-27
python-sql(Not specified)SQL InjectionModerateView or DownloadUNDERCODE2024-12-27

Windows Kernel

Not specified

Elevation of Privilege

View or DownloadUNDERCODE2024-12-27
Windows KernelNot mentionedInformation DisclosureMEDIUMView or DownloadUNDERCODE2024-12-27

Skype for Consumer

Not specified

Remote Code Execution

View or DownloadUNDERCODE2024-12-27
Microsoft QUICNot MentionedDenial of ServiceView or DownloadUNDERCODE2024-12-27
Windows 11-TamperingMedium (CVSS score: 6.5)View or DownloadUNDERCODE2024-12-27
Windows Kernel(not mentioned in the article)Elevation of PrivilegeView or DownloadUNDERCODE2024-12-27
lgsl(Specific version if available)Stored Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-12-26
2.1.4SQL injectionView or DownloadUNDERCODE2024-12-26
Amazon Redshift JDBC Driver2.1.0.31SQL injectionView or DownloadUNDERCODE2024-12-26
Apache HugeGraph-Server1.0.0 to 1.4.9Authentication BypassModerateView or DownloadUNDERCODE2024-12-26
Marp Core>= 3.0.2, <= 3.9.0, = 4.0.0Cross-Site Scripting (XSS)ModerateView or DownloadUNDERCODE2024-12-26
Apache Hive, Spark1.2.0 (Hive), 2.0.0 (Spark)CookieSigner Signature ExposureHighView or DownloadUNDERCODE2024-12-23
All versions before 0.13.1 or 0.14.0+devUnintended Git options ignored for creating tagsView or DownloadUNDERCODE2024-12-23

WildFly

< 3.7.7.Final

Cross-site scripting (XSS)

View or DownloadUNDERCODE2024-12-23
Solana SPL Token SwapNot specifiedUnsound `u8` type castingModerateView or DownloadUNDERCODE2024-12-23
KVM0.1.0 - 0.19.0Undefined BehaviorModerateView or DownloadUNDERCODE2024-12-23
PHP>= 1.0.12, < 1.1.13Cross-site Scripting (XSS)ModerateView or DownloadUNDERCODE2024-12-23
Jinja(Not specified in the provided article)Sandbox BreakoutModerateView or DownloadUNDERCODE2024-12-23
Symlink Editing VulnerabilityView or DownloadUNDERCODE2024-12-23
Gogs< 0.13.1Arbitrary File WriteCriticalView or DownloadUNDERCODE2024-12-23
Acclaim USAHERDS7.4.0.1 and belowHardcoded CredentialsCriticalView or DownloadUNDERCODE2024-12-23
Piranha CMS11.1Cross-site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-12-20
Piranha CMS11.1Stored Cross-site Scripting (XSS)ModerateView or DownloadUNDERCODE2024-12-20
Oqtane Framework6.0.0Incorrect Access ControlHighView or DownloadUNDERCODE2024-12-20
Uptime Kuma(unknown)Improper URL Handling (LFI)CriticalView or DownloadUNDERCODE2024-12-20
SocialStreamAffected versions prior to v6.2Account TakeoverHighView or DownloadUNDERCODE2024-12-20
Spring FrameworkAffected versions are not yet specified.Path TraversalHighView or DownloadUNDERCODE2024-12-19
QOS.CH logback-coreUp to and including 1.5.12Expression Language InjectionModerateView or DownloadUNDERCODE2024-12-19
QOS.ch logback-core1.5.12 (and earlier)Server-Side Request Forgery (SSRF)LowView or DownloadUNDERCODE2024-12-19
OpenShift DedicatedAll versions before 0.0.0-20240604173837-d1557bc283dd (patched)Improper Input Validation (Snyk-GOLANG-GITHUBCOMOPENSHIFTMUSTGATHEROPERATORCONTROLLERSMUSTGATHER-7278175)HighView or DownloadUNDERCODE2024-12-19
WhoDBAll versions up to v0.43.0Denial-of-Service (DoS)CriticalView or DownloadUNDERCODE2024-12-19
AstroSource Map DisclosureLowView or DownloadUNDERCODE2024-12-19
openCart4.0.2.3Server-Side Template Injection (SSTI)ModerateView or DownloadUNDERCODE2024-12-18
golang.org/x/net/htmlUnaffected versions not yet disclosedNon-linear parsing of case-insensitive contentCriticalView or DownloadUNDERCODE2024-12-18
Craft CMS< 5.5.2 and < 4.13.2Remote Code Execution (RCE)CriticalView or DownloadUNDERCODE2024-12-18
Apache Kafka0.10.2.0 - 3.9.0 (excluding fixed versions)Incorrect Implementation of Authentication AlgorithmLow (Exploitable only in plaintext scenarios)View or DownloadUNDERCODE2024-12-18
TShockAffected versions prior to 5.2.1Security EscalationHighView or DownloadUNDERCODE2024-12-18
AgeAffected versionsArbitrary Code ExecutionModerateView or DownloadUNDERCODE2024-12-18
Rage0.6.0, 0.7.0-0.7.1, 0.8.0-0.8.1, 0.9.0-0.9.2, 0.10.0, 0.11.0Arbitrary Code ExecutionModerateView or DownloadUNDERCODE2024-12-18
Bun< 1.1.30Prototype PollutionModerateView or DownloadUNDERCODE2024-12-18
Laravel Filemanager< 2.9.1Remote Code Execution (RCE)HighView or DownloadUNDERCODE2024-12-18

hd-wallet crate

v0.4.x (vulnerable), v0.6.0 (patched)

Infinite loop in Slip10-like derivation for curves other than secp256k1 and secp256r1

Low

View or DownloadUNDERCODE2024-12-18
Spatie Browsershot< 5.0.2Directory TraversalHighView or DownloadUNDERCODE2024-12-18
jsiiPrototype PollutionView or DownloadUNDERCODE2024-12-18
Cleartext Transmission of Sensitive InformationModerateView or DownloadUNDERCODE2024-12-18
Reolink devices (RLC-410W, C1 Pro, C2 Pro, RLC-422W, RLC-511W)Up to 1.0.227Command InjectionCriticalView or DownloadUNDERCODE2024-12-18
Reolink RLC-410Wv3.0.0.136_20121102Command InjectionCRITICALView or DownloadUNDERCODE2021-12-22
NUUO NVRmini2Up to 3.11Unauthenticated Remote Code Execution (RCE)CriticalView or DownloadUNDERCODE2024-12-18

Astro

Not specified (versions before 6031962ab5f56457de986eb82bd24807e926ba1b)

CSRF Protection Bypass

Low

View or DownloadUNDERCODE2024-12-18
Apache Tomcat11.0.0-M1 through 11.0.1, 10.1.0-M1 through 10.1.33, 9.0.0.M1 through 9.0.97Uncontrolled Resource ConsumptionModerateView or DownloadUNDERCODE2024-12-17
TraefikAffected versions are not explicitly specified.Improper handling of HTTP/3 connectionsModerateView or DownloadUNDERCODE2024-12-17
Cleo Harmony, VLTrader, LexiComBefore 5.8.0.24Remote Code Execution (RCE)CriticalView or DownloadUNDERCODE2023-11-14
Next.jsAll versions before 14.2.15 (vulnerable)Authorization BypassHighView or DownloadUNDERCODE2024-12-17
TOTOLINK X5000RV.9.1.0u.6369_B20230113Denial of Service (DoS)Critical (CVSS 3.x not available)View or DownloadUNDERCODE2024-12-16
TOTOLINK X6000RV9.4.0cu.1041_B20240224Unrestricted File Upload (Uci_Set Str function without strict parameter filtering)View or DownloadUNDERCODE2024-12-16
TOTOLink RouterX5000R V9.1.0u.6118-B20201102, A7000R V9.1.0u.6115-B20201022Buffer OverflowCriticalView or DownloadUNDERCODE2024-12-16
Totolink X6000R9.4.0cu.852_20230719OS Command Injection (CVE-2024-2353)CriticalView or DownloadUNDERCODE2024-12-16
NetApp SnapCenter4.8 and earlierImproper Authorization (CVE-2024-21987)Not yet analyzed (awaiting analysis)View or DownloadUNDERCODE2024-12-16
Oracle Java SE, GraalVM Enterprise Edition8u411, 8u411-perf, 11.0.23 (Java SE), 20.3.14, 21.3.10 (GraalVM)Partial DoSLow (CVSS score: 3.7)View or DownloadUNDERCODE2024-12-16
OpenHarmonyUp to v3.2.4 (inclusive)Insecure Storage of Sensitive InformationMedium (CVSS v3.1 score: 4.3)View or DownloadUNDERCODE2024-12-16
AndroidAndroid 12.0, 12.1, 13.0, 14.0 (potentially others)Privilege Escalation (Carrier Restriction Bypass)Critical (CVSS score not provided)View or DownloadUNDERCODE2024-12-16
Android12.0, 12.1, 13.0, 14.0 (potentially other versions as well)Heap Buffer Overflow (CVE-2024-0051)CriticalView or DownloadUNDERCODE2024-12-16
Android12, 12L, 13, 14Heap Buffer Overflow (CVE-2024-0049)HighView or DownloadUNDERCODE2024-12-16
Android12, 12L, 13, 14Privilege Escalation (CVE-2024-0048)HighView or DownloadUNDERCODE2024-12-16
Apache HugeGraph-Server1.0.0 to 1.2.1 (Java 8 or Java 11)Remote Code Execution (RCE)View or DownloadUNDERCODE2024-12-16
Concrete CMSPrior to 9.2.8 and 8.5.16Stored XSS in the Search FieldLow (CVSS v3 score: 3.1)View or DownloadUNDERCODE2024-12-16
Concrete CMS9.0.0 - 9.3.2 (Versions below 9 are not affected)Stored XSSMedium (CVSS v3 score: 3.1, CVSS v4 score: 1.8)View or DownloadUNDERCODE2024-12-16
Concrete CMSBelow 9.2.8 and 8.5.16Stored XSSMedium (CVSS v3.1 score: 3.1)View or DownloadUNDERCODE2024-12-16
Mattermost10.1.x <= 10.1.2, 10.0.x <= 10.0.2, 9.11.x <= 9.11.4, 9.5.x <= 9.5.12Data Amplification (DoS)ModerateView or DownloadUNDERCODE2024-12-16
Cosmos SDKNot Applicable (multiple versions affected)Stack Overflow (ASA-2024-0012), Resource Exhaustion (ASA-2024-0013)HighView or DownloadUNDERCODE2024-12-16
ColdFusion2023.6, 2021.12 and earlierImproper Access ControlHIGH (CVSS: 7.4)View or DownloadUNDERCODE2024-12-16
WindowsAll versions (affected versions not specified)Elevation of Privilege in Kernel-Mode DriversCritical (CVSS v3 score: 7.8)View or DownloadUNDERCODE2024-12-16
D-Tale< 3.16.1Remote Code ExecutionModerateView or DownloadUNDERCODE2024-12-13
FHIR/Ucum-java1.0.8 and belowXXECriticalView or DownloadUNDERCODE2024-12-13
Browsershot< 5.0.1Local File InclusionHighView or DownloadUNDERCODE2024-12-13
phpMyFAQAll versions before 3.2.10Unrestricted File DownloadCriticalView or DownloadUNDERCODE2024-12-13
Cleo Harmony, VLTrader, LexiComBefore 5.8.0.21Unrestricted File Upload/DownloadCriticalView or DownloadUNDERCODE2024-12-13
Adobe Framemaker2020.7, 2022.5 and earlierStack-based Buffer Overflow (CVE-2024-53959)Critical (CVSS: 7.8)View or DownloadUNDERCODE2024-12-13
Adobe Substance 3D Modeler1.14.1 and earlierOut-of-Bounds Write (CWE-787)Critical (CVSS 3.1 base score: 7.8)View or DownloadUNDERCODE2024-12-12
F5 BIG-IP (Advanced WAF/ASM)All versions before 17.1.1 (17.x) are vulnerable. No fix available for 15.x and 16.x versions.Request Body Handling vulnerability (CVE-2024-23308)High (CVSS score: 7.5)View or DownloadUNDERCODE2024-12-12
Cache SystemsN/AMD5 Collision VulnerabilityCriticalView or DownloadUNDERCODE2024-12-12
python-libarchiveUp to 4.2.1Directory TraversalHighView or DownloadUNDERCODE2024-12-12
XWikiAll versions between 2.3 and 15.10.8 (excluding 15.10.9) and between 16.0.0-rc-1 and 16.2.9 (excluding 16.3.0)Remote Code Execution (RCE) via XWiki.ConfigurableClass objectCriticalView or DownloadUNDERCODE2024-12-12
XWikiAll versions between 9.7-rc-1 and 16.5.0 (excluding patched versions)Remote Code Execution (RCE) through Macro Descriptions (CVE-ID not yet assigned)CriticalView or DownloadUNDERCODE2024-12-12
XWikiXWiki versions 1.2-milestone-2 to 15.10.8 and 16.0.0-rc-1 to 16.2.9 are affected.Unauthorized execution of scheduled operationsModerateView or DownloadUNDERCODE2024-12-12
Apache SupersetBefore 4.1.0SQL InjectionHighView or DownloadUNDERCODE2024-12-12
ryanbekhen/nanoproxyNot specifiedOutdated golang.org/x/crypto dependencyHighView or DownloadUNDERCODE2024-12-12
Remote Code Execution (RCE)CriticalView or DownloadUNDERCODE2024-12-12
Online Class and Exam Scheduling System1.0SQL Injection (CVE-2024-12487)CriticalView or DownloadUNDERCODE2024-12-12
Apache Fineract< 1.8.5SQL InjectionCRITICALView or DownloadUNDERCODE2024-12-12
Tenda AC10U Router15.03.06.48Stack-Based Buffer Overflow (CVE-2024-2764)CriticalView or DownloadUNDERCODE2024-12-12
Codezips Technical Discussion Forum1.0SQL Injection (CVE-2024-12484)CriticalView or DownloadUNDERCODE2024-12-12
Online Class and Exam Scheduling System1.0 (specifically vulnerable)SQL Injection (CWE-74, CWE-89)Critical (CVSS v3.1: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L)View or DownloadUNDERCODE2024-12-12
macOS SonomaAll versions before 14.7.1File System Modification (CVE-2024-44301)CriticalView or DownloadUNDERCODE2024-12-12
WordPressGutenberg Blocks by Kadence Blocks plugin up to 3.2.23Stored XSS (Cross-Site Scripting)CriticalView or DownloadUNDERCODE2024-12-12
Online Class and Exam Scheduling System1.0SQL InjectionCritical (CVSS v3: MEDIUM)View or DownloadUNDERCODE2024-12-12
GitLab CE/EE12.5 before 16.9.6, 16.10 before 16.10.4, 16.11 before 16.11.1Unauthenticated ReDoS in FileFinder with crafted wildcard filtersHigh (CVSS: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)View or DownloadUNDERCODE2024-12-12
Online Class and Exam Scheduling System1.0SQL InjectionView or DownloadUNDERCODE2024-12-12
Apache Fineract< 1.8.5SQL Injection (CVE-2024-23539)HIGHView or DownloadUNDERCODE2024-12-12
Qualcomm Windows WLAN HostNot specifiedImproper Restriction of Operations within the Bounds of a Memory Buffer (CVE-2024-43053)High (CVSS Score: 7.8)View or DownloadUNDERCODE2024-12-12
Apple iOSNot specified (all versions before 17.7 and 18)Unexpected App TerminationCritical (An attacker can exploit the vulnerability to crash applications)View or DownloadUNDERCODE2024-12-12
macOSNot specified (all versions before 14.7 and 15 are potentially vulnerable)Out-of-bounds writeCritical (CVSS details not available yet)View or DownloadUNDERCODE2024-12-12
macOS, iOS, iPadOSAll versions before macOS Ventura 13.7, iOS 17.7/iPadOS 17.7, visionOS 2, iOS 18/iPadOS 18, macOS Sonoma 14.7, macOS Sequoia 15 (inclusive)Race condition in archive unpacking (CVE-2024-27876)Critical (CVSS v3 score likely high)View or DownloadUNDERCODE2024-12-12
LinuxNot specifiedOut-of-bounds memory accessCVSS information is not yet available in the public record.View or DownloadUNDERCODE2024-12-12
Linux KernelNot specifiedInteger Overflow in pagemap_scan_get_args()Moderate (CVSS score: 5.5)View or DownloadUNDERCODE2024-12-12
rahman SelectCours 1.0 (Template Handler component)Not specifiedTemplate Injection (CVE-2024-2064)CriticalView or DownloadUNDERCODE2024-12-12
Synack TargetAllSQLi Blind Time-BasedMediumView or Download + Steps to reproduceDailyCve.com12-12-2024
golangorg/x/crypto/sshbefore v0.31.0, partially mitigated in v0.31.0Authorization Bypass via Misused ServerConfig.PublicKeyCallbackMediumView or DownloadUNDERCODE2024-12-11
Linux KernelNot specified (all versions before the fix)Memory Leak (due to missing kfree_skb())Low (addressed in kernel updates)View or DownloadUNDERCODE2024-12-11
GitLab CE/EEAll versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1Uncontrolled Resource Consumption (DoS)MediumView or DownloadUNDERCODE2024-12-11

