Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send...
Prisma Access Agent: Local Authenticated VPN Enforcement Bypass on Linux
Prisma Browser: Improperly Restricted Automation Bridge Allows Security Bypass
Improper protection of an alternate path in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to retain access when their ...
AWS API MCP File Access Restriction Bypass
Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API
Prisma Browser: Insufficient Policy Enforcement Vulnerability in Prisma Browser
Improper Protection of Alternate Path (CWE-424) in the AppSuite of desknet's NEO V4.0R1.0 to V9.0R2.0 allows an attacker to create malicious AppSui...
Privilege Management for Windows - Elevation of Privilege
Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow file overwrite via TFTP because a remote filename with a space character allows an a...
Arris VIP1113 devices through 2025-05-30 with KreaTV SDK allow booting an arbitrary image via a crafted /usr/bin/gunzip file
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers' methods when running on PHP...
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the template engine
CodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploading a .h...
CodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScript, but it can be bypassed ...
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the w...
Cortex XDR Broker VM: Unauthorized Access to Broker VM Docker Containers
Container Escape Vulnerability in TR7's Application Security Platform (ASP)
A vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 14 pro+ (J31032-...
Improper Protection of Alternate Path in GitLab
Showing 1 - 20 of 1,000+ results