Search across all tracked vulnerability databases
Browse and filter security vulnerabilities across ecosystems
CVE-2025-13467
Keycloak LDAP User Federation provider enables admin-triggered untrusted Java deserialization
CVE-2025-66524
Apache NiFi GetAsanaObject Processor has Remote Code Execution via Unsafe Deserialization
CVE-2025-68384
Elasticsearch has Excessive Allocation of Resources via Submission of Oversized User Settings Data
CVE-2025-68390
Elasticsearch privileged authenticated users can cause DoS through Excessive Resource Allocation
CVE-2025-68161
Apache Log4j does not verify the TLS hostname in its Socket Appender
CVE-2025-14763
Amazon S3 Encryption Client for Java has a Key Commitment Issue
CVE-2024-29371
jose4j is vulnerable to DoS via compressed JWE content
CVE-2025-68113
ALTCHA Proof-of-Work Vulnerable to Challenge Splicing and Replay
CVE-2025-67735
Netty has a CRLF Injection vulnerability in io.netty.handler.codec.http.HttpRequestEncoder
CVE-2025-37731
Elasticsearch PKI Realm Authentication Bypass Vulnerability Allows User Impersonation Through Crafted Client Certificates
CVE-2025-14674
snail-job is vulnerable to Code Injection through QLExpressEngine.doEval function
CVE-2025-67721
aircompressor Snappy and LZ4 Java-based decompressor implementation can leak information from reused output buffer
CVE-2025-3586
Liferay Portal and DXP Instance Admin can execute code using Objects Actions and Validations
CVE-2025-53960
Apache StreamPark: Use the user’s password as the secret key Vulnerability
CVE-2025-54981
Apache StreamPark uses a Weak Encryption Algorithm
CVE-2025-54947
Apache StreamPark has a hard-coded encryption key
CVE-2025-26866
Apache HugeGraph-Server: RAFT and deserialization vulnerability
CVE-2025-14518
PowerJob has a server-side request forgery vulnerability in PingPongUtils.java
CVE-2025-67505
Race condition in the Okta Java SDK
CVE-2025-66033
Improper Memory Cleanup in the Okta Java SDK
Showing 1 - 20 of 1,000+ results