CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
Divi Membership <= 2.3.0 - Unauthenticated Authentication Bypass via 'paypal_param' Parameter
DevKit Pro <= 2.3.0 - Unauthenticated Authentication Bypass to Administrator Account Takeover via 'original_user_id' Cookie in Frontend Revert Switch Flow
Improper MLS Welcome roster validation in Discord libdave allows unauthorized group membership
389-ds-base: 389-ds-base: starttls plaintext-buffer retention allows on-path attacker to forge an ldap client's authentication result
Mooncake transfer engine before 0.3.13 Unauthenticated Arbitrary Memory Read/Write via TCP Transport
SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability
: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data. This issue affects EasyIO FS32:…
Hardcoded Passwords in Teledyne FLIR Robots running Aware2
Local File Inclusion in Teledyne FLIR Robots running Aware2
Cleartext HTTP for Control Traffic in Teledyne FLIR Robots running Aware2
Cadmos LTI exposure of sensitive information via debug mode
Joyland AI WebView command injection
GetSimple CMS: Missing CSRF protection in UpdateCE allows forging a privileged server-side update request
GetSimple CMS: CSRF, SSRF, and Unrestricted Zip Extraction
GetSimple CMS: Predictable Password Reset Password Allows Administrator Account Takeover
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 thro…
DHIS2: Unsafe Java Deserialization - Remote Code Execution (RCE)
Capacitor Android and iOS: remote content can be loaded at the app origin via the internal HTTP proxy path
Foreman: safemode bypass leading to rce
Foreman: excessive permissions for viewer role on preview
Apache HTTP Server: mod_ssl SSLRequire allows .htaccess ap_expr file-function
WatchGuard Endpoint Security Missing Authentication in Kernel Memory Access Driver Allows Arbitrary Kernel Memory Access
Apache HTTP Server: mod_http2 use-after-free / wild write via shared session->bbtmp re-entrancy
Apache HTTP Server: mod_rewrite use-after-free via %{LA-U:HTTP:...}
Classroom 50 vulnerable to arbitrary file overwrite on the teacher's machine via symlink in a student repo (gh teacher download)
Showing 1 to 25 CVEs · page 1 (more available)