Search
907 CVEs · Medium severity
CVEs (907, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 907 (capped at 500)
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-23565 | MEDIUM | 5.3 | 2026-07-17 | HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. The actor could b … | |
| CVE-2024-23566 | MEDIUM | 6.5 | 2026-07-17 | HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various security issues like brute force , autom… | |
| CVE-2024-23567 | MEDIUM | 4.3 | 2026-07-17 | HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during normal usage. Data… | |
| CVE-2024-23568 | MEDIUM | 5.3 | 2026-07-17 | HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. Displaying version information of soft… | |
| CVE-2024-23569 | MEDIUM | 4.3 | 2026-07-17 | HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header | |
| CVE-2024-23570 | MEDIUM | 4.3 | 2026-07-17 | HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulnerable application in an iFrame on … | |
| CVE-2024-23571 | MEDIUM | 4.3 | 2026-07-17 | HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to which the page and its form fields sh… | |
| CVE-2024-23572 | MEDIUM | 4.2 | 2026-07-17 | HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the cont… | |
| CVE-2024-23574 | MEDIUM | 5.3 | 2026-07-17 | HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. U… | |
| CVE-2024-23575 | MEDIUM | 5.3 | 2026-07-17 | HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the server. An attacker may … | |
| CVE-2024-23577 | MEDIUM | 4.3 | 2026-07-17 | HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary hosts when requested in http protocol. When an appl… | |
| CVE-2024-23578 | MEDIUM | 4.2 | 2026-07-17 | HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any … | |
| CVE-2024-42214 | MEDIUM | 5.3 | 2026-07-17 | HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the methods that are supported by… | |
| CVE-2024-5300 | MEDIUM | 5.6 | 2026-07-21 | An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules locat… | |
| CVE-2024-58357 | MEDIUM | Patched | 6.5 | 2026-07-18 | SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time() function that panics when unwrap is called on a None result from timestamp_o… |
| CVE-2024-58358 | MEDIUM | Patched | 4.9 | 2026-07-18 | SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owner users to define users with nonexistent roles. Atta… |
| CVE-2024-58359 | MEDIUM | Patched | 6.5 | 2026-07-18 | SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting mechanism when using ORDER BY rand() clause. Authorized clients can execute queries… |
| CVE-2024-58361 | MEDIUM | Patched | 6.5 | 2026-07-18 | SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code when processing empty strings. Authorized clients ca… |
| CVE-2024-58363 | MEDIUM | Patched | 6.3 | 2026-07-18 | SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clause or use method. Attackers with an authenticated se… |
| CVE-2024-58364 | MEDIUM | Patched | 6.5 | 2026-07-18 | SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span rendering when parsing queries with errors on line terminator characters. Autho… |
| CVE-2024-58365 | MEDIUM | Patched | 6.5 | 2026-07-18 | SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls to nonexistent built-in functions. Authorized client… |
| CVE-2024-58369 | MEDIUM | Patched | 6.5 | 2026-07-18 | SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or namespace levels, causing server panic. Authorized client… |
| CVE-2024-58370 | MEDIUM | Patched | 6.5 | 2026-07-18 | SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested SurrealQL statements including IF, RELATE, and attribute access idioms. Authorize… |
| CVE-2025-13146 | MEDIUM | Patched | 6.5 | 2026-07-22 | The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.6. This is due… |
| CVE-2025-68081 | MEDIUM | 5.9 | 2026-07-23 | Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions. |