Linux Kernel

Unaffected versions not listed (all potentially affected)
A memory leak vulnerability exists in the Linux

Medium (CVSS v3 base score not available yet)

View or DownloadUNDERCODE2024-12-11
macOS SonomaAll versions before 14.6Buffer Overflow (CVSS: High)CriticalView or DownloadUNDERCODE2024-12-11
Linux KernelUnaffected versions not listed (all versions before the fix are assumed vulnerable)Memory Leak (vsock sk_error_queue)Medium (CVSS 3.x Base Score: 5.5)View or DownloadUNDERCODE2024-12-11
kcpAffected versions are prior to 0.26.1.Impersonation vulnerabilityCriticalView or DownloadUNDERCODE2023-11-28
SiYuan<= 0.0.0-20241210012039-5129ad926a21Server-Side Template Injection (SSTI)ModerateView or DownloadUNDERCODE2024-12-11
SiYuan<= 0.0.0-20241210012039-5129ad926a21Arbitrary File ReadHighView or DownloadUNDERCODE2024-12-11
SiYuan<= 0.0.0-20241210012039-5129ad926a21Arbitrary File WriteHighView or DownloadUNDERCODE2024-12-11
Apple iOS, iPadOS, tvOS, and visionOSUnaffected versions not listed (Update to the latest version is recommended)Kernel Memory Corruption (CVE-2024-44277)CriticalView or DownloadUNDERCODE2024-12-11
Linux KernelNot specified (all versions potentially affected)Bluetooth handle release issueMedium (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-12-11
DowngradeView or DownloadUNDERCODE2024-12-11
Apple Products (iOS, iPadOS, macOS, watchOS, visionOS)Unaffected versions not listed (all prior versions potentially vulnerable)Information Disclosure (CVE-2024-44278)CriticalView or DownloadUNDERCODE2024-12-11
JFinalCMS1.0Server-Side Template InjectionView or DownloadUNDERCODE2024-12-11
Liferay Digital Experience PlatformUp to 7.4.3.15Remote Code Execution (RCE)CriticalView or DownloadUNDERCODE2024-12-11
Kashipara E-learning Management Systemv1.0CriticalView or DownloadUNDERCODE2024-12-11
Liferay Portal, Liferay DXP7.2.0 through 7.4.3.12 (Portal), all versions before update 9 (DXP 7.4), all versions before service pack 3 (DXP 7.3), all versions before fix pack 19 (DXP 7.2), and older unsupported versions.Open Redirect (CVE-2024-25609)Critical (CVSS: 6.1)View or DownloadUNDERCODE2024-12-11
macOSNot specified (potentially all versions before Ventura 13.7.1 and Sonoma 14.7.1)PackageKit flaw allowing modification of protected file system areas (CVE-2024-44275)Unknown (awaiting analysis)View or DownloadUNDERCODE2024-12-11
Kashipara E-learning Management Systemv1.0SQL InjectionCritical (CVSS score unavailable)View or DownloadUNDERCODE2024-12-11
JFinalCMS1.0Cross-Site Request Forgery (CSRF)MediumView or DownloadUNDERCODE2024-12-11
Linux KernelNot specifiedUndefined Behavior due to stack usageLow (CVSS details not provided)View or DownloadUNDERCODE2024-12-11
Linux KernelNot specifiedBluetooth handle overflow (CVE-2024-42132)Low (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-12-11
Linux Kernel (ARM)Not specifiedCache Flushing IssueCritical (CVSS details not provided)View or DownloadUNDERCODE2024-12-11
OpenHarmonyPrior to 4.0.1Out-of-Bounds ReadView or DownloadUNDERCODE2024-12-11
Linux KernelUnaffected versions not mentionedUse-after-free (UAF) in the sctp_v6_available() functionCritical (DoS)View or DownloadUNDERCODE2024-12-11
Hewlett Packard Enterprise Insight Remote Support( not specified )Directory TraversalCRITICAL (CVSS Score: 9.8)View or DownloadUNDERCODE2024-12-11
Linux KernelNot specifiedUnbalanced pm_runtime_enable! (CVE-2024-53134)MediumView or DownloadUNDERCODE2024-12-11
Linux KernelNot specifiedDeadlock when accessing tmpfs over NFSMedium (CVSS details not provided)View or DownloadUNDERCODE2024-12-11
Huawei (exact platform unspecified)(not specified)Insufficient verification in system sharing pop-up module (CVE-2024-32989)High (availability impact)View or DownloadUNDERCODE2024-12-11
HarmonyOSAll versions before a patch is applied (specifically mentioned for 4.0.0 and 4.2.0)Permission verification vulnerability in the system sharing pop-up moduleMEDIUM (CVSS score: 6.1)View or DownloadUNDERCODE2024-12-11
Apache Airflow2.8.0 - 2.8.2 (inclusive)Incorrect Privilege AssignmentModerateView or DownloadUNDERCODE2024-12-11
HarmonyOS (all versions mentioned in the references are vulnerable)Not specifiedOut-of-bounds memory accessView or DownloadUNDERCODE2024-12-11
Apache AirflowBefore 2.9.2Use of Web Browser Cache Containing Sensitive InformationMediumView or DownloadUNDERCODE2024-12-11
HarmonyOSNot specifiedInsufficient verification vulnerability in the baseband moduleHighView or DownloadUNDERCODE2024-12-11
MEDIUM (CVSS 3.1 score: 6.2)View or DownloadUNDERCODE2024-12-11
wpa_supplicant module (platform not specified)Not specifiedPermission verification vulnerability (CVE-2024-32991)Critical (CVSS score not explicitly mentioned but the description indicates critical impact)View or DownloadUNDERCODE2024-12-11
Linux KernelUnaffected versions not specified (all before the patch)Privilege EscalationLowView or DownloadUNDERCODE2024-12-11
Missing outer runtime PM protection in drm/xe driverMedium (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-12-11
Local Privilege Escalation (SBAMSvc Link Following)Critical (CVSS score likely high)View or DownloadUNDERCODE2024-12-11
Linux KernelNot specified (all versions using nilfs2 file system are potentially affected)Null Pointer DereferenceLow (CVSS score might be available elsewhere)View or DownloadUNDERCODE2024-12-11
Local Privilege EscalationCritical (CVSS score likely high)View or DownloadUNDERCODE2024-12-11
Heap-based Buffer Overflow (CVE-2024-8025)CriticalView or DownloadUNDERCODE2024-12-11
IBM Cognos Controller11.0.0, 11.0.1Malicious File Upload (CVE-2024-25019)CriticalView or DownloadUNDERCODE2024-12-11
Visteon Infotainment SystemN/ALocal Privilege Escalation (LPE)CriticalView or DownloadUNDERCODE2024-12-11
Visteon Infotainment App SoC (System-on-Chip)Not specifiedMissing Immutable Root of Trust (Hardware Local Privilege Escalation)View or DownloadUNDERCODE2024-12-11
Visteon Infotainment Systems(not specified)Command Injection (CVE-2024-8359)High (CVSS score: 6.8)View or DownloadUNDERCODE2024-12-11
IBM Cognos Controller11.0.0, 11.0.1Exposure of Sensitive InformationNot available (CVSS details not provided)View or DownloadUNDERCODE2024-12-11
IBM Cognos Controller11.0.0, 11.0.1Unrestricted File UploadCritical (CVSS 3.1 score not provided)View or DownloadUNDERCODE2024-12-11
IBM Cognos Controller11.0.0, 11.0.1File Upload Vulnerability (CVE-2024-45676)CriticalView or DownloadUNDERCODE2024-12-11
IBM Cognos Controller11.0.0, 11.0.1Weak Cryptographic AlgorithmsCritical (CVSS details not provided)View or DownloadUNDERCODE2024-12-11
Checkmk Exchange Plugin for MikroTik2.0.0 - 2.5.5 & 0.4a_mk - 2.0aImproper Certificate Validation (CVE-2024-38861)MEDIUM (CVSS v4.0: 4.9)View or DownloadUNDERCODE2024-12-11
Multiple Apple products (iOS, iPadOS, macOS, watchOS, tvOS)All versions before iOS/iPadOS 17.7, macOS 13.7, etc. (see NVD for specifics)CVE-2024-44169 (Kernel Logic Issue)Not specified (likely medium or high)View or DownloadUNDERCODE2024-12-11
macOSAll versions before macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15 (patched)Buffer overflow in Intel Graphics Driver (CVE-2024-44160)CriticalView or DownloadUNDERCODE2024-12-11
CheckmkBefore 2.3.0p16 and 2.2.0p34Cross-Site Scripting (XSS)MEDIUM (CVSS v3: 5.1)View or DownloadUNDERCODE2024-12-11
Apple iOSAll versions before iOS 18 and iPadOS 18 (Vulnerable)Authentication Bypass (CVE-2024-44202)CriticalView or DownloadUNDERCODE2024-12-11
Wazifa System1.0Cross-site Scripting (XSS)Medium (CVSS score: 5.3)View or DownloadUNDERCODE2024-12-11
1000 Projects Library Management System1.0SQL Injection (CVE-2024-12188)CriticalView or DownloadUNDERCODE2024-12-11
PHPGurukul Complaint Management System1.0SQL Injection (CVE-2024-12230)CriticalView or DownloadUNDERCODE2024-12-11
WeiYe-Jing datax-web2.1.1OS Command Injection (CVE-2024-12358)CriticalView or DownloadUNDERCODE2024-12-11
TP-Link VN020 F3v(T)TT_V6.2.1021Buffer OverflowCriticalView or DownloadUNDERCODE2024-12-11
Online Class and Exam Scheduling System1.0SQL Injection (CWE-74, CWE-89)Critical (CVSS v2: 6.5, CVSS v3: 6.3, CVSS v4: 5.3)View or DownloadUNDERCODE2024-12-11
TOTOLINK EX1800T9.1.0cu.2112_B20220316Stack Overflow (CVE-2024-12352)MediumView or DownloadUNDERCODE2024-12-11
code-projects Online Notice BoardUp to 1.0Unrestricted File UploadCritical (CVSS v3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)View or DownloadUNDERCODE2024-12-11
SourceCodester Phone Contact Manager System1.0Improper Input ValidationMedium (CVSS v3.1: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)View or DownloadUNDERCODE2024-12-11
PHPGurukul Complaint Management System1.0SQL Injection (CVE-2024-12228)CriticalView or DownloadUNDERCODE2024-12-11
SourceCodester Petrol Pump Management Software1.0Unrestricted File UploadCritical (CVSS score not provided)View or DownloadUNDERCODE2024-12-11
SourceCodester Best House Rental Management System1.0File InclusionMedium (CVSS v3: 4.3, CVSS v2: 5.0, CVSS v4: 6.9)View or DownloadUNDERCODE2024-12-11
SourceCodester Phone Contact Manager System1.0Improper Input ValidationMedium (CVSS v3.1: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)View or DownloadUNDERCODE2024-12-11
Tenda Routers (FH451, FH1201, FH1202, FH1206)Up to 20241129Null Pointer Dereference (in websReadEvent function of /goform/GetIPTV)MEDIUM (CVSS score: 5.3)View or DownloadUNDERCODE2024-12-11

Override leakage to global cache

Critical

View or DownloadUNDERCODE2024-12-10
Ruby on RailsCross-Site Scripting (XSS)LowView or DownloadUNDERCODE2024-12-10
peerigon/angular-expressionsUnaffected versions: >= 1.4.3Remote Code Execution (RCE)CriticalView or DownloadUNDERCODE2024-12-10
wasmvm, cosmwasm-vm(details not yet available)Medium (Moderate + Likely)View or DownloadUNDERCODE2024-12-10
CosmWasm VMMultiple (see Affected Versions)Unspecified (details pending)MediumView or DownloadUNDERCODE2024-12-10
Linux KernelNot specified (versions up to 6.11.3 are vulnerable)Integer overflow in AMD display driver (CVE-2024-50177)MediumView or DownloadUNDERCODE2024-12-10
SourceCodester Simple Online Bidding System1.0SQL InjectionCritical (CVSS v3 Base Score: 5.3 - MEDIUM)View or DownloadUNDERCODE2024-12-10
SourceCodester Simple Online Bidding System1.0Cross-Site Request Forgery (CSRF)MEDIUM (CVSS score: 6.9)View or DownloadUNDERCODE2024-12-10
SourceCodester Simple Online Bidding System1.0SQL InjectionView or DownloadUNDERCODE2024-12-10
SourceCodester Simple Online Bidding System1.0Cross-Site Request Forgery (CSRF)MEDIUMView or DownloadUNDERCODE2024-12-10
Linux KernelAll versions with MPTCP enabled (potentially from 5.7 to later)mptcp: handle consistently DSS corruptionMedium (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-12-10
SourceCodester Simple Online Bidding System1.0SQL InjectionCritical (CVSS v3.1: AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L)View or DownloadUNDERCODE2024-12-10
Hugo>= 0.123.0, < 0.139.4Unescaped Attributes in Internal TemplatesModerateView or DownloadUNDERCODE2024-12-09
Apache Superset2.0.0 to 4.1.0 (excluding 4.1.0)Improper AuthorizationHighView or DownloadUNDERCODE2024-12-09
Winter CMSAffected versionsTwig Sandbox BypassCriticalView or DownloadUNDERCODE2024-12-09
idna<= 0.5.0Punycode Spoofing (CVE- not mentioned)CriticalView or DownloadUNDERCODE2024-12-09
League/CommonMarkAffected versions prior to 2.6.0Denial of Service (DoS)CriticalView or DownloadUNDERCODE2023-11-28
HarmonyOSNot specified (all versions before May 2024 patch are likely vulnerable)Null Pointer Access (CVE-2024-32998)MediumView or DownloadUNDERCODE2024-12-09
HarmonyOSNot specified (all versions before 17.5 are likely vulnerable)Race condition in binder driver module (CVE-2024-32997)HighView or DownloadUNDERCODE2024-12-09
(Multiple - see below)(All versions before 17.5/10.5/14.5)Logic Issue (CVE-2024-27816)CriticalView or DownloadUNDERCODE2024-12-09
HuaweiEMUI 14, EMUI 13, HarmonyOS 4.2, HarmonyOS 4.0, HarmonyOS 3.1, HarmonyOS 3.0 (based on Huawei security bulletin)PIN enhancement failures in the screen lock moduleHighView or DownloadUNDERCODE2024-12-09
Cracking vulnerability in the OS security moduleView or DownloadUNDERCODE2024-12-09
EMUI (Huawei)Not specifiedImproper Permission Control in Window ManagementMediumView or DownloadUNDERCODE2024-12-09
HarmonyOSAll versions before a fix is applied (specific versions not mentioned)Cracking vulnerability in the OS security moduleMedium (CVSS score: 6.4)View or DownloadUNDERCODE2024-12-09
HarmonyOSAll versions (not specified)Privilege Escalation due to permission control issue in the App Multiplier moduleHighView or DownloadUNDERCODE2024-12-09
Apple Vision ProNot specified (versions before 1.1 are vulnerable)Permissions IssueCriticalView or DownloadUNDERCODE2024-12-09
macOS SonomaNot specifiedCode ExecutionCritical (CVSS score likely high)View or DownloadUNDERCODE2024-12-09
Apple Platforms (tvOS, iOS, iPadOS, macOS, watchOS)Unaffected versions are tvOS 17.4, iOS 17.4, iPadOS 17.4, macOS Sonoma 14.4, and watchOS 10.4 or later.CVE-2024-23293 - Spotlight vulnerability allowing access to sensitive user data through Siri with physical access.CriticalView or DownloadUNDERCODE2024-12-09
Rockwell Automation Arena Simulation SoftwareNot specifiedHeap-based memory buffer overflowHIGH (CVSS v3 score: 7.8)View or DownloadUNDERCODE2024-12-09
Rockwell Automation Arena Simulation softwareNot specifiedMemory buffer overflowCritical (CVSS v3 score: 7.8, CVSS v4 score: 8.4)View or DownloadUNDERCODE2024-12-09
Rockwell Automation Arena SimulationAll Versions (not specified)Memory Buffer OverflowMedium (CVSS v3 score: 4.4)View or DownloadUNDERCODE2024-12-09
Palo Alto Networks PAN-OS (with Captive Portal enabled)Not specifiedReflected Cross-Site Scripting (XSS) - CVE-2024-0011MEDIUM (CVSS v3 score: 4.3)View or DownloadUNDERCODE2024-12-09
Palo Alto Networks PAN-OSReflected Cross-Site Scripting (XSS) - CVE-2024-0010MEDIUM (CVSS score: 4.3)View or DownloadUNDERCODE2024-12-09
Rockwell Automation Arena SimulationAll versions (not specified)Arbitrary Code ExecutionCritical (CVSS v3: 7.8, CVSS v4: 8.4)View or DownloadUNDERCODE2024-12-09
Not specified (all versions before iOS 17.4, iPadOS 17.4, macOS Monterey 12.7.4, etc. are vulnerable)

