CVE Tracker
Every vulnerability in the news, ranked by real-world risk.
TP-Link Archer AX-21 Command Injection Vulnerability
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint.
JetBrains TeamCity Relative Path Traversal Vulnerability
PHP-CGI OS Command Injection Vulnerability
Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability
ConnectWise ScreenConnect Authentication Bypass Vulnerability
CrushFTP Authentication Bypass Vulnerability
JetBrains TeamCity Authentication Bypass Vulnerability
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-lev
Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability
GeoServer is an open source server that allows users to share and edit geospatial data.
Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability
CWP Control Web Panel OS Command Injection Vulnerability
Meta React Server Components Remote Code Execution Vulnerability
A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload
Next.js is a React framework for building full-stack web applications.
Microsoft SMBv1 Remote Code Execution Vulnerability
Microsoft Windows Buffer Overflow Vulnerability
Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
Langflow Code Injection Vulnerability
WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Qu
Apache ActiveMQ Improper Input Validation Vulnerability
SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability
Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability
In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or truncate arbitrary files through a Postgre
Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote co
Marimo Remote Code Execution Vulnerability
Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validate
Fortinet FortiClient EMS SQL Injection Vulnerability
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management).
Sangoma FreePBX Authentication Bypass Vulnerability
In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: avoid in-place decrypt on shared skb frags MSG_SPLICE_PAGES can attach pages from
In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when paged frags are present The DATA-packet handl
Samsung MagicINFO 9 Server Path Traversal Vulnerability
Microsoft Internet Explorer Use-After-Free Vulnerability
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execution.
Fortinet FortiSandbox OS Command Injection Vulnerability
Linux Kernel Privilege Escalation Vulnerability
Fortinet FortiClient EMS Improper Access Control Vulnerability
SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability
ConnectWise ScreenConnect Path Traversal Vulnerability
D-Link DIR-823X Command Injection Vulnerability
Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security rest
BerriAI LiteLLM SQL Injection Vulnerability
Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability
A vulnerability was found in TBK DVR-4104 and DVR-4216 up to 20240412 and classified as critical.
Once an user is authenticated on Jolokia, he can potentially trigger arbitrary code execution.
Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability
Drupal Core SQL Injection Vulnerability
Sangoma FreePBX OS Command Injection Vulnerability
A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a craf
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Citrix NetScaler Out-of-Bounds Read Vulnerability
Microsoft Active Directory Domain Services Privilege Escalation Vulnerability
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to by