Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

15,095 CVEs · Low severity

CVEs (15,095, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 326–350 of 15,095 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2023-42235 LOW Patched 3.8 2025-01-13 An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple parameters of /monitor/s_nor…
CVE-2023-42236 LOW Patched 3.8 2025-01-13 An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in a GET parameter of /common/ajaxfunction.php.
CVE-2023-42237 LOW Patched 3.8 2025-01-13 An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple GET parameters of /vam/vam_i…
CVE-2024-13308 LOW Patched 3.8 2025-01-09 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Browser Back Button allows Cross-Site Scripting (XSS).This issu…
CVE-2025-22449 LOW Patched 3.8 2025-01-09 Mattermost versions 9.11.x <= 9.11.5 fail to enforce invite permissions, which allows team admins, with no permission to invite users to their team, to invite users by upda&hellip;
CVE-2024-56321 LOW Patched 3.8 2025-01-03 GoCD is a continuous deliver server. GoCD versions 18.9.0 through 24.4.0 (inclusive) can allow GoCD admins to abuse the backup configuration "post-backup script" feature to&hellip;
CVE-2023-23814 LOW 3.8 2024-12-09 Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects C&hellip;
CVE-2024-6156 LOW Patched 3.8 2024-12-06 Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could be bypassed if the client's certificate was present in the trust store.
CVE-2024-6219 LOW Patched 3.8 2024-12-06 Mark Laing discovered in LXD's PKI mode, until version 5.21.1, that a restricted certificate could be added to the trust store with its restrictions not honoured.
CVE-2024-53502 LOW 3.8 2024-12-03 Seecms v4.8 was discovered to contain a SQL injection vulnerability in the SEMCMS_SeoAndTag.php page.
CVE-2024-8160 LOW Patched 3.8 2024-11-26 Erik de Jong, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API ftptest.cgi did not have a sufficient input validation allowing for a possible command &hellip;
CVE-2024-5030 LOW Patched 3.8 2024-11-18 The CM Table Of Contents WordPress plugin before 1.2.3 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin&hellip;
CVE-2024-38660 LOW 3.8 2024-11-13 Protection mechanism failure in the SPP for some Intel(R) Xeon(R) processor family (E-Core) may allow an authenticated user to potentially enable escalation of privilege vi&hellip;
CVE-2024-25565 LOW 3.8 2024-11-13 Insufficient control flow management in UEFI firmware for some Intel(R) Xeon(R) Processors may allow an authenticated user to enable denial of service via local access.
CVE-2024-30142 LOW 3.8 2024-11-07 HCL BigFix Compliance is affected by a missing secure flag on a cookie. If a secure flag is not set, cookies may be stolen by an attacker using XSS, resulting in unauthori&hellip;
CVE-2024-20528 LOW Patched 3.8 2024-11-06 A vulnerability in the API of Cisco ISE could allow an authenticated, remote attacker to upload files to arbitrary locations on the underlying operating system of an affect&hellip;
CVE-2024-10228 LOW Patched 3.8 2024-10-29 The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path that could be modified by an unprivileged user, introducing potential for &hellip;
CVE-2024-46897 LOW Patched 3.8 2024-10-18 Incorrect permission assignment for critical resource issue exists in Exment v6.1.4 and earlier and Exment v5.0.11 and earlier. A logged-in user with the permission of tabl&hellip;
CVE-2024-21247 LOW Patched 3.8 2024-10-15 Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9&hellip;
CVE-2024-45599 LOW 3.8 2024-09-25 Cursor is an artificial intelligence code editor. Prior to version 0.41.0, if a user on macOS has granted Cursor access to the camera or microphone, any program that is run&hellip;
CVE-2024-8612 LOW 3.8 2024-09-20 A flaw was found in QEMU, in the virtio-scsi, virtio-blk, and virtio-crypto devices. The size for virtqueue_push as set in virtio_scsi_complete_req / virtio_blk_req_complet&hellip;
CVE-2024-8694 LOW Patched 3.8 2024-09-11 A vulnerability, which was classified as problematic, was found in JFinalCMS up to 20240903. This affects the function update of the file /admin/template/update of the comp&hellip;
CVE-2024-42425 LOW Patched 3.8 2024-09-10 Dell Precision Rack, 14G Intel BIOS versions prior to 2.22.2, contains an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker with local &hellip;
CVE-2024-38304 LOW Patched 3.8 2024-08-29 Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker with &hellip;
CVE-2024-5445 LOW 3.8 2024-08-12 Ecosystem Agent version 4 < 4.1.5.2597 and Ecosystem Agent version 5 < 5.1.4.2473 did not properly validate SSL/TLS certificates, which could allow a malicious actor to per&hellip;