Validation Issue

High

View or DownloadUNDERCODE2024-12-09
macOS SonomaAll versions before 14.4Improper handling of temporary files (CVE-2024-23287)CriticalView or DownloadUNDERCODE2024-12-09
Apple GarageBandAll versions before 10.4.11 (Vulnerable)Use-after-freeCritical (CVSS score not provided)View or DownloadUNDERCODE2024-12-09
macOS, iOS, iPadOS(Unaffected versions not specified)Incomplete data redaction in log entriesCritical (An app may be able to access user-sensitive data)View or DownloadUNDERCODE2024-12-09
macOS (various versions)Not specifiedMemory CorruptionCriticalView or DownloadUNDERCODE2024-12-09
Apple (iOS, iPadOS, macOS, watchOS)All versions before iOS 16.7.6, iPadOS 16.7.6, iOS 17.4, iPadOS 17.4, macOS Sonoma 14.4, watchOS 10.4Lock Screen Bypass via SiriCriticalView or DownloadUNDERCODE2024-12-09
Apple iOSAll versions before 16.7.6 and 17.4System Notification SpoofingCritical (CVSS score unavailable)View or DownloadUNDERCODE2024-12-09

Remote Code Execution (RCE)

Critical (unauthenticated attacker can execute arbitrary code)

View or DownloadUNDERCODE2024-12-09
WhatsUp GoldBefore 2023.1.2Server-Side Request Forgery (SSRF)MEDIUMView or DownloadUNDERCODE2024-12-09
WhatsUp GoldBefore 2023.1.2SSRFMedium (CVSS v3 score: 4.2)View or DownloadUNDERCODE2024-12-09
WhatsUp GoldBefore 24.0.1SQL Injection (CVE-2024-46906)Critical (CVSS score: 8.8)View or DownloadUNDERCODE2024-12-09
Drupal CoreVulnerable versionsImproper Error HandlingModerateView or DownloadUNDERCODE2024-12-07
AndroidAffected versions are prior to 2.3.4.Deserialization vulnerabilityLowView or DownloadUNDERCODE2024-12-07
ModerateView or DownloadUNDERCODE2024-12-07
`path-to-regexp`0.1.xReDoSModerateView or DownloadUNDERCODE2024-12-07
(not specified in the article)HTML Injection (CVE-2024-54128)CriticalView or DownloadUNDERCODE2024-12-07
PyO30.23.0 to 0.23.2Build corruptionModerateView or DownloadUNDERCODE2024-12-07
pprof(Unaffected versions not specified)Unsound memory access due to type mismatch and misalignmentLowView or DownloadUNDERCODE2024-12-07
linkmeAffected versionsType MismatchLowView or DownloadUNDERCODE2024-12-07
Drupal Core>= 10.1.0, = 10.2.0, < 10.2.2Denial of ServiceHighView or DownloadUNDERCODE2024-12-07
Solana Web3.js1.95.6 and 1.95.7Supply chain attack leading to private key theftCriticalView or DownloadUNDERCODE2024-12-07
anstream (Rust)< 0.6.8UnsoundnessModerateView or DownloadUNDERCODE2024-12-07
GitHub CLINot specified (versions before 2.63.1)Path TraversalModerateView or DownloadUNDERCODE2024-12-07

PAN-OS

Privilege EscalationMEDIUMView or DownloadUNDERCODE2024-12-07
MetabaseAffected versions include 0.40.4 and earlier, and 1.40.4 and earlier.Local File Inclusion (LFI)Critical (CVSS Score: 10.0)View or DownloadUNDERCODE2024-12-07
WindowsMultiple Windows versions are affected.Elevation of PrivilegeHIGHView or DownloadUNDERCODE2024-12-07
Atlassian Jira Server and Data CenterBefore 8.5.14, 8.6.0-8.13.6, 8.14.0-8.16.1Path TraversalCriticalView or DownloadUNDERCODE2021-03-16
Safari, iOS, iPadOS, macOS, visionOSAffected versions are older than Safari 18.1.1, iOS 17.7.2, iPadOS 17.7.2, macOS Sequoia 15.1.1, iOS 18.1.1, iPadOS 18.1.1, visionOS 2.1.1.Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-12-07
Kemp LoadMasterAll versions before 7.2.48.10, 7.2.54.8, 7.2.59.2Unauthenticated Command InjectionCritical (CVSS v3 score: 10.0)View or DownloadUNDERCODE2024-12-07
vCenter ServerAffected versions are not explicitly mentioned.Heap-overflow vulnerability in the DCERPC protocol implementation.Critical (CVSS Score: 9.8)View or DownloadUNDERCODE2024-12-07
Palo Alto Networks Expedition(Not specified)SQL Injection (CVE-2024-9465)Critical (CVSS score: 9.2)View or DownloadUNDERCODE2024-12-07
Zyxel ATP Series, USG FLEX Series, USG FLEX 50(W) Series, and USG20(W)-VPN SeriesV5.00 through V5.38Directory TraversalHIGHView or DownloadUNDERCODE2024-12-07
Oracle Agile PLM Framework9.3.6Information DisclosureHighView or DownloadUNDERCODE2024-12-07
ProjectSendPrior to r1720Improper AuthenticationCritical (CVSS Score: 9.8)View or DownloadUNDERCODE2024-12-07
Not specified (WebKit is used across various Apple products)Versions prior to those mentioned above (specific versions not provided)Sandbox Escape (Critical)CriticalView or DownloadUNDERCODE2024-12-06
Apple iOS, iPadOS, macOSVersions before iOS 17.4, iPadOS 17.4, and macOS Sonoma 14.4Authentication Bypass in Hidden Photos AlbumCritical (CVSS details not shown in excerpt)View or DownloadUNDERCODE2024-12-06
Apple (mentioned in source)Not specified (all versions before the fixed ones are vulnerable)Race Condition (mentioned in description)High (implied by potential access to user-sensitive data)View or DownloadUNDERCODE2024-12-06
Zyxel USG FLEX H SeriesuOS versions up to (excluding) 1.30Insufficiently protected credentialsCritical (CVSS v3 score details not provided)View or DownloadUNDERCODE2024-12-06
iOS, iPadOS, tvOS, watchOS, macOS (all versions before the mentioned fixes)Not applicable (all versions before the fixes)Unrestricted Microphone AccessView or DownloadUNDERCODE2024-12-06
macOS SonomaNot specified (all versions before 14.4 are vulnerable)Improper memory handlingMedium (allows denial-of-service or potential information disclosure)View or DownloadUNDERCODE2024-12-06
macOS Sonoma(Not specified in the provided text)Memory Access IssueCritical (CVE-2024-23249)View or DownloadUNDERCODE2024-12-06
Apple iOSVersions before 17.4Shake-to-Undo information disclosure (CVE-2024-23240)CriticalView or DownloadUNDERCODE2024-12-06
macOSSonoma 14.4, Monterey 12.7.4 (Unaffected versions not listed)Privilege EscalationCriticalView or DownloadUNDERCODE2024-12-06
macOS SonomaBefore 14.4Permissions Issue (CVE-2024-23253)LowView or DownloadUNDERCODE2024-12-06
macOSNot specified (all versions vulnerable before macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5)Out-of-bounds write in Kerberos v5 PAM moduleCritical (CVSS v3.1: CISA-ADP AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)View or DownloadUNDERCODE2024-12-06
(see below)(see below)Information LeakageView or DownloadUNDERCODE2024-12-06
macOSSonoma 14.4, Monterey 12.7.4, Ventura 13.6.5 (all prior versions are vulnerable)Improper Memory Handling (Code Execution)CriticalView or DownloadUNDERCODE2024-12-06
DirectusNot specified (update to latest version)Client-Side HTML Injection (CVE-2024-54128)CriticalView or DownloadUNDERCODE2024-12-05
sigstore-javaLow (for non-monitors/witnesses)View or DownloadUNDERCODE2024-12-05
Drupal CoreN/AImproper Error HandlingModerateView or DownloadUNDERCODE2024-12-05
Drupal Core10.1.0 - 10.1.7, 10.2.0 - 10.2.1Denial of ServiceHighView or DownloadUNDERCODE2024-12-05
Apache Hive4.0.0-alpha-1Deserialization of untrusted dataHighView or DownloadUNDERCODE2024-12-05
Perl (App::cpanminus package)Up to 1.7047Insecure HTTP DownloadCritical (CVSS 3.0: 9.8/10)View or DownloadUNDERCODE2024-12-05
LowView or DownloadUNDERCODE2024-12-05
PyO30.23.0 - 0.23.2Build CorruptionModerateView or DownloadUNDERCODE2024-12-05
Microsoft Brokering File System (Platform details not specified)(Version information not provided)Elevation of PrivilegeHIGH (CVSS v3 Base Score: 7.8)View or DownloadUNDERCODE2024-12-05
Dell Secure Connect Gateway (SCG) Policy ManagerAllStored Cross-Site Scripting (XSS)HIGHView or DownloadUNDERCODE2024-12-05
RpgpAll versions prior to 0.14.1Multiple vulnerabilities leading to denial-of-serviceCriticalView or DownloadUNDERCODE2024-12-05
Spring LDAPAll versions before 2.4.0, 2.4.0 through 2.4.3, 3.0.0 through 3.0.9, 3.1.0 through 3.1.7, 3.2.0 through 3.2.7Information ExposureModerate (CVE-2024-38829)View or DownloadUNDERCODE2024-12-04
Anstream (platform unspecified)Not specifiedUnhandled Character EncodingView or DownloadUNDERCODE2024-12-04
Apache HTTP ServerAffected versions include 2.4.49 and earlier.A remote code execution vulnerability that can be exploited to execute arbitrary code on the server.CriticalView or DownloadUNDERCODE2024-12-04
LinkmeAffected versionsType MismatchLowView or DownloadUNDERCODE2024-12-04
CheckmkUp to 2.0.0, specific 2.1.0 and 2.2.0 versionsMultiple vulnerabilities (CVE-2023-43277, CVE-2023-43278, CVE-2023-43279)High (CVE-2023-43277), Medium (CVE-2023-43278, CVE-2023-43279)View or DownloadUNDERCODE2024-12-04
PDF-XChange Editor(not specified)Out-of-Bounds Read Information DisclosureView or DownloadUNDERCODE2024-12-04
Adobe Animate24.0 and earlier (including 23.0.3)Out-of-Bounds Read (CVE-2024-20762)MEDIUM (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-12-04
Zabbix ServerNot specified (all versions before 6.4.16rc1 and 7.0.0 are vulnerable)Code Injection (CWE-94)Critical (CVSS score: 9.9)View or DownloadUNDERCODE2024-12-04
Adobe Animate23.0.4 and earlierOut-of-bounds read (CVE-2024-20797)Critical (CVSS score: 7.8)View or DownloadUNDERCODE2024-12-04
Adobe Animate23.0.4 and earlierOut-of-bounds read (CVE-2024-20796)Medium (CVSS 3.1 base score: 5.5)View or DownloadUNDERCODE2024-12-04
GitHub CLIPrior to 2.63.1Path TraversalCriticalView or DownloadUNDERCODE2024-12-04
CyberPanelBefore 1c0c6cb (through 2.3.6 and unpatched 2.3.7)Command InjectionCritical (CVSS score: 10.0)View or DownloadUNDERCODE2024-12-04
Adobe Experience ManagerVersions 6.5.19 and earlier (not specified)Stored Cross-Site Scripting (XSS)Medium (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUM (CVSS 3.x Base Score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)Medium (CVSS v3 base score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUM (CVSS 3.1 base score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUM (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
ChargePoint Home Flex(Not specified in the article)Denial-of-Service (DoS)MEDIUM (CVSS score: 4.3)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUMView or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUM (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
Trimble SketchUpAll versions (unaffected versions not specified yet)Stack-based buffer overflow remote code executionCriticalView or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUM (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUM (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
PDF-XChange EditorAll versions before a patch is released (information not yet available)Out-of-bounds read leading to remote code execution (RCE)High (CVSS v3 score to be determined)View or DownloadUNDERCODE2024-12-03
IBM QRadar Suite, IBM Cloud Pak for Security1.10.12.0 through 1.10.17.0 (QRadar Suite), 1.10.0.0 through 1.1.11.0 (Cloud Pak for Security)Information ExposureCritical (CVSS score details unavailable)View or DownloadUNDERCODE2024-12-03
Linux KernelNot specified (all versions using the iwlwifi driver are potentially vulnerable)Memory Error (improper response handling)Critical (CVE-2024-53059)View or DownloadUNDERCODE2024-12-03
Linux KernelNot specified (all versions potentially affected)Null pointer dereferenceCriticalView or DownloadUNDERCODE2024-12-03
HighView or DownloadUNDERCODE2024-12-03
code-projects FarmaciaUp to 1.0SQL InjectionCritical (CVSS score: 5.3 MEDIUM)View or DownloadUNDERCODE2024-12-03
CheckmkBelow 2.3.0p22, 2.2.0p37, and 2.1.0p50Information DisclosureMedium (CVSS v3: 6.5, CVSS v4: 5.7)View or DownloadUNDERCODE2024-12-03
element-hq/synapseBefore 1.106Unauthenticated Writes to Media RepositoryModerateView or DownloadUNDERCODE2024-12-03
element-hq/synapseBefore 1.120.1Malformed Invite Disrupts /sync FunctionalityHighView or DownloadUNDERCODE2024-12-03
SynapseBelow 1.120.1Unsupported content type handling (multipart/form-data)HighView or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)Medium (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
Stack-based Buffer Overflow (Remote Code Execution)Critical (CVSS score likely high)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierReflected Cross-Site Scripting (XSS)MediumView or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierReflected Cross-Site Scripting (XSS) (CWE-79)Important (CVSS Score: 5.4 - Medium)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierCross-Site Scripting (XSS)Medium (CVSS v3 score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUM (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS) - CVE-2024-26038MEDIUM (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)Medium (CVSS 3.1 score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUM (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
Zyxel ATP Series, USG FLEX Series, USG FLEX 50(W) Series, and USG20(W)-VPN SeriesV5.00 through V5.38Directory TraversalHIGHView or DownloadUNDERCODE2024-12-03
ProjectSendPrior to r1720Improper AuthenticationCritical (CVSS score: 9.8)View or DownloadUNDERCODE2024-12-03
Adobe InDesign Desktop19.0, 20.0 and earlierOut-of-bounds read (CVE-2024-49529)MEDIUM (CVSS 3.x Base Score: 5.5)View or DownloadUNDERCODE2024-12-03
Adobe Dreamweaver Desktop21.3 and earlierOS Command Injection (CVE-2024-30314)CriticalView or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierDOM-based Cross-Site Scripting (XSS)MEDIUM (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUM (CVSS 3.x Base Score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Substance 3D Stager3.0.2 and earlierOut-of-bounds read (CVE-2024-52998)Medium (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS) - CVE-2024-26043MEDIUM (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierDOM-based XSS (Cross-Site Scripting)Medium (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored XSSMEDIUMView or DownloadUNDERCODE2024-12-03
Adobe Premiere Pro23.6.5, 24.4.1 and earlierUntrusted Search PathCriticalView or DownloadUNDERCODE2024-12-03
Adobe Experience Manager (AEM)6.5.20 and earlierStored Cross-Site Scripting (XSS)Medium (CVSS v3 score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.20 and earlierDOM-based XSS (CVE-2024-49524)MediumView or DownloadUNDERCODE2024-12-03
Adobe Experience Manager (AEM)6.5.19 and earlier (all versions before 6.5.20 are potentially vulnerable)DOM-based Cross-Site Scripting (XSS)MEDIUM (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Substance 3D Painter9.1.2 and earlierOut-of-bounds readImportant (CVSS Score: 5.5)View or DownloadUNDERCODE2024-12-03
Adobe Experience ManagerVersions 6.5.19 and earlier (information incomplete due to reanalysis)Stored Cross-Site Scripting (XSS)Medium (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe InDesign DesktopID18.5.2, ID19.3 and earlierNULL Pointer DereferenceImportant (CVSS Score: 5.5)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlier (all prior versions are vulnerable)Stored Cross-Site Scripting (XSS) (CVE-2024-26056)MEDIUM (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUM (CVSS 3.x score: 5.4)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUMView or DownloadUNDERCODE2024-12-03
Adobe Substance 3D Painter9.1.2 and earlierOut-of-bounds read (CVE-2024-30308)Important (CVSS Score: 5.5)View or DownloadUNDERCODE2024-12-03
Adobe InDesignID18.5.2, ID19.3 and earlierHeap-based Buffer Overflow (CVE-2024-39392)Critical (CVSS score: 7.8)View or DownloadUNDERCODE2024-12-03
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUM (CVSS score: 5.4)View or DownloadUNDERCODE2024-12-03
RailsRails >= 7.1.0 and Nokogiri < 1.15.7, or 1.16.x < 1.16.8 (Rails::HTML::Sanitizer 1.6.0 is vulnerable)XSSCriticalView or DownloadUNDERCODE2024-12-03

Rails

Rails >= 7.1.0 & Rails::HTML::Sanitizer 1.6.0

Cross-Site Scripting (XSS)

