CVE Tracker
Vulnerabilities in the news. Explore recent activity, known exploitation, severity, and EPSS.
GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
JFrog Artifactory Improper Authentication Vulnerability
JFrog Artifactory Incorrect Authorization Vulnerability
ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
Flowise is a drag & drop user interface to build a customized large language model flow.
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K.
Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K.
Authorization bypass through User-Controlled key vulnerability in Apache Camel K.
Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.
A server-side request forgery issue due to improper validation of equivalent address representations in the port forwarding to remote hosts functionality in Ama
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the sub
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arb
A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Sec
Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerab
Dell ThinOS 10, versions prior to 2605_10.2616, contain an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability.
Dell ThinOS 10, versions prior to 2605_10.2616, contain a Protection Mechanism Failure vulnerability.
Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerab
Dell ThinOS 10, versions prior to 2605_10.2616, contain a Download of Code Without Integrity Check vulnerability.
Dell ThinOS 10, versions prior to 2605_10.2616, contain a Security Version Number Mutable to Older Versions vulnerability.
OmniRoute is an open-source AI gateway providing a single endpoint for multiple model providers.
VLC media player computes the size of a picture buffer with 32-bit arithmetic and allocates from the wrapped result.
VLC media player copies an RTSP response line into a fixed buffer without guaranteeing termination and then treats that buffer as a C string.
PaperCut NG/MF Missing Authentication for Critical Function Vulnerability
PaperCut NG/MF Unsafe Reflection Vulnerability
JFrog Artifactory Improper Authentication Vulnerability
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
Google Chromium V8 Memory Corruption Vulnerability
Improper escaping of a request URL in ConfigServer Security & Firewall allows an unauthenticated remote attacker to execute arbitrary commands as the CSF servic
OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who controls a configured allow/deny feed to execu
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path
GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clients to retrieve PTZ information and issu
In Contacts Provider, there is a possible way to access the contacts database due to SQL injection.
MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
Google Chromium V8 Out of Bounds Write Vulnerability
Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
In p2p_process_prov_disc_bootstrap_req of p2p_pd.c, there is a possible out of bounds write due to a heap buffer overflow.
Google Chromium V8 Type Confusion Vulnerability
Microsoft Windows Heap-Based Buffer Overflow Vulnerability
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ".
BerriAI LiteLLM Command Injection Vulnerability
BerriAI LiteLLM Improper Authentication Vulnerability
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format.