Click to open the Alert Filter

 
Year Month
Severity
Categories
Search by Alert Name
Page(s) : 1 ... 388 389 390 391 392 393 394 395 396 397 [398] 399 400 401 402 403 404 405 406 407 408 ... Result(s) : 324964

Alerts Feed Alerts

DATE NAME CATEGORIES DETAIL
N/A 2025-04-28 CVE-2025-22235 cve EndpointRequest.to() creates a matcher for null/** if the actuator endpoint, for which the EndpointRequest has been created, is disabled or not exposed. Your application may be...
N/A 2025-04-28 CVE-2025-0627 cve The WordPress Tag, Category, and Taxonomy Manager WordPress plugin before 3.30.0 does not sanitise and escape some of its Widgets settings, which could allow high privilege use...
4.3 2025-04-28 CVE-2025-0049 cve When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message includes the absolute server path which may allo...
N/A 2025-04-28 CVE-2024-9771 cve The WP-Recall WordPress plugin before 16.26.12 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-S...
9.8 2025-04-28 CVE-2024-32499 cve Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed.
N/A 2025-04-28 CVE-2024-13688 cve The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 uses a hardcoded password in its Password Protection feature, allowing attacker to bypass the protection off...
N/A 2025-04-28 CVE-2024-12706 cve Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText™ Digital Asset Management. T he vulnerability could all...
5.4 2025-04-28 CVE-2024-11922 cve Missing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7.8.0 allows an attacker with permission to trigger emails to insert ...
5.3 2025-04-28 CVE-2024-10635 cve Enterprise Protection contains an improper input validation vulnerability in attachment defense that allows an unauthenticated remote attacker to bypass attachment scanning secu...
9.8 2025-04-28 CVE-2023-42404 cve OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution.
9.8 2025-04-28 CVE-2023-35817 cve DevExpress before 23.1.3 allows AsyncDownloader SSRF.
5.3 2025-04-28 CVE-2023-35816 cve DevExpress before 23.1.3 allows arbitrary TypeConverter conversion.
9.8 2025-04-28 CVE-2023-35815 cve DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data.
9.8 2025-04-28 CVE-2023-35814 cve DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms.
8.8 2025-04-28 CVE-2022-41871 cve SEPPmail through 12.1.17 allows command injection within the Admin Portal. An authenticated attacker is able to execute arbitrary code in the context of the user root.
6.1 2025-04-28 CVE-2015-4582 cve The TheCartPress boot-store (aka Boot Store) theme 1.6.4 for WordPress allows header.php tcp_register_error XSS. NOTE: CVE-2015-4582 is not assigned to any Oracle product.
8.8 2025-04-28 CVE-2015-2079 cve Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argument) form of Perl open.
8.8 2025-04-27 CVE-2025-46690 cve Ververica Platform 2.14.0 allows low-privileged users to access SQL connectors via a direct namespaces/default/formats request.
6.1 2025-04-27 CVE-2025-46689 cve Ververica Platform 2.14.0 contain an Reflected XSS vulnerability via a namespaces/default/formats URI.
8.4 2025-04-27 CVE-2025-46688 cve quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected.
Page(s) : 1 ... 388 389 390 391 392 393 394 395 396 397 [398] 399 400 401 402 403 404 405 406 407 408 ... Result(s) : 324964