Medium

View or DownloadUNDERCODE2024-12-03
Potential XSS (Cross-Site Scripting)View or DownloadUNDERCODE2024-12-03
RailsRails >= 7.1.0 with Rails::HTML::Sanitizer 1.6.0XSSCriticalView or DownloadUNDERCODE2024-12-03
Mongoose< 8.8.3Search InjectionHighView or DownloadUNDERCODE2024-12-03

Rails::HTML::Sanitizer

1.6.0

XSS (Cross-Site Scripting)

Medium

View or DownloadUNDERCODE2024-12-03
Adobe FrameMaker2020.5, 2022.3 and earlier (all versions before 2020.6 or 2022.4)Out-of-bounds read (CVE-2024-30287)Important (CVSS 3.x Base Score: 5.5)View or DownloadUNDERCODE2024-12-02
Adobe FrameMaker2020.5, 2022.3 and earlierHeap-Based Buffer Overflow (CVE-2024-30288)Critical (CVSS Score: 7.8)View or DownloadUNDERCODE2024-12-02
Adobe FrameMaker2020.5 and earlier (including 2022.3)Out-of-bounds read (CVE-2024-30286)Medium (CVSS score: 5.5)View or DownloadUNDERCODE2024-12-02
Adobe Acrobat Reader20.005.30574 and earlierUse After Free (CVE-2024-30284)Critical (CVSS: 3.1 High - 7.8)View or DownloadUNDERCODE2024-12-02
Adobe Acrobat ReaderVersions 20.005.30574, 24.002.20736 and earlier (fill in "all" if all versions are affected)Use After FreeCritical (CVSS score: 7.8)View or DownloadUNDERCODE2024-12-02
Adobe Acrobat ReaderAll versions before 20.005.30635 and 24.002.20759Improper Access Control (CVE-2024-34099)HIGH (CVSS: 7.8)View or DownloadUNDERCODE2024-12-02
Adobe Acrobat ReaderVersions before 20.005.30574 and 24.002.20736Out-of-bounds write vulnerabilityHIGH (CVSS 3.1 base score: 7.8)View or DownloadUNDERCODE2024-12-02
Adobe Acrobat Reader20.005.30574, 24.002.20736 and earlierOut-of-Bounds ReadHIGH (CVSS 3.x Base Score: 7.8)View or DownloadUNDERCODE2024-12-02
Adobe Acrobat ReaderVersions before 20.005.30635 and 24.002.20759 (inclusive)Use After Free (CVE-2024-34095)HIGH (CVSS v3 score: 7.8)View or DownloadUNDERCODE2024-12-02
Adobe Acrobat Reader DC20.005.30539, 23.008.20470 and earlierUse After Free (CVE-2024-30301)Critical (CVSS 7.8)View or DownloadUNDERCODE2024-12-02
Adobe Acrobat Reader20.005.30574, 24.002.20736 and earlierUse After Free (CVE-2024-34100)Critical (CVSS: 3.1/7.8)View or DownloadUNDERCODE2024-12-02
Adobe Acrobat Reader20.005.30574, 24.002.20736 and earlierOut-of-bounds read (CVE-2024-30311)MediumView or DownloadUNDERCODE2024-12-02
Adobe Acrobat Reader20.005.30574 and earlierOut-of-bounds read (CVE-2024-30312)CriticalView or DownloadUNDERCODE2024-12-02
Adobe Acrobat ReaderAll versions before 20.005.30574 and 24.002.20736Out-of-bounds read (CVE-2024-34101)Medium (CVSS 3.x Base Score: 5.5)View or DownloadUNDERCODE2024-12-02
Adobe FrameMaker2020.5, 2022.3 and earlier (all versions before 2020.6 or 2022.4)Out-of-Bounds Read (CVE-2024-30283)Medium (CVSS score: 5.5)View or DownloadUNDERCODE2024-12-02
`ruzstd`Affected versionsUninitialized and Out-of-Bounds Memory ReadsModerateView or DownloadUNDERCODE2024-12-02
Python-multipartAffected versionsDenial of Service (DoS)HighView or DownloadUNDERCODE2024-12-02
Adobe Experience Manager6.5.19 and earlierStored Cross-Site Scripting (XSS)MEDIUM (CVSS v3 score: 5.4)View or DownloadUNDERCODE2024-12-02
Google ChromeBefore 122.0.6261.57Inappropriate implementation in NavigationCritical (Chromium security severity: Medium)View or DownloadUNDERCODE2024-12-02
Symfony!ERROR! B2746 -> Formula Error: Unexpected ,DeserializationHighView or DownloadUNDERCODE2024-12-02
Ant-Media-Server2.8.2Improper Output Neutralization for LogsHighView or DownloadUNDERCODE2024-12-02
SymfonyAffected versions are not explicitly mentioned. It is recommended to upgrade to the latest version to mitigate the risk.Authentication BypassModerateView or DownloadUNDERCODE2024-12-02
SimpleSAMLphpAll versions before 2.3.4, 2.2.4, 2.1.7, and 2.0.15XXE (XML External Entity)CriticalView or DownloadUNDERCODE2024-12-02
N/A (Lettuce is a Java library)Affected versions < 6.5.1.RELEASENetty vulnerability (CVE-TBD)ModerateView or DownloadUNDERCODE2024-12-02
Ibexa Admin UIAffected versions are not explicitly mentioned.Cross-site Scripting (XSS)ModerateView or DownloadUNDERCODE2024-12-02
SFTPGo2.3.0 to 2.6.3Brute Force Takeover of OpenID Connect Session CookiesModerateView or DownloadUNDERCODE2024-12-02
SimpleSAMLphp SAML2(Unaffected versions not specified)XXEModerateView or DownloadUNDERCODE2024-12-02
Node.js10.0.4Prototype PollutionCriticalView or DownloadUNDERCODE2024-12-02
Not specifiedNot specifiedCache ConfusionModerateView or DownloadUNDERCODE2024-12-02
Versions before 10.0.0Cross-Site Scripting (XSS)MediumView or DownloadUNDERCODE2024-12-02
veraPDF CLIAffected versions are not explicitly specified.XXE (XML External Entity Injection)LowView or DownloadUNDERCODE2024-12-02
SimpleSAMLphpNot specifiedXXEHighView or DownloadUNDERCODE2024-12-02
(Not specified in the provided text)libarchive versions before 3.7.5Out-of-bounds memory access in execute_filter_audio functionHIGH (CVSS v3 score: 7.8)View or DownloadUNDERCODE2024-12-02
AMTT Hotel Broadband Operation SystemUp to 3.0.3.151204SQL Injection (CVE-2024-11051)CriticalView or DownloadUNDERCODE2024-12-02
Concert Ticket Ordering System1.0SQL InjectionView or DownloadUNDERCODE2024-12-02
Team Plugins360 All-in-One Video GalleryAll versions up to 3.5.2Missing AuthorizationHIGHView or DownloadUNDERCODE2024-12-02
Veritas Enterprise VaultBefore 15.2Remote Code ExecutionCritical (CVSS score: 9.8)View or DownloadUNDERCODE2024-11-29
Veritas Enterprise VaultBefore 15.2Remote Code Execution (RCE)Critical (CVSS 3.x score: 9.8)View or DownloadUNDERCODE2024-11-29
Microsoft WindowsNot specified (all versions potentially affected)Elevation of PrivilegeHIGH (CVSS 3.1 base score: 7.0)View or DownloadUNDERCODE2024-11-29
Open Management Infrastructure (OMI)Not specified (all versions likely affected)Remote Code Execution (RCE)Critical (CVSS: 9.8)View or DownloadUNDERCODE2024-11-29
.NET7.0 (<= 7.0.16), 8.0 (<= 8.0.2)Denial of Service (DoS)HIGH (CVSS score: 7.5)View or DownloadUNDERCODE2024-11-29
Kerberos Security Feature BypassHIGH (CVSS 3.1 base score: 7.5)View or DownloadUNDERCODE2024-11-29
WordPressProfileGrid plugin versions up to 5.9.3.6Unauthorized data modificationMedium (CVSS: 6.5)View or DownloadUNDERCODE2024-11-29
HIGH (CVSS: 7.0)View or DownloadUNDERCODE2024-11-29
Microsoft Dynamics 365 (on-premises)Not specifiedCross-site Scripting (XSS)HIGH (CVSS v3 score: 7.6)View or DownloadUNDERCODE2024-11-29
WordPressAshe theme versions up to 2.243Reflected Cross-Site Scripting (XSS)MEDIUM (CVSS: 6.1)View or DownloadUNDERCODE2024-11-29
WordPress Plugin - MailChimp Forms by MailMunchAll versions up to 3.2.3 (inclusive)Reflected Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-11-29
Veritas Enterprise VaultBefore 15.2Remote Code Execution (RCE)Critical (CVSS v3 score: 9.8)View or DownloadUNDERCODE2024-11-29
Out-of-Bounds Read Remote Code Execution (RCE)Critical (CVSS v3 score: 7.8)View or DownloadUNDERCODE2024-11-29
PDF-XChange Editor(not specified in available information)Out-of-Bounds Write Remote Code ExecutionHIGH (CVSS score: 7.8) based on Zero Day Initiative (ZDI)View or DownloadUNDERCODE2024-11-29
MediumView or DownloadUNDERCODE2024-11-29
PDF-XChange EditorAll versions before a patch is releasedInformation DisclosureView or DownloadUNDERCODE2024-11-22
PDF-XChange EditorNot specified (all versions before a patch is released are vulnerable)Out-of-Bounds Read Remote Code ExecutionHIGHView or DownloadUNDERCODE2024-11-29
PDF-XChange Editor(information not available)Out-of-bounds read remote code execution (RCE)Critical (CVSS v3.0 base score likely high)View or DownloadUNDERCODE2024-11-29
EMF File Parsing Out-Of-Bounds ReadLOW (CVSS: 3.3)View or DownloadUNDERCODE2024-11-29
Out-of-Bounds Read Remote Code Execution (RCE) in XPS parsingCritical (CVSS score likely high)View or DownloadUNDERCODE2024-11-29
Foxit PDF ReaderAll versions (unspecified)Out-of-Bounds Read Remote Code ExecutionCriticalView or DownloadUNDERCODE2024-11-29
Foxit PDF ReaderNot specified in this sourceAnnotation Use-After-FreeCriticalView or DownloadUNDERCODE2024-11-29
Local Privilege EscalationCriticalView or DownloadUNDERCODE2024-11-29
Foxit PDF Reader (all versions)Not specifiedIncorrect Permission Assignment in Update Service (Local Privilege Escalation)CriticalView or DownloadUNDERCODE2024-11-29
Foxit PDF ReaderAll versions (not specified)Out-of-Bounds Read Information DisclosureCriticalView or DownloadUNDERCODE2024-11-29
Annotation Use-After-Free Remote Code ExecutionCritical (CVSS score likely high)View or DownloadUNDERCODE2024-11-29
Annotation Out-of-Bounds ReadCriticalView or DownloadUNDERCODE2024-11-29
Out-of-Bounds Write Remote Code ExecutionCriticalView or DownloadUNDERCODE2024-11-29
SolarWinds Web Help Desk (WHD)Not specified in the provided information.Hardcoded CredentialsCritical (CVSS score: 9.1)View or DownloadUNDERCODE2024-11-29
SolarWinds Serv-UAll versions up to 15.4.2 Hotfix 1Directory TraversalCriticalView or DownloadUNDERCODE2024-11-29
D-Link NAS devices (DNS-320L, DNS-325, DNS-327L, DNS-340L)All versions up to April 3rd, 2024 (EOL)Command Injection (CVE-2024-3273)Critical (CVSS score likely high)View or DownloadUNDERCODE2024-11-29
Windows (10 and above), Windows Server (2016 and later)Not specifiedHeap-based buffer overflow in DWM Core LibraryHIGH (CVSS v3 score: 7.8)View or DownloadUNDERCODE2024-11-29
AndroidAll versions (initially reported on Pixel devices but affects all)Privilege Escalation (CVE-2024-32896)CriticalView or DownloadUNDERCODE2024-11-29
IrfanViewAll versionsHeap-based buffer overflow due to SVG file parsingCritical (CVSS score: 7.8)View or DownloadUNDERCODE2024-11-29
IrfanViewAll versions (unaffected version not specified)Out-of-Bounds Read Remote Code Execution (RCE)View or DownloadUNDERCODE2024-11-29
IrfanViewAll versionsDXF File Parsing Type Confusion Remote Code ExecutionCriticalView or DownloadUNDERCODE2024-11-29
CriticalView or DownloadUNDERCODE2024-11-29
Foxit PDF ReaderAll versions up to (including) 13.1.3 (Windows) & 13.1.2 (Mac)Use-After-Free Remote Code Execution (RCE)CriticalView or DownloadUNDERCODE2024-11-29
Microsoft Windows KernelNot specifiedTime-Of-Check Time-Of-Use (TOCTOU) race conditionCritical (CVSS score: 7.0)View or DownloadUNDERCODE2024-11-29
Windows MSHTML Platform(Not specified in the provided information)Security Feature BypassCritical (CVSS v3 score: 8.8)View or DownloadUNDERCODE2024-11-29
Oracle CRM Technical Foundation (Oracle E-Business Suite)12.2.3 - 12.2.13Partial Denial of Service (DoS)Medium (CVSS 3.1 Base Score: 4.3)View or DownloadUNDERCODE2024-11-29
JD Edwards EnterpriseOne ToolsPrior to 9.2.8.1Information DisclosureCriticalView or DownloadUNDERCODE2024-11-29
Oracle MySQL Server8.0.35 and prior, 8.2.0 and priorPrivilege Escalation (CVE-2024-20964)Critical (CVSS 3.1 Base Score: 5.3)View or DownloadUNDERCODE2024-11-29
Hugging Face TransformersNot specifiedDeserialization of Untrusted Data (Remote Code Execution)CriticalView or DownloadUNDERCODE2024-11-28
Hugging Face Transformers (MaskFormer model)Not specifiedDeserialization of Untrusted Data (Remote Code Execution)ImportantView or DownloadUNDERCODE2024-11-28
Linux KernelNot specifiedImproper lock handling (CVE-2024-53086)Moderate (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-11-28
Linux KernelNot specified (potentially all versions with the vulnerable remoteproc driver)Error Handling Vulnerability (CWE-755)Low (CVSS v3 details not provided)View or DownloadUNDERCODE2024-11-28
Linux KernelNot specifiedUse-After-Free (UAF)Moderate (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-11-28
Linux KernelNot specified (all versions potentially affected)Exec Queue LeakMedium (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-11-28
Linux KernelNot specified (versions 6.5 to 6.12 likely affected)Uninitialized variables (hdr_len and txbuf_len)Medium (CVSS 3.1 base score: 5.5)View or DownloadUNDERCODE2024-11-28
Linux KernelNot specified (all versions potentially affected)Race ConditionModerate (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-11-28
Linux KernelNot specified (all versions potentially affected)Access to uninitialized variable in tick_ctx_cleanup() functionMedium (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-11-28
Hugging Face Transformers (Library)(Unaffected versions not specified yet)Remote Code Execution (RCE)Critical (CVSS score unavailable, but details suggest high severity)View or DownloadUNDERCODE2024-11-28
Linux kernelNot specified (likely impacts specific kernel versions)Improper use of use_count in media:qcom:camss:stop_streaming functionMedium (CVSS 3.x Base Score: 5.5)View or DownloadUNDERCODE2024-11-28
Linux KernelNot specified (potential impact on all versions with Loongson 3 CPU support)Improper Resource Handling (use of incorrect function)LowView or DownloadUNDERCODE2024-11-28
Linux KernelNot specified (all versions affected by commit de8548813824)Race condition during group handle conversionMedium (CVSS 3.x Base Score: 4.7)View or DownloadUNDERCODE2024-11-28

Cilium

v1.16.0 - v1.16.3 (inclusive)

