Search across all tracked vulnerability databases
Browse and filter security vulnerabilities across ecosystems
CVE-2025-15107
SQLE's JWT Secret Handler can be manipulated to use hard-coded cryptographic key
CVE-2025-68943
Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order
CVE-2025-68946
Gitea vulnerable to Cross-site Scripting
CVE-2025-68944
Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries
CVE-2025-68945
Gitea: anonymous user can visit private user's project
CVE-2025-68942
Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text
CVE-2025-68941
Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources
CVE-2025-68938
Gitea mishandles authorization for deletion of releases
CVE-2025-68940
Gitea doesn't adequately enforce branch deletion permissions after merging a pull request.
CVE-2025-68939
Gitea allows attackers to add attachments with forbidden file extensions
CVE-2025-64641
Mattermost doesn't verify that post actions invoking `/share-issue-publicly` were created by the Jira plugin
CVE-2025-13767
Mattermost doesn't validate user channel membership when attaching Mattermost posts as comments to Jira issues
CVE-2025-68476
KEDA has Arbitrary File Read via Insufficient Path Validation in HashiCorp Vault Service Account Credential
CVE-2025-68383
Filebeat Beats has Buffer Overflow via Malformed Syslog Message or Malicious Tokenizer Pattern in Dissect Configuration
CVE-2025-68388
Elasticsearch Packetbeat has Excessive Allocation of Memory and CPU via Malicious IPv4 Fragments
CVE-2025-14764
Amazon S3 Encryption Client has a Key Commitment Issue
CVE-2025-63389
Ollama Platform has missing authentication enabling attackers to perform model management operations
CVE-2025-13324
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation
CVE-2025-12689
Mattermost fails to check Websocket request for proper UTF-8 format potentially crashing Calls plug-in
CVE-2025-62190
Mattermost has CSRF vulnerability via Calls Widget page
Showing 1 - 20 of 1,000+ results