Page(s) : 1 ... 388 389 390 391 392 393 394 395 396 397 [398] 399 400 401 402 403 404 405 406 407 408 ... | Result(s) : 324964 |
Alerts
DATE | NAME | CATEGORIES | DETAIL | |
---|---|---|---|---|
N/A | 2025-04-28 | CVE-2025-22235 | cve | EndpointRequest.to() creates a matcher for null/** if the actuator endpoint, for which the EndpointRequest has been created, is disabled or not exposed. Your application may be... |
N/A | 2025-04-28 | CVE-2025-0627 | cve | The WordPress Tag, Category, and Taxonomy Manager WordPress plugin before 3.30.0 does not sanitise and escape some of its Widgets settings, which could allow high privilege use... |
4.3 | 2025-04-28 | CVE-2025-0049 | cve | When a Web User without Create permission on subfolders attempts to upload a file to a non-existent directory, the error message includes the absolute server path which may allo... |
N/A | 2025-04-28 | CVE-2024-9771 | cve | The WP-Recall WordPress plugin before 16.26.12 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-S... |
9.8 | 2025-04-28 | CVE-2024-32499 | cve | Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed. |
N/A | 2025-04-28 | CVE-2024-13688 | cve | The Admin and Site Enhancements (ASE) WordPress plugin before 7.6.10 uses a hardcoded password in its Password Protection feature, allowing attacker to bypass the protection off... |
N/A | 2025-04-28 | CVE-2024-12706 | cve | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in OpenText™ Digital Asset Management. T he vulnerability could all... |
5.4 | 2025-04-28 | CVE-2024-11922 | cve | Missing input validation in certain features of the Web Client of Fortra's GoAnywhere prior to version 7.8.0 allows an attacker with permission to trigger emails to insert ... |
5.3 | 2025-04-28 | CVE-2024-10635 | cve | Enterprise Protection contains an improper input validation vulnerability in attachment defense that allows an unauthenticated remote attacker to bypass attachment scanning secu... |
9.8 | 2025-04-28 | CVE-2023-42404 | cve | OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution. |
9.8 | 2025-04-28 | CVE-2023-35817 | cve | DevExpress before 23.1.3 allows AsyncDownloader SSRF. |
5.3 | 2025-04-28 | CVE-2023-35816 | cve | DevExpress before 23.1.3 allows arbitrary TypeConverter conversion. |
9.8 | 2025-04-28 | CVE-2023-35815 | cve | DevExpress before 23.1.3 has a data-source protection mechanism bypass during deserialization on XML data. |
9.8 | 2025-04-28 | CVE-2023-35814 | cve | DevExpress before 23.1.3 does not properly protect XtraReport serialized data in ASP.NET web forms. |
8.8 | 2025-04-28 | CVE-2022-41871 | cve | SEPPmail through 12.1.17 allows command injection within the Admin Portal. An authenticated attacker is able to execute arbitrary code in the context of the user root. |
6.1 | 2025-04-28 | CVE-2015-4582 | cve | The TheCartPress boot-store (aka Boot Store) theme 1.6.4 for WordPress allows header.php tcp_register_error XSS. NOTE: CVE-2015-4582 is not assigned to any Oracle product. |
8.8 | 2025-04-28 | CVE-2015-2079 | cve | Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argument) form of Perl open. |
8.8 | 2025-04-27 | CVE-2025-46690 | cve | Ververica Platform 2.14.0 allows low-privileged users to access SQL connectors via a direct namespaces/default/formats request. |
6.1 | 2025-04-27 | CVE-2025-46689 | cve | Ververica Platform 2.14.0 contain an Reflected XSS vulnerability via a namespaces/default/formats URI. |
8.4 | 2025-04-27 | CVE-2025-46688 | cve | quickjs-ng through 0.9.0 has an incorrect size calculation in JS_ReadBigInt for a BigInt, leading to a heap-based buffer overflow. QuickJS before 2025-04-26 is also affected. |
Page(s) : 1 ... 388 389 390 391 392 393 394 395 396 397 [398] 399 400 401 402 403 404 405 406 407 408 ... | Result(s) : 324964 |