Layer 7 policy enforcement bypass with port ranges

Medium

View or DownloadUNDERCODE2024-11-28
MLflowN/APrivilege EscalationHighView or DownloadUNDERCODE2024-11-28
deno_doc(not specified)Self-XSSLowView or DownloadUNDERCODE2024-11-28
Querydsl (with JPA)Not specified (but vulnerable in versions up to 6.8.0)HQL Injection (Blind)CriticalView or DownloadUNDERCODE2024-11-28
SPEmailHandler-PHP< 1.0.0Arbitrary Email SendingHighView or DownloadUNDERCODE2024-11-28
Python0.1.13Credential HarvestingHighView or DownloadUNDERCODE2024-11-28
sigstore-javav1.0.0Improper verification of log entry in bundle verification (CVE-2024-53267)CriticalView or DownloadUNDERCODE2024-11-28
libre-chat0.0.6Path TraversalModerateView or DownloadUNDERCODE2024-11-28
lakeFSAffected versions are not explicitly specified.Privilege EscalationModerateView or DownloadUNDERCODE2024-11-28
Jenkins< 0.0.15Path TraversalModerateView or DownloadUNDERCODE2024-11-28
Keycloak26 and earlierDenial-of-Service (DoS)CriticalView or DownloadUNDERCODE2023-11-21
Keycloak!ERROR! B2830 -> Formula Error: Unexpected ,Sensitive Data ExposureView or DownloadUNDERCODE2024-11-28
Jenkins1.4.4 and earlierStored Cross-Site Scripting (XSS)HighView or DownloadUNDERCODE2024-11-28
GitHub CLIPrior to 2.63.0Token LeakCriticalView or DownloadUNDERCODE2024-11-28
Devolutions.XTS.NETAll versionsTiming AttackModerateView or DownloadUNDERCODE2024-11-28
Android (uses Apache ExternalStorageProvider)Unaffected versions not specified (potential for widespread impact)File Path Filter BypassCriticalView or DownloadUNDERCODE2024-11-28
Safari, iOS, iPadOS, macOS, visionOSAffected versions prior to Safari 18.1.1, iOS 17.7.2 and iPadOS 17.7.2, macOS Sequoia 15.1.1, iOS 18.1.1 and iPadOS 18.1.1, visionOS 2.1.1Arbitrary Code ExecutionCriticalView or DownloadUNDERCODE2024-11-28
vCenter ServerAffected versionsPrivilege EscalationHIGHView or DownloadUNDERCODE2024-11-28
Oracle Agile PLM Framework9.3.6Information DisclosureHIGHView or DownloadUNDERCODE2024-11-28
SQL Injection (CVE-2024-9465)Critical (CVSS score: 9.2)View or DownloadUNDERCODE2024-11-28
CyberPanel (aka Cyber Panel)Before 5b08cd6d53f4dbc2107ad9f555122ce8b0996515 (versions through 2.3.6 and unpatched 2.3.7)Remote Code Execution (RCE)Critical (CVSS 10.0)View or DownloadUNDERCODE2024-11-28
Progress Kemp LoadMasterAll versions after 7.2.48.1 (including LoadMaster Multi-Tenant VFNs)Unauthenticated Command InjectionCRITICALView or DownloadUNDERCODE2024-11-28
Missing AuthenticationCritical (CVSS score: 9.3)View or DownloadUNDERCODE2024-11-28
NTLMv2 Hash Disclosure SpoofingView or DownloadUNDERCODE2024-11-28
Cisco Adaptive Security Appliance (ASA)Not specifiedCross-site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-11-28
Palo Alto Networks PAN-OSView or DownloadUNDERCODE2024-11-28
WindowsMultiple versions affectedElevation of PrivilegeHighView or DownloadUNDERCODE2024-11-28
Apple Products (Safari, iOS, iPadOS, macOS, visionOS)Affected versions include Safari 18.1, iOS 17.7, iPadOS 17.7, macOS Sonoma 15.1, iOS 18.1, iPadOS 18.1, and visionOS 2.1.Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-11-28
Hugging Face Transformers MaskFormer ModelAll versions before a fix is appliedDeserialization of Untrusted Data Remote Code ExecutionCriticalView or DownloadUNDERCODE2024-11-27
Linux KernelNot specified (the vulnerability was identified in a pre-release version)Suspicious RCU usage in ip_tunnel_find() functionMediumView or DownloadUNDERCODE2024-11-27
Linux KernelNot specified (all versions potentially affected)Memory Corruption in drm/vc4 driverModerate (CVSS v3 score to be determined)View or DownloadUNDERCODE2024-11-27
go-ghPrior to 2.11.1Improper Token HandlingModerateView or DownloadUNDERCODE2024-11-27
GitHub CLIPrior to 2.63.0Token LeakCriticalView or DownloadUNDERCODE2024-11-27
SPEmailHandler-PHP< 1.0.0Arbitrary Email SendingHighView or DownloadUNDERCODE2024-11-27
Linux KernelUnaffected versions not specified yet (Needs Evaluation for most Ubuntu versions)Use-after-free (accessing uninitialized variable)Moderate (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-11-27
Linux KernelNot specified (potentially all versions with qcom:camss driver)Incorrect usage of reference counter in qcom:camss driver (CVE-2024-50175)ModerateView or DownloadUNDERCODE2024-11-27
Linux KernelNot specified (versions 6.10 to 6.12 likely affected)Race condition (CVE-2024-50174)Moderate (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-11-27
ServiceNow VancouverMultipleRemote Code Execution (RCE)CriticalView or DownloadUNDERCODE2024-11-27
Linux KernelNot specified (all versions before the fix are potentially vulnerable)Exec Queue LeakMedium (CVSS score details not yet available)View or DownloadUNDERCODE2024-11-27
Google ChromePrior to 124.0.6367.207Out-of-bounds write in V8 JavaScript engineCritical (High in Chromium)View or DownloadUNDERCODE2024-11-27
Linux KernelNot specifiedResource Leak due to Object Reference LoopMediumView or DownloadUNDERCODE2024-11-27
Linux KernelNot specifiedRace condition in TPM suspension (CVE-2024-53085)Moderate (CVSS score details not provided)View or DownloadUNDERCODE2024-11-27
Linux KernelNot specified (all versions using the vulnerable cpufreq driver)cpufreq: loongson3: Use raw_smp_processor_id() in do_service_request() (CVE-2024-50178)CriticalView or DownloadUNDERCODE2024-11-27
Apple Safari, iOS, iPadOS, macOS SequoiaAll versions before Safari 18.1.1, iOS 17.7.2, iPadOS 17.7.2, macOS Sequoia 15.1.1, iOS 18.1.1, iPadOS 18.1.1, and visionOS 2.1.1Code Execution (CVE-2024-44308)CriticalView or DownloadUNDERCODE2024-11-27
Google ChromePrior to 124.0.6367.201Use After Free in VisualsHighView or DownloadUNDERCODE2024-11-27
Linux KernelNot specifiedImproper Error Handling (remoteproc driver)Moderate (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-11-27
Linux KernelNot specifiedUninitialized variable (hdr_len, txbuf_len)MediumView or DownloadUNDERCODE2024-11-27
ServiceNow Now PlatformAll versions before Xanadu General Availability (vague)Sandbox Escape (allows remote code execution)Critical (CVSS score: 9.3)View or DownloadUNDERCODE2024-11-27
Jenkins< 0.0.15Path TraversalModerateView or DownloadUNDERCODE2024-11-27
QuerydslNot specified (vulnerable since initial versions)HQL InjectionCriticalView or DownloadUNDERCODE2024-11-27
Devolutions.XTS.NETAll versions before 2024.11.26Timing Attack (CVE-2024-11862)ModerateView or DownloadUNDERCODE2024-11-27
Google ChromeBefore 125.0.6422.112Type Confusion in V8 JavaScript EngineView or DownloadUNDERCODE2024-11-27
Google ChromePrior to 128.0.6613.84 (Unaffected versions not specified)Type Confusion (CVE-2024-7971)Critical (CVSS score likely high)View or DownloadUNDERCODE2024-11-27
Linux KernelNot specifiedBounds checking error in snd_soc_dapm_widget_listMediumView or DownloadUNDERCODE2024-11-27
Oracle WebCenter Portal (Oracle Fusion Middleware)12.2.1.4.0 (affected version)Unauthorized access (update, insert, delete, read) to some of Oracle WebCenter Portal dataMedium (CVSS v3 score: 4.4)View or DownloadUNDERCODE2024-11-27
Oracle Agile Product Lifecycle Management for ProcessPrior to 6.2.4.2Unauthenticated remote code executionCritical (CVSS 3.1 Base Score: 7.3)View or DownloadUNDERCODE2024-11-27
MySQL Server8.0.35 and prior, 8.2.0 and priorServer : Security : FirewallMediumView or DownloadUNDERCODE2024-11-27
Oracle BI Publisher6.4.0.0.0, 7.0.0.0.0Unauthorized access (update, insert, delete, read)Critical (CVSS score: 5.4)View or DownloadUNDERCODE2024-11-27
Linux KernelUnaffected versions not specified (likely all before a patched version is released)Integer underflow in PLL value checks for Samsung Arbiter 0521 sensorCriticalView or DownloadUNDERCODE2024-11-27
Oracle Hospitality Simphony (component: Simphony Enterprise Server)19.1.0 - 19.5.4Easily exploitable via HTTPCritical (CVSS 3.1 Base Score: 9.9)View or DownloadUNDERCODE2024-11-27
Oracle MySQL Server8.0.36 and prior, 8.3.0 and priorInformation Schema flawCritical (CVSS score: 5.3)View or DownloadUNDERCODE2024-11-27
Oracle WebLogic Server (Core component)12.2.1.4.0, 14.1.1.0.0Security Feature BypassCritical (CVSS 3.1 Base Score: 6.1)View or DownloadUNDERCODE2024-11-27
Oracle E-Business Suite12.2.3 - 12.2.13Unauthorized data accessMedium (CVSS 3.1 Base Score: 5.3)View or DownloadUNDERCODE2024-11-27
Oracle Solaris11Zone component vulnerabilityCritical (CVSS score: 8.2)View or DownloadUNDERCODE2024-11-27
Oracle MySQL Server8.0.35 and prior, 8.2.0 and prior (all versions before these are vulnerable)Improper handling within the Optimizer componentCritical (CVSS 3.1 Base Score: 4.9)View or DownloadUNDERCODE2024-11-27
Oracle E-Business Suite12.2.3 - 12.2.13CVE-2024-20958Medium (CVSS 3.1 Base Score: 5.4)View or DownloadUNDERCODE2024-11-27
Oracle Database Sharding19.3-19.22 & 21.3-21.13An attacker with DBA privileges and network access can cause a partial denial-of-service (DoS).Low (CVSS v3 base score: 2.4)View or DownloadUNDERCODE2024-11-27
Linux KernelNot specifiedBuffer overflow in video capture when using more than 32 buffers.Medium (CVSS v3.1: 5.5)View or DownloadUNDERCODE2024-11-27
Linux KernelUnaffected versions not specified (all before 6.11.8 likely vulnerable)Missing buffer index check in dvb_vb2_expbuf() functionLow (CVSS v3 score not yet available)View or DownloadUNDERCODE2024-11-27
Linux Kernel (Xilinx axienet)Not specified (affects specific platforms)Race condition in network transmissionModerate (CVSS: 5.5)View or DownloadUNDERCODE2024-11-27
Linux KernelUnaffected versions not listed (all potentially vulnerable)Btrfs reference list handling error in `insert_delayed_ref()`LowView or DownloadUNDERCODE2024-11-27
Linux KernelNot specified (all versions potentially affected)Infinite Loop in filemap_read()Medium (CVSS v3: 5.5)View or DownloadUNDERCODE2024-11-27
Linux KernelNot specified (all versions vulnerable before a fix is applied)Crash due to invalid pointer accessMedium (CVSS score not yet assigned)View or DownloadUNDERCODE2024-11-27
Linux KernelNot specifiedInteger overflow in damon_feed_loop_next_input functionModerate (CVSS score details might be available elsewhere)View or DownloadUNDERCODE2024-11-26
Linux Kernel(Unaffected versions not specified)Improper IO Mapping HandlingHighView or DownloadUNDERCODE2024-11-26
CRI-O!ERROR! B2894 -> Formula Error: Unexpected ,Malicious checkpoint file can lead to arbitrary node accessModerateView or DownloadUNDERCODE2024-11-26
TCPDF6.7.5Local File Inclusion (LFI)ModerateView or DownloadUNDERCODE2024-11-26
Tungsten Automation Power PDFAll versions (not specified)Out-of-Bounds Read Remote Code Execution (RCE) in JP2 file parsingCriticalView or DownloadUNDERCODE2024-11-26
Tungsten Automation Power PDFAll versions (not specified)JPG File Parsing Out-Of-Bounds ReadInformation Disclosure (allows attackers to see sensitive information)View or DownloadUNDERCODE2024-11-26
Tungsten Automation Power PDFAllJP2 File Parsing Out-Of-Bounds Read Remote Code ExecutionCriticalView or DownloadUNDERCODE2024-11-26
Tungsten Automation Power PDFNot specifiedOut-of-Bounds Read Information DisclosureNot officially rated (CVSS information not yet available)View or DownloadUNDERCODE2024-11-26
WordPressSirv plugin up to 7.3.0Unauthorized modification of data leading to Denial-of-Service (DoS)CriticalView or DownloadUNDERCODE2024-11-26
WordPress Restaurant Menu – Food Ordering System PluginUp to and including 2.4.2Reflected Cross-Site Scripting (XSS)Medium (CVSS v3: 6.1)View or DownloadUNDERCODE2024-11-26
WordPressContact Form 7 Email Add On plugin <= 1.9Local File InclusionHIGHView or DownloadUNDERCODE2024-11-26
WordPressWooCommerce Product Table Lite plugin versions up to 3.8.6Arbitrary Shortcode Execution & Reflected Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-11-26
FastStone Image ViewerAll versions before 7.8 are affected (unspecified in report)Out-of-Bounds Write in GIF ParsingCritical (Allows remote code execution)View or DownloadUNDERCODE2024-11-26
Tungsten Automation Power PDF(not specified)Out-of-Bounds Read in PDF ParsingInformation Disclosure (Exploitation likely requires additional vulnerabilities)View or DownloadUNDERCODE2024-11-26
PDF-XChange Editor (all versions)Not applicableOut-of-bounds write during PDF parsingCriticalView or DownloadUNDERCODE2024-11-26
Perl (Imager package)Before 1.0.25Heap-based buffer overflowCritical (CVSS details not provided)View or DownloadUNDERCODE2024-11-26
Ivanti Cloud Services Appliance (CSA)4.6 (before Patch 518)OS Command Injection (CVE-2024-8190)CriticalView or DownloadUNDERCODE2024-11-26
Use-After-Free leading to Remote Code ExecutionCritical (allows attackers to take full control of the system)View or DownloadUNDERCODE2024-11-26
WordPressWPGYM <= 67.1.0Unauthenticated Arbitrary File UploadCriticalView or DownloadUNDERCODE2024-11-26
WordPressWPGYM plugin up to 67.1.0Privilege EscalationModerate (CVSS score not yet available)View or DownloadUNDERCODE2024-11-26
AMD EPYC Processors (see below for affected models)Firmware versions up to (excluding) milanpi_1.0.0.d or genoapi_1.0.0.c (depending on the model)Details not specified in the excerpt, but likely exploitable by attackers.Critical (highest severity level)View or DownloadUNDERCODE2024-11-26
Dell PowerProtect DDPrior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50Access ControlCriticalView or DownloadUNDERCODE2024-11-26
IrfanViewAll versions (to be confirmed)Out-of-Bounds Read Remote Code Execution (RCE) in SID file parsingCriticalView or DownloadUNDERCODE2024-11-26
IBM Watson Query on Cloud Pak for Data, IBM Db2 Big SQL on Cloud Pak for Data1.8, 2.0, 2.1, 2.2 (Watson Query), 7.3, 7.4, 7.5, 7.6 (Db2 Big SQL)Insufficient session expirationCriticalView or DownloadUNDERCODE2024-11-26
PHP8.1. before 8.1.31, 8.2. before 8.2.26, 8.3. before 8.3.14HTTP Request Smuggling (CVE-2024-11234)CriticalView or DownloadUNDERCODE2024-11-26
Pandora FMS700 through <= 777.4Command Injection (LDAP Authentication)MEDIUMView or DownloadUNDERCODE2024-11-26
WordPressMy Contador lesr plugin <= 2.0Unauthenticated Stored Cross-Site Scripting (XSS)Medium (CVSS: 3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)View or DownloadUNDERCODE2024-11-26
WordPressDino Game - Embed Google Chrome Dinosaur Game plugin versions up to 1.1.0Stored Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-11-26
WordPressPure CSS Circle Progress Bar plugin <= 1.2Stored Cross-Site Scripting (XSS)Critical (Unauthenticated attackers can inject malicious scripts)View or DownloadUNDERCODE2024-11-26
WordPressUp to and including 1.1.6Reflected Cross-Site Scripting (XSS)Medium (CVSS: 6.1)View or DownloadUNDERCODE2024-11-26
WordPressTheater for WordPress <= 0.18.6.2Reflected Cross-Site Scripting (XSS)MediumView or DownloadUNDERCODE2024-11-26
Android(Not specified)Local Privilege Escalation through Screen CaptureCriticalView or DownloadUNDERCODE2024-11-26
Zoho ManageEngine Exchange Reporter Plus5714 and belowAuthenticated SQL injectionCriticalView or DownloadUNDERCODE2024-11-26
Jewel Theme Master Addons for ElementorAll versions up to 2.0.5.4.1 (uncertain about earlier versions)Missing AuthorizationCriticalView or DownloadUNDERCODE2024-11-26
HarmonyOS (based on source)Not specifiedMissing permission check in applyCustomDescription of SaveUi.javaHigh (Local Information Disclosure)View or DownloadUNDERCODE2024-11-26
KiviCareUp to 3.6.2Authorization Bypass Through User-Controlled KeyCriticalView or DownloadUNDERCODE2024-11-26
Keycloak Connector Server< 2.5.5Reflected XSSModerateView or DownloadUNDERCODE2024-11-26

sigstore-java

v1.0.0 (patched in v1.1.0)

Incomplete verification in KeylessVerifier.verify()

