Search

Search Results (374569 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-53490 2 Jly, Mediawiki 2 Campaignevents, Mediawiki 2025-10-01 5.6 Medium
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - CampaignEvents Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - CampaignEvents Extension: from 1.43.X before 1.43.2.
CVE-2023-46988 1 Onlyoffice 1 Document Server 2025-10-01 6.7 Medium
Path Traversal vulnerability in ONLYOFFICE Document Server before v8.0.1 allows a remote attacker to copy arbitrary files by manipulating the fileExt parameter in the /example/editor endpoint, leading to unauthorized access to sensitive files and potential Denial of Service (DoS).
CVE-2022-50397 1 Linux 1 Linux Kernel 2025-10-01 5.5 Medium
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-61722 2025-10-01 N/A
Not used
CVE-2025-61721 2025-10-01 N/A
Not used
CVE-2025-61720 2025-10-01 N/A
Not used
CVE-2025-61719 2025-10-01 N/A
Not used
CVE-2025-61718 2025-10-01 N/A
Not used
CVE-2025-61717 2025-10-01 N/A
Not used
CVE-2025-61716 2025-10-01 N/A
Not used
CVE-2025-61715 2025-10-01 N/A
Not used
CVE-2025-61714 2025-10-01 N/A
Not used
CVE-2024-7480 1 Avaya 1 Aura System Manager 2025-10-01 4.2 Medium
An Improper access control vulnerability was found in Avaya Aura System Manager which could allow a command-line interface (CLI) user with administrative privileges to read arbitrary files on the system. Affected versions include 10.1.x.x and 10.2.x.x. Versions prior to 10.1 are end of manufacturer support.
CVE-2024-4196 1 Avaya 1 Ip Office 2025-10-01 10 Critical
An improper input validation vulnerability was discovered in Avaya IP Office that could allow remote command or code execution via a specially crafted web request to the Web Control component. Affected versions include all versions prior to 11.1.3.1.
CVE-2024-12756 1 Avaya 1 Spaces 2025-10-01 7.3 High
An HTML Injection vulnerability in Avaya Spaces may have allowed disclosure of sensitive information or modification of the page content seen by the user.
CVE-2025-29932 1 Jetbrains 1 Goland 2025-09-30 4.1 Medium
In JetBrains GoLand before 2025.1 an XXE during debugging was possible
CVE-2025-30232 1 Exim 1 Exim 2025-09-30 8.1 High
A use-after-free in Exim 4.96 through 4.98.1 could allow users (with command-line access) to escalate privileges.
CVE-2025-32054 1 Jetbrains 1 Intellij Idea 2025-09-30 3.3 Low
In JetBrains IntelliJ IDEA before 2024.3, 2024.2.4 source code could be logged in the idea.log file
CVE-2024-52974 1 Elastic 1 Kibana 2025-09-30 6.5 Medium
An issue has been identified where a specially crafted request sent to an Observability API could cause the kibana server to crash. A successful attack requires a malicious user to have read permissions for Observability assigned to them.
CVE-2024-52980 1 Elastic 1 Elasticsearch 2025-09-30 6.5 Medium
A flaw was discovered in Elasticsearch, where a large recursion using the innerForbidCircularReferences function of the PatternBank class could cause the Elasticsearch node to crash. A successful attack requires a malicious user to have read_pipeline Elasticsearch cluster privilege assigned to them.