CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
CTX Feed Pro <= 7.6.12 - Authenticated (Administrator+) Remote Code Execution
Visitors Traffic Real Time Statistics Pro <= 11.22 - Unauthenticated Stored Cross-Site Scripting via ahcpro_track_visitor (page_title)
Transmission of a sensitive key in the URL over an unencrypted HTTP connection. The request is sent over HTTP rather than HTTPS, meaning the key is transmitted…
An API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials…
API key is hardcoded and retrievable from the application package. Since Android applications can be reverse engineered, embedding sensitive API credentials di…
ClipBucket v5 through 5.5.3-#197 SQL Injection via ads_manager.php delete Parameter
Mooncake through 0.3.13.post1 Missing Authentication in HTTP Metadata Server
Mooncake transfer engine through 0.3.13.post1 Memory Exhaustion via Unbounded Notify Queue
Mooncake transfer engine through 0.3.13.post1 Denial of Service via P2P Handshake Daemon Response Write
Office-PowerPoint-MCP-Server through 2.0.7 Path Traversal via save_presentation and manage_image
389-ds-base: 389-ds-base: unauthenticated worker-thread-pool exhaustion via completed-operation-then-incomplete-pdu connection requeue
- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack. This issue affects EasyIO NEO…
PictShare < 3.7.1 Predictable Delete Code via rand()
- On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations. This issue affects Neo Series M…
- On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations. This issue affects EasyIO FS32: bef…
PictShare < 3.7.1 Sensitive Information Disclosure via info API
- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection. This issue affects EasyIO FS32: before 3.0b63.
Uncontrolled recursion in the Ion reader in Amazon Ion Python
figlet is vulnerable to denial of service via unbounded loop when whitespaceBreak is used with a small width
Out-of-bounds write in PeaZip PEA extractor allows code execution via a crafted .pea archive
Unencrypted UDP Control Traffic in Teledyne FLIR Robots running Aware2
Missing Authentication in Teledyne FLIR Robots running Aware2
Document Merge Service vulnerable to RCE via SSTI (xlsx tempaltes)
pgvector buffer overflow in IVFFlat index build
Sakai Conversations has a Stored XSS Issue
Showing 1 to 25 CVEs · page 1 (more available)