Critical

View or DownloadUNDERCODE2024-11-26
AndroidNot specified (All versions potentially affected)Confused Deputy in PrintManagerService.javaMediumView or DownloadUNDERCODE2024-11-26
Qualcomm Snapdragon FirmwareAllCWE-835 (Loop or Recursion Vulnerability)View or DownloadUNDERCODE2024-11-26
Qualcomm Multi-mode Call ProcessorNot Applicable (Affects All Versions)Denial-of-Service (DoS)MediumView or DownloadUNDERCODE2024-11-26

Unknown (reference to CWE-787 suggests Out-of-bounds Write)

Unknown (severity cannot be determined from this blog post)View or DownloadUNDERCODE2024-11-26
UkrSolution Barcode Scanner with Inventory & Order ManagerCriticalView or DownloadUNDERCODE2024-11-26
Lobe ChatBefore 1.19.13Unauthorized SSRFCritical (CVSS: 9.0)View or DownloadUNDERCODE2024-11-26
AndroidNot specified (all versions potentially affected)Out-of-bounds write due to missing bounds checkCritical (allows remote code execution)View or DownloadUNDERCODE2024-11-26
IrfanViewAll versions (unaffected versions not specified)DXF file parsing out-of-bounds read leading to RCECriticalView or DownloadUNDERCODE2024-11-26
IrfanViewAll versions (unaffected versions not yet identified)Out-of-bounds read in DXF file parsing leading to RCECriticalView or DownloadUNDERCODE2024-11-26
IrfanViewAll versions (unaffected version not specified yet)Out-of-Bounds Read Remote Code Execution (DXF File Parsing)CriticalView or DownloadUNDERCODE2024-11-26
CentreonAll versions before 22.04.24, 22.10.22, 23.04.18, 23.10.12, and 24.04.0 (not mentioned in the article)SQL Injection in the updateServiceHost functionCritical (allows remote code execution)View or DownloadUNDERCODE2024-11-26
Centreon WebAll versions before the fixes mentioned belowSQL Injection leading to Remote Code ExecutionCriticalView or DownloadUNDERCODE2024-11-26
Dell PowerProtect DDBefore 7.7.5.50Exposure of Sensitive Information to Unauthorized ActorLow (CVSS: 3.1)View or DownloadUNDERCODE2024-11-26
Dell PowerProtect Data DomainPrior to 8.1.0.0, 7.13.1.10, 7.10.1.40, and 7.7.5.50Escalation of Privilege (EoP)Critical (CVSS score details not provided)View or DownloadUNDERCODE2024-11-26
Project Worlds Free Download Online Shopping SystemAll versions up to 192.168.1.88 (unclear if specific to this IP or a version range)SQL injectionCritical (CVSS score: 5.3 MEDIUM)View or DownloadUNDERCODE2024-11-26
ManageEngine ADAudit PlusBelow 8121SQL Injection (CVE-2024-5608)Critical (CVSS score: 8.3)View or DownloadUNDERCODE2024-11-26
emqx NeuronUp to 2.10.0Buffer OverflowCritical (CVSS v4.0: MEDIUM)View or DownloadUNDERCODE2024-11-26
E-Health Care System1.0SQL InjectionCriticalView or DownloadUNDERCODE2024-11-26
GitLab CE/EE16.0 to 17.3.6, 17.4 to 17.4.3, 17.5 to 17.5.1 (Fixed in 17.3.7, 17.4.4, 17.5.2)Unauthorized access to Kubernetes agent (CVE-2024-9693)High (CVSS score: 8.5)View or DownloadUNDERCODE2024-11-26
Python0.1.13Credential HarvestingHighView or DownloadUNDERCODE2024-11-25
Linux KernelNot specifiedOut-of-memory access in dvbdevHigh (CVSS score not provided)View or DownloadUNDERCODE2024-11-25
MLflowAffected versions are not explicitly specified.Excessive directory permissionsHighView or DownloadUNDERCODE2024-11-25
IrfanViewAll versionsHeap-based buffer overflow in JPM file parsingCriticalView or DownloadUNDERCODE2024-11-25
IrfanViewAll versionsDJVU File Parsing Use-After-Free Remote Code ExecutionCriticalView or DownloadUNDERCODE2024-11-25
IrfanViewAllHeap-based Buffer Overflow Remote Code ExecutionCriticalView or DownloadUNDERCODE2024-11-25
PDF File Parsing Out-Of-Bounds Read Information DisclosureLOWView or DownloadUNDERCODE2024-11-25
IrfanViewAll versions (unaffected versions not yet disclosed)Out-of-Bounds Read Remote Code Execution (RCE)CriticalView or DownloadUNDERCODE2024-11-25
IrfanViewAll versionsOut-of-Bounds Write in JPM File ParsingCriticalView or DownloadUNDERCODE2024-11-25
IrfanViewAll versionsDXF file parsing memory corruption leading to remote code executionCriticalView or DownloadUNDERCODE2024-11-25
IrfanViewAll versionsOut-of-bounds read during DWG file parsing leading to Remote Code Execution (RCE)Critical (CVSS score: 7.8)View or DownloadUNDERCODE2024-11-25
IrfanViewAll versions (not specified)Out-of-bounds write during ARW file parsingCritical (CVSS score: 7.8)View or DownloadUNDERCODE2024-11-25
IrfanViewAll versions (unaffected versions not specified)Out-of-bounds write during JPM file parsing (CVE-2024-11517)Critical (RCE)View or DownloadUNDERCODE2024-11-25
IrfanViewAll versions (unaffected versions not specified yet)DWG File Parsing Memory Corruption RCECriticalView or DownloadUNDERCODE2024-11-25
IrfanViewAll versions (unaffected versions not yet identified)DXF File Parsing Use-After-Free Remote Code ExecutionCriticalView or DownloadUNDERCODE2024-11-25
WordPressImagePress – Image Gallery plugin versions up to 1.2.2 (inclusive)Cross-Site Request Forgery (CSRF)Medium (CVSS v3 score not provided)View or DownloadUNDERCODE2024-11-25
IrfanViewAll versionsDXF File Parsing Memory Corruption Remote Code ExecutionCritical (CVSS: 7.8)View or DownloadUNDERCODE2024-11-25
Keycloak26 and earlierDenial-of-Service (DoS)CriticalView or DownloadUNDERCODE2024-11-25
Keycloak!ERROR! B2967 -> Formula Error: Unexpected ,Denial-of-Service (DoS)ModerateView or DownloadUNDERCODE2024-11-25
deno_docAll versions before a fix is releasedCross-site Scripting (XSS)LowView or DownloadUNDERCODE2024-11-25
Keycloak!ERROR! B2969 -> Formula Error: Unexpected ,Sensitive data exposureHighView or DownloadUNDERCODE2024-11-25
Dell SmartFabric OS10 Software10.5.3.x, 10.5.4.x, 10.5.5.x, 10.5.6.xImproper Neutralization of Special Elements (Command Injection)HIGHView or DownloadUNDERCODE2024-11-25
Keycloak!ERROR! B2971 -> Formula Error: Unexpected ,Sensitive data exposure during build processModerateView or DownloadUNDERCODE2024-11-25
Keycloak!ERROR! B2972 -> Formula Error: Unexpected ,Path TraversalLowView or DownloadUNDERCODE2024-11-25
Keycloak!ERROR! B2973 -> Formula Error: Unexpected ,Inefficient Regular Expression ComplexityView or DownloadUNDERCODE2024-11-25
Xiaomi Router AX9000Not specifiedPost-authorization Command InjectionMEDIUM (CVSS 3.1 base score: 6.4)View or DownloadUNDERCODE2024-11-25
IrfanViewAll versions (unspecified)Out-of-Bounds Write during SID File Parsing (Remote Code Execution)CriticalView or DownloadUNDERCODE2024-11-25
1000 Projects Beauty Parlour Management System1.0SQL InjectionCriticalView or DownloadUNDERCODE2024-11-25
Tungsten Automation Power PDFNot specifiedJPF File Parsing Out-Of-Bounds Write Remote Code ExecutionCriticalView or DownloadUNDERCODE2024-11-25
IrfanViewAll versions (unaffected versions not specified)WSQ File Parsing Out-Of-Bounds Write Remote Code ExecutionCriticalView or DownloadUNDERCODE2024-11-25
Tungsten Automation Power PDFNot specifiedPSD File Parsing Out-Of-Bounds Write Remote Code ExecutionCritical (CVSS score not provided, but the description indicates remote attackers can execute arbitrary code)View or DownloadUNDERCODE2024-11-25
Tungsten Automation Power PDFNot specifiedStack-based buffer overflow in TIF file parsingCriticalView or DownloadUNDERCODE2024-11-25
WordPressHUSKY - Products Filter Professional for WooCommerce plugin versions up to 1.3.6.3Reflected Cross-Site Scripting (XSS)MediumView or DownloadUNDERCODE2024-11-25
W3speedsterUp to 7.25Cross-Site Request Forgery (CSRF)CriticalView or DownloadUNDERCODE2024-11-25
Vivwebs Dynamic WidgetsUp to 1.6.4Cross-Site Request Forgery (CSRF)Medium (based on CVSS v3.1 score)View or DownloadUNDERCODE2024-11-25
XSS in error messagesLow (user-controlled input needed in error message)View or DownloadUNDERCODE2024-11-25

Taurus Multi-Party Signature Library

Not specified

Critical (both vulnerabilities)

