Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

907 CVEs · Medium severity

CVEs (907, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 907 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2024-23565 MEDIUM 5.3 2026-07-17 HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functionality. The actor could b …
CVE-2024-23566 MEDIUM 6.5 2026-07-17 HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various security issues like brute force , autom…
CVE-2024-23567 MEDIUM 4.3 2026-07-17 HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during normal usage. Data…
CVE-2024-23568 MEDIUM 5.3 2026-07-17 HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. Displaying version information of soft…
CVE-2024-23569 MEDIUM 4.3 2026-07-17 HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header
CVE-2024-23570 MEDIUM 4.3 2026-07-17 HCL Aftermarket EPC is affected by clickjacking vulnerability Cross-Frame Scripting is an attack technique where an attacker loads a vulnerable application in an iFrame on …
CVE-2024-23571 MEDIUM 4.3 2026-07-17 HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to which the page and its form fields sh…
CVE-2024-23572 MEDIUM 4.2 2026-07-17 HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk associated with this issue. You should review the cont…
CVE-2024-23574 MEDIUM 5.3 2026-07-17 HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid users in the system. U…
CVE-2024-23575 MEDIUM 5.3 2026-07-17 HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the server. An attacker may …
CVE-2024-23577 MEDIUM 4.3 2026-07-17 HCL Aftermarket EPC is vulnerable since the application does not have a validation for HOST header and accepts arbitrary hosts when requested in http protocol. When an appl…
CVE-2024-23578 MEDIUM 4.2 2026-07-17 HCL Aftermarket EPC is vulnerable to attack as the application implements an HTML5 cross-origin resource sharing (CORS) policy for this request that allows access from any …
CVE-2024-42214 MEDIUM 5.3 2026-07-17 HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the methods that are supported by…
CVE-2024-5300 MEDIUM 5.6 2026-07-21 An access control bypass and information disclosure vulnerability exists in the base AppArmor security profile configuration of Canonical snapd. The abstraction rules locat…
CVE-2024-58357 MEDIUM Patched 6.5 2026-07-18 SurrealDB versions before 2.1.0 contain an uncaught exception vulnerability in the rand::time() function that panics when unwrap is called on a None result from timestamp_o…
CVE-2024-58358 MEDIUM Patched 4.9 2026-07-18 SurrealDB versions before 2.1.0 contain a denial of service vulnerability in role conversion that allows privileged owner users to define users with nonexistent roles. Atta…
CVE-2024-58359 MEDIUM Patched 6.5 2026-07-18 SurrealDB versions before 2.1.0 contain a denial of service vulnerability in the sorting mechanism when using ORDER BY rand() clause. Authorized clients can execute queries…
CVE-2024-58361 MEDIUM Patched 6.5 2026-07-18 SurrealDB versions before 2.0.4 contain an uncaught exception handling vulnerability in the parser error rendering code when processing empty strings. Authorized clients ca…
CVE-2024-58363 MEDIUM Patched 6.3 2026-07-18 SurrealDB before 1.5.4 fails to properly validate authentication when a scope user switches databases using the USE clause or use method. Attackers with an authenticated se…
CVE-2024-58364 MEDIUM Patched 6.5 2026-07-18 SurrealDB versions before 1.2.1 contain an uncaught exception handling vulnerability in span rendering when parsing queries with errors on line terminator characters. Autho…
CVE-2024-58365 MEDIUM Patched 6.5 2026-07-18 SurrealDB versions before 1.2.0 contain an uncaught exception vulnerability in the query executor when processing calls to nonexistent built-in functions. Authorized client…
CVE-2024-58369 MEDIUM Patched 6.5 2026-07-18 SurrealDB versions before 1.1.1 fail to properly validate invocation of custom parameters and functions at root or namespace levels, causing server panic. Authorized client…
CVE-2024-58370 MEDIUM Patched 6.5 2026-07-18 SurrealDB versions before 1.1.0 fail to enforce recursion depth limits when parsing nested SurrealQL statements including IF, RELATE, and attribute access idioms. Authorize…
CVE-2025-13146 MEDIUM Patched 6.5 2026-07-22 The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.6. This is due…
CVE-2025-68081 MEDIUM 5.9 2026-07-23 Administrator Cross Site Scripting (XSS) in WP-Polls <= 2.77.3 versions.