CVE Browser
Search and filter CVEs by severity, ecosystem, EPSS score, and more.
Page 1 (more results available)
SourceCodester Online Reviewer Management System btn_functions.php activity sql injection
modelcontextprotocol mcp-server-fetch/mcp-server-everything Fetch Tool server.py fetch_url server-side request forgery
calcom cal.diy PBAC Permission BookingAccessService.ts doesUserIdHaveAccessToBooking authorization
itsourcecode Pet Shop Management System admin_reservefilter.php sql injection
Improper access control in ManagedProvisioning prior to SMR Sep-2026 Release 1 allows local attackers to install arbitrary applications.
itsourcecode Pet Shop Management System admin_reject_completed.php sql injection
- Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying. This issue affects EasyIO FG: before 2.0b52.
- Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations. This issue affects Easy I…
: Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse. This issue affects EasyIO FS32: befo…
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in CWE-79 - Cross-site Scripting CAPEC-63 allows Cross-Site…
- External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack. This issue affects EasyIO FS32: before 3.0b63.
Fail-open error handling in the data masking utility in Powertools for AWS Lambda (Python)
- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows - Command Injection. This issue affects EasyIO FS32: before 3.0b63.
: Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials. This issue affects Ea…
Physical UART Access Leading to an Unauthenticated Root Shell in TP-Link Kasa EC70 and EC71
stream-json: Prototype pollution: Assembler writes this.current[this.key] on plain objects
stream-json: JSONC parser and verifier re-scan the whole accumulated comment on every input chunk
Filament: Multi-factor authentication (app) management actions do not require password reauthentication
Unencrypted 802.11 Network in Teledyne FLIR Robots running Aware2
OpenRun: Redirect URL validation bypass using //host paths leads to Open Redirect
NetBox Device Type Library: Arbitrary Code Execution on CI Runner Through Malicious requirements.txt, .pre-commit-hooks-config.yaml, and .gitmodules Files
Wormhole.app SSRF
A component of one of the Motorola system applications was exported without permission, allowing for the revocation of runtime permissions from other apps.
Joyland AI WebView accepts invalid SSL certificates
Joyland AI enables HTTP
Showing 1 to 25 CVEs · page 1 (more available)