View or DownloadUNDERCODE2024-11-25
Linux KernelNot specified (all versions potentially affected)Race condition in i40e driverModerate (CVSS score not provided)View or DownloadUNDERCODE2024-11-25
lxml (HTML cleaning functionality)Before 0.4.0Improper context handling for special HTML tags (SVG, Math, Noscript)Critical (CVSS score likely high)View or DownloadUNDERCODE2024-11-25
AndroidNot specifiedImproper Input Validation in CompanionDeviceManagerService.java (CVE-2024-0022)HighView or DownloadUNDERCODE2024-11-25
Linux KernelNot specifiedImproper reference count handling for CPU device nodes (RISC-V)Medium (CVSS v3 base score: 5.5)View or DownloadUNDERCODE2024-11-25
Linux KernelNot specified (likely impacts multiple versions)Improper resource handling in iwlwifi driver during AP stop/startMedium (CVSS 3.x Base Score: 5.5)View or DownloadUNDERCODE2024-11-25
Linux KernelNot specified (requires kernel update)Incorrect NULL vs IS_ERR() check in drm/tegra driverLow (CVSS v3 Base Score: 5.5)View or DownloadUNDERCODE2024-11-25
Linux KernelUnaffected versions not listed (potentially all before the fix)Out-of-bounds memory access in virtio_net driverHIGH (CVSS 3.1 base score: 7.1)View or DownloadUNDERCODE2024-11-25
emqx neuronUp to 2.10.0Information Disclosure (CVE-2024-10965)MEDIUMView or DownloadUNDERCODE2024-11-23
AMTT Hotel Broadband Operation SystemUp to 3.0.3.151204Cross-site scripting (XSS)Medium (CVSS score: 5.3)View or DownloadUNDERCODE2024-11-23
code-projects Task Manager1.0SQL InjectionCriticalView or DownloadUNDERCODE2024-11-23
Job Recruitment1.0Cross-site Scripting (XSS)MEDIUMView or DownloadUNDERCODE2024-11-23
WordPress Plugin - CTT Expresso para WooCommerceUp to 3.2.12 (inclusive)Sensitive Information ExposureMediumView or DownloadUNDERCODE2024-11-23
Code4Berry Decoration Management System1.0Improper Access ControlCriticalView or DownloadUNDERCODE2024-11-23
Dropbox DesktopAllMark-of-the-Web BypassCriticalView or DownloadUNDERCODE2024-11-23
WordPressFundEngine plugin versions up to and including 1.7.0Privilege EscalationCriticalView or DownloadUNDERCODE2024-11-23
Code4Berry Decoration Management System1.0Permission Issues (User Handler - /decoration/admin/userregister.php)CriticalView or DownloadUNDERCODE2024-11-23
Linux KernelNot specified (potentially all versions before the fix)mctp i2c NULL header address handlingMedium (CVSS score not provided)View or DownloadUNDERCODE2024-11-22
All versions before the fixMemory LeakMedium (CVSS score to be determined)View or DownloadUNDERCODE2024-11-22
Linux KernelNot specifiedNull pointer dereference in firmware:qcom:scmMedium (CVSS score not provided)View or DownloadUNDERCODE2024-11-22
MBed OS6.16.0Buffer Overflow (CVE-2024-48982)CriticalView or DownloadUNDERCODE2024-11-22
Code4Berry Decoration Management System1.0User Permission Handling Vulnerability (CVE-2024-11486)MediumView or DownloadUNDERCODE2024-11-22
Mbed OS6.16.0Buffer Overflow (CVE-2024-48986)CriticalView or DownloadUNDERCODE2024-11-22
Tailoring Management System1.0 (Unaffected versions not specified)SQL Injection through /expcatedit.php argument manipulation (id)Medium (CVSS v4.0 Base Score: 5.3)View or DownloadUNDERCODE2024-11-22
Code4Berry Decoration Management System1.0SQL Injection (CVE-2024-11487)CriticalView or DownloadUNDERCODE2024-11-22
1000 Projects Bookstore Management System1.0SQL InjectionCriticalView or DownloadUNDERCODE2024-11-22
AVL-DiTEST-DiagDev libdoip1.0.0Null Pointer Dereference in DoIPConnection::reactOnReceivedTcpMessageMediumView or DownloadUNDERCODE2024-11-22
idcCMS1.60Cross-Site Scripting (XSS)MediumView or DownloadUNDERCODE2024-11-22
Linux KernelNot specified (all versions with vulnerable bnxt_re driver)Out-of-bounds memory accessModerate (CVSS v3 base score: 5.5)View or DownloadUNDERCODE2024-11-22
smol-toml<1.3.1Stack OverflowLowView or DownloadUNDERCODE2023-11-13
TornadoPrior to 6.4.2HTTP Cookie Parsing DoSHighView or DownloadUNDERCODE2024-11-22
SentryAll versions before next releasePotential Client ID and Secret exposure in error messageLowView or DownloadUNDERCODE2024-11-22
UAMQP C libraryUnaffected versions not specifiedRemote Code Execution (RCE)Critical (CVSS score likely high)View or DownloadUNDERCODE2024-11-22
WordPressUp to and including 1.7.2Stored Cross-Site Scripting (XSS)MediumView or DownloadUNDERCODE2024-11-22
java_shop1.0File Upload VulnerabilityNot yet rated by NISTView or DownloadUNDERCODE2024-11-22
AndroidNot specified (all versions before August 2024 patch)Logic error in OwnersData.javaHighView or DownloadUNDERCODE2024-11-22
LibreNMSNot specifiedReflected XSS (CVE-2024-51496)MediumView or DownloadUNDERCODE2024-11-22
ManageEngine ADAudit PlusBelow 8110Authenticated SQL Injection (CVE-2024-36518)HighView or DownloadUNDERCODE2024-11-22
Zyxel P-6101C ADSL modemP-6101CSA6AP_20140331Improper AuthenticationHIGHView or DownloadUNDERCODE2024-11-22
LibreNMSAll versions before 24.10.0Reflected XSSCriticalView or DownloadUNDERCODE2024-11-22
WordPressBreakdance versions up to 1.7.2 (inclusive)Unauthorized Access of DataMediumView or DownloadUNDERCODE2024-11-22
java_shop1.0Incorrect Access ControlCritical (CVSS details not yet available)View or DownloadUNDERCODE2024-11-22
SourceCodester Student Record Management System1.0Memory CorruptionCriticalView or DownloadUNDERCODE2024-11-22
Querydsl5.1.0SQL/HQL InjectionHighView or DownloadUNDERCODE2024-11-22
Not specified (versions 3.2.0 through 4.1.3 are vulnerable)Server-Side Request Forgery (SSRF)High (CVSS score: 7.5)View or DownloadUNDERCODE2024-11-22
SFTPGoAll versionsArbitrary Command ExecutionCriticalView or DownloadUNDERCODE2023-10-24
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHigh (CVSS Score: 7.8)View or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHigh (CVSS Score: 7.8)View or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
Luxion KeyShotNot specifiedRemote Code Execution (RCE) through jt file parsingCritical (CVSS score: 7.8)View or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
Luxion KeyShotNot specifiedStack overflow due to improper validation in 3DS file parsingCritical (CVSS score: 7.8)View or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code Execution (RCE)High (CVSS Score: 7.8)View or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHigh (CVSS Score: 7.8)View or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHigh (CVSS Score: 7.8)View or DownloadUNDERCODE2024-11-22
Adobe InDesign(not specified)Information DisclosureLowView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-18
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHigh (CVSS Score: 7.8)View or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-22
Linux KernelNot specifiedDivision by zero error in v4l2-tpgMediumView or DownloadUNDERCODE2024-11-22
Linux KernelNot specified (all versions potentially affected)Slab-use-after-free in ksmbd_smb2_session_createHigh (CVSS score: 7.8)View or DownloadUNDERCODE2024-11-22
Linux kernelNot specifiedSlab-use-after-free in smb3_preauth_hash_rsp functionHIGH (CVSS v3 score not provided)View or DownloadUNDERCODE2024-11-22
Linux KernelNot specified (all versions vulnerable before a fix)SCTP Chunk Size Validation Error (CVE-2024-50299)Not officially rated by NIST (NVD) yetView or DownloadUNDERCODE2024-11-22
Linux KernelNot specifiedBuffer overflow in amdgpu_debugfs_gprwave_read() functionMedium (CVSS v2: 4.6, CVSS v3: 7.8)View or DownloadUNDERCODE2024-11-22
Linux KernelNot specified (all versions potentially affected)Uninitialized use of regulator_config in rtq2208 driverHigh (CVSS score not yet available from NVD)View or DownloadUNDERCODE2024-11-22
SourceCodester Student Record Management System1.0Stack-based buffer overflowCriticalView or DownloadUNDERCODE2024-11-22
AndroidNot specified (all versions before March 2024 security patch)Local Information Disclosure (exercise route data)HighView or DownloadUNDERCODE2024-11-22
AndroidNot specifiedIncorrect tag used during device policy serialization (CVE-2024-0047)High (Potential for DoS)View or DownloadUNDERCODE2024-11-22
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-21
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-21
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-21
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHigh (CVSS Score: 7.8)View or DownloadUNDERCODE2024-11-21
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-21
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-21
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-21
IrfanViewAffected versions prior to 4.70Remote Code Execution (RCE)High (CVSS Score: 7.8)View or DownloadUNDERCODE2024-11-21
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHigh (CVSS Score: 7.8)View or DownloadUNDERCODE2024-11-21
IrfanView4.69 and earlierRemote Code ExecutionHighView or DownloadUNDERCODE2024-11-21
IrfanViewAffected versions prior to 4.70Remote Code ExecutionHighView or DownloadUNDERCODE2024-11-21
Linux Kernel(Not specified in the provided information)Improper access control in raw_copy_{to,from}_user() functionsCritical (CVSS score not yet available)View or DownloadUNDERCODE2024-11-21
Linux KernelNot specified (all versions potentially affected)Use-after-free in USB serial io_edgeport codeMedium (CVSS v2 score: 4.6, CVSS v3 score: 7.8)View or DownloadUNDERCODE2024-11-21
Linux KernelAll versions before the fix for CVE-2024-50265 are vulnerable.Null pointer dereference in ocfs2_xa_remove() functionCriticalView or DownloadUNDERCODE2024-11-21
Linux Kernel(Not specified in the provided information)Flaw in sch_cake's flow accounting logicMediumView or DownloadUNDERCODE2024-11-21
Linux KernelUnaffected versions not specifiedUse-After-Free in vsock/virtio (CVE-2024-50264)Critical (CVSS v3 score details not provided)View or DownloadUNDERCODE2024-11-21
Linux KernelNot specified (all versions vulnerable before fix)Double free of TX skbCriticalView or DownloadUNDERCODE2024-11-21
Oracle Agile PLM Framework9.3.6Information DisclosureHIGH (CVSS Score: 7.5)View or DownloadUNDERCODE2024-11-21
Opencast13 and 14Infinite loop with Elasticsearch queriesCriticalView or DownloadUNDERCODE2024-11-20
LitestarAll versionsDenial of Service (DoS)CriticalView or DownloadUNDERCODE2024-11-20
Microsoft SharePoint ServerNot specifiedRemote Code Execution (RCE)Critical (CVSS score: 7.2)View or DownloadUNDERCODE2024-11-20
Linux KernelNot specified (potential impact on all versions)Information DisclosureLowView or DownloadUNDERCODE2024-11-20
Linux KernelNot specified (likely affects multiple versions)Firmware crash due to invalid peer nss value in association requestModerate (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-11-20
Qualcomm Multiple ProductsVariousMultiple VulnerabilitiesVariesView or DownloadUNDERCODE2024-11-20
Linux KernelNot specified (all versions potentially affected)io_uring overflow handling flawLowView or DownloadUNDERCODE2024-11-20
Linux KernelNot specifiedMemory access issue in drm/amd/display codeModerate (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-11-20
cert-managerAll versions since v0.1.0Denial-of-service (DoS)MediumView or DownloadUNDERCODE2024-11-20
7-ZipAffected versions prior to 24.07Remote Code ExecutionHigh (CVSS Score: 7.8)View or DownloadUNDERCODE2024-11-20
N/AN/AN/AN/AView or DownloadUNDERCODE2024-11-20
Undercoding (mentioned in the article but not a security vulnerability)N/A (Undercoding is not a security vulnerability)View or DownloadUNDERCODE2024-11-20
Linux KernelNot specified (all versions potentially affected)Race condition in ntfs3 driverModerate (CVSS v3 score: 5.5)View or DownloadUNDERCODE2024-11-20
Qualcomm devices(not specified)(not specified)(not specified)View or DownloadUNDERCODE2024-11-20
Qualcomm(see article for specific versions)Potential Remote CompromiseCriticalView or DownloadUNDERCODE2024-11-20
D-Link DI-803316.07.26A1Buffer Overflow (CVE-2024-52759)Critical (CVSS v3 score: 9.8)View or DownloadUNDERCODE2024-11-20
Monoprice Select Mini V2V37.115.32Improper input validation in printing filesMedium (CVSS 3.x Base Score: 5.5)View or DownloadUNDERCODE2024-11-20
WordPress Testimonials Widget PluginUp to and including 4.0.4Stored Cross-Site Scripting (XSS)Unlisted (CVSS score not provided)View or DownloadUNDERCODE2024-11-20
Tenda AC6v2.0 v15.03.06.50Buffer overflow in function "fromSetSysTime" (CVE-2024-52714)Critical (CVSS v3 score: 9.8)View or DownloadUNDERCODE2024-11-20
Linux KernelNot specifiedInteger overflow in drm/amd/display codeModerateView or DownloadUNDERCODE2024-11-20
Cosmos SDKcosmossdk.io/math versions <= math/v1.3.0Mismatched bit-length validation in sdk.Int and sdk.DecHighView or DownloadUNDERCODE2024-11-20
MoodleInsecure Direct Object Reference (IDOR)ModerateView or DownloadUNDERCODE2024-11-20
django CMSBefore 4.0Cross-site Scripting (XSS)ModerateView or DownloadUNDERCODE2024-11-20
Linux KernelNot specified (likely affects multiple versions)Improper synchronization when accessing superblock bufferModerate (CVSS v3 base score: 5.5)View or DownloadUNDERCODE2024-11-20
Linux KernelNot specified (potentially all versions with aforementioned configurations enabled)Out-of-bounds read (based on CVE description)Medium (according to CVE details, no exploit exists)View or DownloadUNDERCODE2024-11-20
N/AN/AN/AN/AView or DownloadUNDERCODE2024-11-20
Buffer overflow in `amdgpu_dm` initializationUnknown (CVSS score not yet available)View or DownloadUNDERCODE2024-11-20
Cisco Identity Services Engine (ISE)All versions (at the time of publishing)Cross-site Scripting (XSS)Medium (CVSS score: 6.1)View or DownloadUNDERCODE2024-11-20
Cisco Identity Services Engine (ISE)
All versions (at the time of publication)
Cross-site Scripting (XSS)
MEDIUM
View or DownloadUNDERCODE2024-11-20
Cisco Identity Services Engine (ISE)
All versions (at the time of publication)
Cross-site Scripting (XSS)
MEDIUM
View or DownloadUNDERCODE2024-11-20
Cisco ISEAll versions (at the time of publishing)XXE (CVE-2024-20531)MEDIUM (CVSS score: 5.5)View or DownloadUNDERCODE2024-11-20
Linux KernelAll versions before 6.11.7Null Pointer Dereference (CVE-2024-53050)MediumView or DownloadUNDERCODE2024-11-20
Cisco Identity Services Engine (ISE)All versions (at the time of publication)Cross-site Scripting (XSS)MEDIUMView or DownloadUNDERCODE2024-11-20
Linux kernelNot specifiedNull pointer dereference in `intel_hdcp_get_capability`Medium (CVSS score not yet available)View or DownloadUNDERCODE2024-11-20
Anton Hoelstad WP Quick Setup<= 2.0Unrestricted Upload of File with Dangerous TypeCriticalView or DownloadUNDERCODE2024-11-20
Mindstien Technologies My Geo Posts FreeAll versions up to 1.2 (inclusive)Deserialization of Untrusted DataCriticalView or DownloadUNDERCODE2024-11-20
WordPress Video Robot - The Ultimate Video ImporterAll versions up to 1.20.0SQL InjectionCriticalView or DownloadUNDERCODE2024-11-20
Lis Video GalleryUp to 0.2.1Deserialization of Untrusted DataCriticalView or DownloadUNDERCODE2024-11-20
Post SMTPAll versions up to 2.9.9SQL InjectionCriticalView or DownloadUNDERCODE2024-11-20
GLPIAll versions before 10.0.17Reflected XSSMediumView or DownloadUNDERCODE2024-11-20
GLPIAll versions before 10.0.17SQL InjectionHigh (CVSS score: 8.1)View or DownloadUNDERCODE2024-11-20
code-projects Job Recruitment1.0SQL InjectionCriticalView or DownloadUNDERCODE2024-11-20
Saso Nikolov Event Tickets with Ticket Scannern/a - 2.3.11Improper Neutralization of Special Elements Used in a Template EngineCriticalView or DownloadUNDERCODE2024-11-20
3.1Heap-Overflow Vulnerability in DCERPC ProtocolCRITICALView or DownloadUNDERCODE2024-11-20
LibreNMSAll versions before 24.10.0Stored Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-11-20
LibreNMSAll versions before 24.10.0Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-11-20
MoodleAll versions before 4.5.0-rc2 (unconfirmed)Improper AuthorizationMedium (CVSS v2 score: 5.0, CVSS v3 score: 6.5)View or DownloadUNDERCODE2024-11-20
LibreNMSAll versions before 24.10.0Stored XSSMediumView or DownloadUNDERCODE2024-11-20
LibreNMSUnaffected versions not listed (all versions before 24.10.0 likely vulnerable)Stored Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-11-20
MoodleVersions before 4.5.0-rc2 are affected (unclear which specific versions)Improper AuthorizationMedium (CVSS v2 score: 6.4, CVSS v3 score: 4.3)View or DownloadUNDERCODE2024-11-20
LibreNMSAll versions before 24.10.0Stored XSSCriticalView or DownloadUNDERCODE2024-11-20
Urchenko Drozd – Addons for ElementorUp to 1.1.1Stored XSS (Cross-site Scripting) (CVE-2024-52425)Medium (CVSS details not specified)View or DownloadUNDERCODE2024-11-20
MoodleAll versions before 4.1.14, 4.2.11, 4.3.8, 4.4.4 (not exhaustive)Information DisclosureMediumView or DownloadUNDERCODE2024-11-20
WordPressLinear plugin <= 2.7.11Cross-site Scripting (XSS)Medium (CVSS details not specified)View or DownloadUNDERCODE2024-11-20
LibreNMSAll versions before 24.10.0Stored Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-11-20
LibreNMSUnaffected versions not listed (all versions before 24.10.0 likely vulnerable)Stored XSSCriticalView or DownloadUNDERCODE2024-11-20
LibreNMSAll versions before 24.10.0Stored Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-11-20
SourceCodester Online Eyewear Shop1.0Cross-Site Scripting (XSS)MediumView or DownloadUNDERCODE2024-11-20
WindowsSecureID Software Token for Microsoft WindowsRemote Code ExecutionHighView or DownloadUNDERCODE2024-11-19
eDrawings ViewerAll versions from SOLIDWORKS 2024 through 2025 (unspecified)Heap-based buffer overflow and uninitialized variable vulnerabilities in X_B and SAT file parsingCritical (CVSS: 7.8)View or DownloadUNDERCODE2024-11-19
1000 Projects Beauty Parlour Management System1.0SQL InjectionCriticalView or DownloadUNDERCODE2024-11-19
WordPressWP Activity Log plugin versions up to 5.2.1Stored Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-11-19
GLPIAll versions before 10.0.17 (vulnerable)Access Control Bypass (CVE-2024-45611)MediumView or DownloadUNDERCODE2024-11-19
WordPressTripetto plugin versions up to 8.0.3Stored Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-11-19
1000 Projects Beauty Parlour Management System1.0SQL InjectionCriticalView or DownloadUNDERCODE2024-11-19
1000 Projects Portfolio Management System MCA1.0SQL injectionCriticalView or DownloadUNDERCODE2024-11-19
Farmacia1.0 (all versions likely affected)Cross-Site Scripting (XSS)MediumView or DownloadUNDERCODE2024-11-19
Adobe Audition23.6.9, 24.4.6 and earlierOut-of-bounds read vulnerabilityMedium (CVSS: 5.5)View or DownloadUNDERCODE2024-11-19
Microsoft VHDX(Not specified)Denial-of-Service (DoS)Medium (CVSS score: 5.9)View or DownloadUNDERCODE2024-11-19
GLPIAll versions before 10.0.17Reflected XSS (CVE-2024-45609)Medium (CVSS v3.1 score: 6.5) - Though some sources list it as High (CVSS v2 score: 7.8)View or DownloadUNDERCODE2024-11-19
WordPressUp to and including 2.5.7Stored Cross-Site Scripting (XSS)MediumView or DownloadUNDERCODE2024-11-19
WindowsNot specifiedElevation of Privilege in USB Video Class System DriverMEDIUM (CVSS score: 6.8)View or DownloadUNDERCODE2024-11-19
Windows SMBv3 Server(not specified in this article)Remote Code Execution (RCE)High (CVSS score: 8.1)View or DownloadUNDERCODE2024-11-19
GLPIAll versions before 10.0.17Reflected Cross-Site Scripting (XSS)Pending analysis by NISTView or DownloadUNDERCODE2024-11-19
WordPress Plugin (The Music Player for Elementor)All versions up to 2.4.1Unauthorized modification of data (CVE-2024-10582)CriticalView or DownloadUNDERCODE2024-11-19
Remote Code ExecutionHigh (CVSS score: 8.8)View or DownloadUNDERCODE2024-11-19
Ceph RGW (civetweb)Not specifiedMultiple connection establishment to exhaust file descriptorsDenial-of-Service (DoS)View or DownloadUNDERCODE2024-11-19
Intel Server Board M10JNP2SB Family (exact versions not specified)Not specifiedImproper input validation in UEFI firmwareHigh (CVSS score: 7.5 - 8.7 depending on the version of CVSS used)View or DownloadUNDERCODE2024-11-19
Windows Registry Elevation of Privilege VulnerabilityHIGH (CVSS score: 7.5)View or DownloadUNDERCODE2024-11-19
ImageMagick, GraphicsMagickBefore 1.3.24 (both platforms)Arbitrary Code ExecutionNot specified (CVSS score likely available elsewhere)View or DownloadUNDERCODE2024-11-19
ImageMagickNot specified (versions before the fix are vulnerable)Out-of-bounds write via PDB fileMedium (CVSS v3 score: 6.5)View or DownloadUNDERCODE2024-11-19
LittleCMS (lcms or liblcms)Before 1.18beta2Multiple integer overflowsHigh (CVSS v2 score: 9.3)View or DownloadUNDERCODE2024-11-19
.NET Core9.0Denial of Service (DoS)High (CVSS v3 base score: 7.5)View or DownloadUNDERCODE2024-11-19
tsMuxernightly-2024-05-12-02-01-18 (specific version only)Heap-based buffer under-readNot specified (CVSS score not provided)View or DownloadUNDERCODE2024-11-19
Improper Access Control in UEFI firmwareNot yet analyzed by NVDView or DownloadUNDERCODE2024-11-19
GentleSource AppointmindAll versions before 4.0.0Cross-Site Request Forgery (CSRF) leading to Stored XSSHigh (based on CVE details)View or DownloadUNDERCODE2024-11-19
rclonev1.68.1Insecure Handling of SymlinksHighView or DownloadUNDERCODE2024-11-19
Siemens Tecnomatix Plant SimulationAll versions before V2302.0018 and V2404.0007Out-of-bounds read vulnerability in WRL file parsingHigh (CVSS v3.1 score: 7.8)View or DownloadUNDERCODE2024-11-19
Siemens Tecnomatix Plant Simulation(not specified)Remote Code Execution (RCE) through WRL file parsingHigh (CVSS v3 score: 7.8)View or DownloadUNDERCODE2024-11-19
Siemens Tecnomatix Plant SimulationNot specifiedRemote Code Execution (RCE) through WRL file parsingView or DownloadUNDERCODE2024-11-19
Cesanta Mongoose Web Server7.14Use of Out-of-range Pointer OffsetMediumView or DownloadUNDERCODE2024-11-19
Cesanta Mongoose Web Server7.14Improper Neutralization of DelimitersMedium (CVSS 3.1 score: 4.0)View or DownloadUNDERCODE2024-11-19
Cesanta Mongoose Web Serverv7.14Out-of-range Pointer OffsetMediumView or DownloadUNDERCODE2024-11-19
Cesanta Mongoose Web Server7.14Use of Out-of-range Pointer OffsetMediumView or DownloadUNDERCODE2024-11-19
Cesanta Mongoose Web Server7.14Use of Out-of-range Pointer OffsetHigh (CVSS Score: 8.5)View or DownloadUNDERCODE2024-11-19
EyouCMS1.51Path TraversalMediumView or DownloadUNDERCODE2024-11-19
Cesanta Mongoose Web Server7.14Integer Overflow or WraparoundHigh (CVSS v2 score: 7.8, CVSS v3 score: 7.5)View or DownloadUNDERCODE2024-11-19
Craft CMSPrior to 4.12.2 and 5.4.3Remote Code Execution (RCE) via Twig Server-Side Template Injection (SSTI)HighView or DownloadUNDERCODE2024-11-19
Cesanta Mongoose Web Server7.14Improper Neutralization of DelimitersMediumView or DownloadUNDERCODE2024-11-19
Cesanta Mongoose Web Server7.14Use of Out-of-range Pointer OffsetMedium (CVSS score: 4.3)View or DownloadUNDERCODE2024-11-19
Craft CMSAll versions before 5.4.9 and 4.12.8Information DisclosureHighView or DownloadUNDERCODE2024-11-19
Apache Kafka2.3.0 - 3.5.2, 3.6.2, 3.7.0Improper Privilege ManagementHighView or DownloadUNDERCODE2023-10-17
Linux kernelNot specified (likely affects multiple versions)Unbalanced locking in pc_clock_settime()Moderate (CVSS v3: 5.5, CVSS v4: 6.8)View or DownloadUNDERCODE2024-11-19
ImageMagickNot specifiedDenial-of-Service (DoS) via crafted PSD fileMedium (CVSS score: 6.5)View or DownloadUNDERCODE2024-11-19
Security Center application (vendor not specified)All versions (not specified)HTML InjectionMedium (CVSS 3.x Base Score: 5.9)View or DownloadUNDERCODE2024-11-19
Linux KernelNot specifiedNamespace copy issue (rbtree removal)Not provided (CVSS details likely missing from provided text)View or DownloadUNDERCODE2024-11-19
Linux KernelNot specifiedMemory Corruption in RDMA/bnxt_re driverNot specified (CVSS score not provided)View or DownloadUNDERCODE2024-11-19
Linux kernelNot specifiedImproper locking during sub buffer order change (CVE-2024-50207)Medium (CVSS score not explicitly mentioned)View or DownloadUNDERCODE2024-11-19
WordPressRoyal Elementor Addons and Templates plugin versions up to 1.7.1001Stored Cross-Site Scripting (XSS)Medium (CVSS 3.1 Base Score: 6.4)View or DownloadUNDERCODE2024-11-19
OpenEMR7.0.1Stored XSSHigh (CVSS score not yet available)View or DownloadUNDERCODE2024-11-19
VK All in One Expansion UnitPrior to 9.100.1.0Cross-site scripting (XSS)Medium (CVSS v3 score: 4.8)View or DownloadUNDERCODE2024-11-19
Linux KernelNot specified (potentially all versions using nilfs2)Improper Error Handling in nilfs2Not yet assigned a CVSS score (as of November 19, 2024)View or DownloadUNDERCODE2024-11-19
WordPressAFI plugin up to and including 1.92.0Reflected Cross-Site Scripting (XSS)Medium (CVSS not yet analyzed)View or DownloadUNDERCODE2024-11-19
WordPressRoyal Elementor Addons and Templates plugin versions up to 1.7.1001Stored Cross-Site Scripting (XSS)MediumView or DownloadUNDERCODE2024-11-19
calibre-webNot specifiedCross-site Scripting (XSS)MediumView or DownloadUNDERCODE2024-11-19
WordPressUp to 2.9.5Local File Inclusion (LFI)Critical (CVSS 3.x Base Score: 9.8)View or DownloadUNDERCODE2024-11-19
WordPressMultiManager WP – Manage All Your WordPress Sites Easily plugin (up to 1.0.5)Authentication BypassCriticalView or DownloadUNDERCODE2024-11-19
WordPressRoyal Elementor Addons and Templates plugin versions up to 1.7.1001Stored Cross-Site Scripting (XSS)MediumView or DownloadUNDERCODE2024-11-19
Thunderbird< 128.4.3 and < 132.0.1Disclosure of plaintext in OpenPGP encrypted messagesNot specified (CVSS score likely available elsewhere)View or DownloadUNDERCODE2024-11-19
DolibarrVersions before 'develop' branchImproper AuthorizationMediumView or DownloadUNDERCODE2024-11-19
HarborUnaffected versions not specified (all versions before 2.5.2 likely vulnerable)Improper AuthorizationNot available in provided resourcesView or DownloadUNDERCODE2024-11-19
calibre-webUnknownImproper Access ControlLowView or DownloadUNDERCODE2024-11-19
HarborNot specifiedImproper AuthorizationHigh (CVSS: 7.4)View or DownloadUNDERCODE2024-11-19
SourceCodester Best Employee Management System1.0SQL InjectionMediumView or DownloadUNDERCODE2024-11-19
Harbor1.0 through 1.10.12, 2.0 through 2.4.2 and 2.5 through 2.5.1 (all versions before the fix)Improper AuthorizationHighView or DownloadUNDERCODE2024-11-19
Harbor(Unaffected versions not specified)Insecure Direct Object Reference (IDOR) - CVE-2022-31667High (CVSS details not yet available)View or DownloadUNDERCODE2024-11-19
PHPGurukul User Registration & Login and User Management System3.2Reflected Cross-Site Scripting (XSS)Not officially rated, but likely medium based on similar vulnerabilities.View or DownloadUNDERCODE2024-11-19
HarborAll versions before 2.5.2Insecure Direct Object Reference (IDOR)HighView or DownloadUNDERCODE2024-11-19
SourceCodester Best Employee Management System1.0 (all versions likely affected)SQL InjectionMedium (CVSS v3: 5.1)View or DownloadUNDERCODE2024-11-19
VIWIS LMS9.11Missing Authorization in Print HandlerCriticalView or DownloadUNDERCODE2024-11-19
phpipamAll versions before 1.4.7Cross-Site Scripting (XSS)LowView or DownloadUNDERCODE2024-11-19
WordPress (Hoo Addons for Elementor plugin)Up to 1.0.6Cross-Site Scripting (XSS)Not yet determined (CVSS information is undergoing analysis)View or DownloadUNDERCODE2024-11-18
Kashipara E-learning Management System Project1.0SQL InjectionCritical (CVSS v3 score: 9.8)View or DownloadUNDERCODE2024-11-18
WindowsMultiple versionsElevation of PrivilegeHighView or DownloadUNDERCODE2024-11-18
NTLM Hash Disclosure Spoofing Vulnerability (CVE-2024-43451)Medium (CVSS score: 6.5)View or DownloadUNDERCODE2024-11-18
Palo Alto Networks ExpeditionNot specifiedSQL Injection (CVE-2024-9465)Critical (CVSS score: 9.2)View or DownloadUNDERCODE2024-11-18
Nostromo nhttpd<= 1.9.6Directory TraversalCritical (Remote Code Execution)View or DownloadUNDERCODE2024-11-18
PTZOptics PT30X-SDI/NDI-xxBefore 6.3.40Insufficient Authentication (CVE-2024-8956)Critical (CVSS Score: 9.1)View or DownloadUNDERCODE2024-11-18
Palo Alto Networks ExpeditionAll versions before 1.2.96 (including 1.2.0)OS Command InjectionCRITICAL (CVSS score: 9.9)View or DownloadUNDERCODE2024-11-18
Roundcube WebmailBefore 1.5.7 and 1.6.x before 1.6.7XSS via SVG animate attributesMedium (CVSS score: 6.1)View or DownloadUNDERCODE2024-11-18
PTZOptics PT30X-SDI/NDI-xxBefore 6.3.40OS Command Injection (CVE-2024-8957)HIGH (CVSS: 7.2)View or DownloadUNDERCODE2024-11-18
View or DownloadUNDERCODE2024-11-18
9.0.0.M30Deserialization of untrusted data vulnerabilityCRITICALView or DownloadUNDERCODE2024-11-18
Metabase< 0.40.5 and < 1.40.5Local File Inclusion (LFI)CRITICALView or DownloadUNDERCODE2023-11-28
Windows KernelAllElevation of PrivilegeHIGHView or DownloadUNDERCODE2024-11-18
Palo Alto Networks ExpeditionAll versions before 1.2.92Missing AuthenticationCRITICAL (CVSS Score: 9.3)View or DownloadUNDERCODE2024-11-18
ScienceLogic SL1 (formerly EM7)All versions before 12.1.3, 12.2.3, and 12.3+Remote Code Execution (RCE) due to unspecified third-party component vulnerability (CVE-2024-9537)CRITICAL (CVSS v2: 9.8, CVSS v3: 9.3)View or DownloadUNDERCODE2024-11-18
RavpnMultiple versions affectedRemote Access VPN (RAVPN) Service Denial of Service (DoS) VulnerabilityMEDIUMView or DownloadUNDERCODE2024-11-18
Jira

