CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
Paella Player: Stored XSS via caption cue text
Apache Thrift, Apache Thrift, Apache Thrift, Apache Thrift: TCompactProtocol varint byte-count limit
expr-eval: expr-eval: Code Execution via crafted expressions in toJSFunction() API
Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host redirect
sealed-env: TOTP secret embedded in unseal token payload (enterprise mode)
Keycloak: keycloak: information disclosure via authorization bypass in admin api
Nu Html Checker (validator.nu) - Restriction bypass vulnerability allowing local SSRF
Nodemailer: nodemailer: denial of service via crafted email address header
ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth b…
A reflected cross-site scripting (XSS) vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.4, 2024.Q3.1 thro…
jsonpath-plus: Remote Code Execution in jsonpath-plus via Improper Input Sanitization
Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such…
Rejected reason: This was not a security issue in Bootstrap. Bootstrap’s JavaScript is not intended to sanitize unsafe or intentionally dangerous HTML. As such…
Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability
angular: Inefficient Regular Expression Complexity
Versions of the package pubnub before 7.4.0; all versions of the package com.pubnub:pubnub; versions of the package pubnub before 6.19.0; all versions of the p…
HTTP/2: Multiple HTTP/2 enabled web servers are vulnerable to a DDoS attack (Rapid Reset Attack)
jquery: Cross-site scripting
An issue was discovered hjson thru 3.0.0 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic depende…
http-cache-semantics: Regular Expression Denial of Service (ReDoS) vulnerability
cookiejar: Regular Expression Denial of Service (ReDoS)
Denial of Service (DoS)
Cross-site Scripting (XSS)
Arbitrary Code Execution
Showing 1 to 25 CVEs · page 1 (more available)