Critical

View or DownloadUNDERCODE2024-11-18
Spring MVCVulnerable versionsDoSModerateView or DownloadUNDERCODE2024-11-19
Apache Tomcat11.0.0-M23 through 11.0.0-M26, 10.1.27 through 10.1.30, 9.0.92 through 9.0.95Request and/or response mix-upModerateView or DownloadUNDERCODE2024-11-19
Rust crate `sharks`Affected versionsShamir Secret Sharing biasMediumView or DownloadUNDERCODE2024-11-19
django CMS3.11.7, 3.11.8, 4.1.2, 4.1.3Cross-Site Scripting (XSS)CriticalView or DownloadUNDERCODE2024-11-19
aiohttp(Affected versions)Memory LeakModerateView or DownloadUNDERCODE2024-11-19
PhpSpreadsheetAll versions before 1.9.4, 2.1.3, 2.3.2, and 3.4.0XXE (XML External Entity)HighView or DownloadUNDERCODE2024-11-19
Moodle!ERROR! B3259 -> Formula Error: Unexpected ,IDOR (Insecure Direct Object Reference)ModerateView or DownloadUNDERCODE2024-11-19
Debezium database connector[Specific version affected]Script injectionModerateView or DownloadUNDERCODE2024-11-19
< v2.10.2Multiple Command Injection VulnerabilitiesMediumView or DownloadUNDERCODE2024-11-19
MoodleIDORModerateView or DownloadUNDERCODE2024-11-19
Cobbler3.0.0 - 3.2.2 / 3.3.6 (all prior to 3.2.3 and 3.3.7)Improper AuthenticationCriticalView or DownloadUNDERCODE2024-11-19
MoodleUnauthorized deletion of report audiencesModerateView or DownloadUNDERCODE2024-11-19
UndertowIncorrect Cookie ParsingHighView or DownloadUNDERCODE2024-11-19
Graylog6.1.0, 6.1.1Concurrent PDF report rendering information leakageHighView or DownloadUNDERCODE2024-11-19
PhpSpreadsheet= 2.0.0 = 2.2.0 = 3.3.0 < 3.4.0XXE (XML External Entity)HighView or DownloadUNDERCODE2024-11-19
LibreNMS(Unaffected versions to be filled by official source)Stored XSSCriticalView or DownloadUNDERCODE2024-11-19
aiohttpVulnerable versionsRequest SmugglingModerateView or DownloadUNDERCODE2024-11-19
Regular Expression Denial of Service (ReDoS)LowView or DownloadUNDERCODE2024-11-19
OpenStack[Specific Version Affected]Improper Deletion of Access RulesModerateView or DownloadUNDERCODE2024-11-19
Elevation of Privilege in Secure Kernel ModeMedium (CVSS v3.1 base score: 6.7)View or DownloadUNDERCODE2024-11-19
Elevation of PrivilegeMedium (CVSS score: 6.8)View or DownloadUNDERCODE2024-11-19
Elevation of Privilege in DWM Core LibraryHIGH (CVSS 3.1 base score: 7.8)View or DownloadUNDERCODE2024-11-19
WindowsNot specified (all Windows versions with Kerberos are likely vulnerable)Remote Code Execution (RCE)Critical (CVSS 3.x score: 9.8)View or DownloadUNDERCODE2024-11-19
Windows (affected versions not specified)Not specifiedElevation of Privilege in USB Video Class System DriverMedium (CVSS v3 score: 6.8)View or DownloadUNDERCODE2024-11-19
Windows(not specified)Windows Registry Elevation of PrivilegeHIGH (CVSS v3 score: 7.8)View or DownloadUNDERCODE2024-11-19
TorchGeo (exact platform unspecified)UnknownRemote Code Execution (RCE)HIGH (CVSS score: 8.1)View or DownloadUNDERCODE2024-11-19
Client-Side Caching Elevation of PrivilegeHIGH (CVSS v3 score: 7.8)View or DownloadUNDERCODE2024-11-19
Win32k Elevation of Privilege VulnerabilityHIGH (CVSS v3.1 base score: 7.8)View or DownloadUNDERCODE2024-11-19
Windows KernelNot specifiedElevation of PrivilegeHIGH (CVSS v3 score: 7.8)View or DownloadUNDERCODE2024-11-19
Secure Kernel Mode Elevation of PrivilegeMedium (CVSS v3 score: 6.7)View or DownloadUNDERCODE2024-11-19
Microsoft PC Manager(not specified in available information)Elevation of PrivilegeHigh (CVSS 3.1: 7.8)View or DownloadUNDERCODE2024-11-19
Windows Telephony Service(Not specified)Remote Code Execution (RCE)High (CVSS 3.x Base Score: 8.8)View or DownloadUNDERCODE2024-11-19
Microsoft Hyper-V(not specified in available information)Denial of Service (DoS)Medium (CVSS 3.1 base score: 6.5)View or DownloadUNDERCODE2024-11-19
Moodle< 4.1.14, >= 4.2.0, < 4.2.11, >= 4.3.0, < 4.3.8, >= 4.4.0, < 4.4.4IDOR (Insecure Direct Object Reference)ModerateView or DownloadUNDERCODE2024-11-19
Moodle< 4.1.14, >= 4.2.0, < 4.2.11, >= 4.3.0, < 4.3.8, >= 4.4.0, < 4.4.4IDOR (Insecure Direct Object Reference)ModerateView or DownloadUNDERCODE2024-11-19
Moodle< 4.1.14, >= 4.2.0, < 4.2.11, >= 4.3.0, < 4.3.8, >= 4.4.0, < 4.4.4IDOR (Insecure Direct Object Reference)ModerateView or DownloadUNDERCODE2024-11-19
Moodle< 4.1.14, >= 4.2.0, < 4.2.11, >= 4.3.0, < 4.3.8, >= 4.4.0, < 4.4.4IDOR (Insecure Direct Object Reference)ModerateView or DownloadUNDERCODE2024-11-19
Moodle< 4.1.14, >= 4.2.0, < 4.2.11, >= 4.3.0, < 4.3.8, >= 4.4.0, < 4.4.4IDOR (Insecure Direct Object Reference)ModerateView or DownloadUNDERCODE2024-11-19
Moodle< 4.1.14, >= 4.2.0, < 4.2.11, >= 4.3.0, < 4.3.8, >= 4.4.0, < 4.4.4IDOR (Insecure Direct Object Reference)ModerateView or DownloadUNDERCODE2024-11-19
Moodle< 4.1.14, >= 4.2.0, < 4.2.11, >= 4.3.0, < 4.3.8, >= 4.4.0, < 4.4.4IDOR (Insecure Direct Object Reference)ModerateView or DownloadUNDERCODE2024-11-19
Moodle< 4.1.14, >= 4.2.0, < 4.2.11, >= 4.3.0, < 4.3.8, >= 4.4.0, < 4.4.4IDOR (Insecure Direct Object Reference)ModerateView or DownloadUNDERCODE2024-11-19
Moodle< 4.1.14, >= 4.2.0, < 4.2.11, >= 4.3.0, < 4.3.8, >= 4.4.0, < 4.4.4IDOR (Insecure Direct Object Reference)ModerateView or DownloadUNDERCODE2024-11-19
Moodle< 4.1.14, >= 4.2.0, < 4.2.11, >= 4.3.0, < 4.3.8, >= 4.4.0, < 4.4.4IDOR (Insecure Direct Object Reference)ModerateView or DownloadUNDERCODE2024-11-19
Apple Products (tvOS, visionOS, Safari, watchOS, iOS, iPadOS, macOS)Not applicable (fixed in specific versions)URL protocol handling issue allowing potential web content restriction bypassMedium (CVSS v2: 5.5, CVSS v3 details not provided)View or DownloadUNDERCODE2024-11-19
Hugging Face TransformersAffected versionsRemote Code ExecutionCritical (CVSS 8.8)View or DownloadUNDERCODE2024-11-19
AndroidNot specifiedOut-of-bounds write in PMRWritePMPageList function (pmr.c)High (Local Privilege Escalation)View or DownloadUNDERCODE2024-11-19
Gogs<= 0.12.7Remote Command ExecutionMediumView or DownloadUNDERCODE2024-11-19
usememos/memos0.9.1 (Vulnerable)Stored XSSCriticalView or DownloadUNDERCODE2024-11-19
Wallabag2.5.2CSRFNot specified in the provided informationView or DownloadUNDERCODE2024-11-19
<br>1.0<br>Test<br>Low<br>https://dailycve.com/test/UNDERCODE2023-01-01

🦑 WANT MORE ?

Loading…
Scroll to Top