CVE-2026-48907 · 2026-07-14 · pending_review
Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users.
CVE-2026-45659 · 2026-07-14 · pending_review
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
CVE-2026-34197 · 2026-07-14 · pending_review
Apache ActiveMQ contains an improper input validation vulnerability that allows for code injection.
CVE-2026-32201 · 2026-07-14 · pending_review
Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network.
CVE-2026-20963 · 2026-07-14 · pending_review
Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network.
CVE-2025-68645 · 2026-07-14 · pending_review
Synacor Zimbra Collaboration Suite (ZCS) contains a PHP remote file inclusion vulnerability that could allow for remote attackers to craft requests to the /h/rest endpoint to influence internal request dispatching, allow…
CVE-2025-54236 · 2026-07-14 · pending_review
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability that could allow an attacker to take over customer accounts through the Commerce REST API.
CVE-2025-53770 · 2026-07-15 · pending_review
Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-20…
CVE-2025-49706 · 2026-07-15 · pending_review
Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive informatio…
CVE-2025-24813 · 2026-07-15 · pending_review
Apache Tomcat contains a path equivalence vulnerability that allows a remote attacker to execute code, disclose information, or inject malicious content via a partial PUT request.
CVE-2024-4577 · 2026-07-15 · pending_review
PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823.
CVE-2024-45195 · 2026-07-15 · pending_review
Apache OFBiz contains a forced browsing vulnerability that allows a remote attacker to obtain unauthorized access.
CVE-2024-38475 · 2026-07-15 · pending_review
Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/…
CVE-2024-27348 · 2026-07-15 · pending_review
Apache HugeGraph-Server contains an improper access control vulnerability that could allow a remote attacker to execute arbitrary code.
CVE-2024-23897 · 2026-07-15 · pending_review
Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution.
CVE-2024-21182 · 2026-07-14 · pending_review
Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can resul…
CVE-2023-7028 · 2026-07-15 · pending_review
GitLab Community and Enterprise Editions contain an improper access control vulnerability. This allows an attacker to trigger password reset emails to be sent to an unverified email address to ultimately facilitate an ac…
CVE-2023-46604 · 2026-07-15 · pending_review
Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to run shell commands by manipulating serialized class types in the OpenWire pro…
CVE-2023-36845 · 2026-07-15 · pending_review
Juniper Junos OS on EX Series and SRX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control an important environment variable. Using a crafte…
CVE-2023-36844 · 2026-07-15 · pending_review
Juniper Junos OS on EX Series contains a PHP external variable modification vulnerability that allows an unauthenticated, network-based attacker to control certain, important environment variables. Using a crafted reques…
CVE-2023-33246 · 2026-07-15 · pending_review
Several components of Apache RocketMQ, including NameServer, Broker, and Controller, are exposed to the extranet and lack permission verification. An attacker can exploit this vulnerability by using the update configurat…
CVE-2023-29357 · 2026-07-15 · pending_review
Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a network attack. This atta…
CVE-2023-27524 · 2026-07-15 · pending_review
Apache Superset contains an insecure default initialization of a resource vulnerability that allows an attacker to authenticate and access unauthorized resources on installations that have not altered the default configu…
CVE-2023-23752 · 2026-07-15 · pending_review
Joomla! contains an improper access control vulnerability that allows unauthorized access to webservice endpoints.
CVE-2023-22518 · 2026-07-15 · pending_review
Atlassian Confluence Data Center and Server contain an improper authorization vulnerability that can result in significant data loss when exploited by an unauthenticated attacker. There is no impact on confidentiality si…
CVE-2023-22515 · 2026-07-15 · pending_review
Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts and access Confluence.
CVE-2023-21839 · 2026-07-15 · pending_review
Oracle WebLogic Server contains an unspecified vulnerability that allows an unauthenticated attacker with network access via T3, IIOP, to compromise Oracle WebLogic Server.
CVE-2022-33891 · 2026-07-15 · pending_review
Apache Spark contains a command injection vulnerability via Spark User Interface (UI) when Access Control Lists (ACLs) are enabled.
CVE-2022-26138 · 2026-07-15 · pending_review
Atlassian Questions For Confluence App has hard-coded credentials, exposing the username and password in plaintext. A remote unauthenticated attacker can use these credentials to log into Confluence and access all conten…
CVE-2022-24706 · 2026-07-15 · pending_review
Apache CouchDB contains an insecure default initialization of resource vulnerability which can allow an attacker to escalate to administrative privileges.
CVE-2022-24086 · 2026-07-18 · pending_review
Adobe Commerce and Magento Open Source contain an improper input validation vulnerability which can allow for arbitrary code execution.
CVE-2021-43798 · 2026-07-15 · pending_review
Grafana contains a path traversal vulnerability that could allow access to local files.
CVE-2021-40438 · 2026-07-18 · pending_review
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
CVE-2021-39935 · 2026-07-14 · pending_review
GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the CI Lint API.
CVE-2021-39226 · 2026-07-15 · pending_review
Grafana contains an authentication bypass vulnerability that allows authenticated and unauthenticated users to view and delete all snapshot data, potentially resulting in complete snapshot data loss.
CVE-2021-26086 · 2026-07-15 · pending_review
Atlassian Jira Server and Data Center contain a path traversal vulnerability that allows a remote attacker to read particular files in the /WEB-INF/web.xml endpoint.
CVE-2021-26085 · 2026-07-15 · pending_review
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a pre-authorization arbitrary file read vulnerability in the /s/ endpoint.
CVE-2021-26084 · 2026-07-18 · pending_review
Atlassian Confluence Server and Data Server contain an Object-Graph Navigation Language (OGNL) injection vulnerability that may allow an unauthenticated attacker to execute code.
CVE-2021-22175 · 2026-07-14 · pending_review
GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled.
CVE-2020-5410 · 2026-07-15 · pending_review
Spring, by VMware Tanzu, Cloud Config contains a path traversal vulnerability that allows applications to serve arbitrary configuration files.
CVE-2020-2883 · 2026-07-15 · pending_review
Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an unspecified vulnerability exploitable by an unauthenticated attacker with network access via IIOP or T3.
CVE-2020-1938 · 2026-07-15 · pending_review
Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited.
CVE-2020-17519 · 2026-07-15 · pending_review
Apache Flink contains an improper access control vulnerability that allows an attacker to read any file on the local filesystem of the JobManager through its REST interface.
CVE-2020-14883 · 2026-07-18 · pending_review
Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity, integrity, and availability.
CVE-2020-13927 · 2026-07-18 · pending_review
The previous default setting for Airflow's Experimental API was to allow all API requests without authentication.
CVE-2020-13671 · 2026-07-18 · pending_review
Improper sanitization in the extension file names is present in Drupal core.
CVE-2020-11978 · 2026-07-18 · pending_review
A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow.
CVE-2020-11738 · 2026-07-18 · pending_review
WordPress Snap Creek Duplicator plugin contains a file download vulnerability when an administrator creates a new copy of their site that allows an attacker to download the generated files from their Wordpress dashboard.…
CVE-2019-2725 · 2026-07-18 · pending_review
Injection vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).
CVE-2019-1003029 · 2026-07-15 · pending_review
Jenkins Script Security Plugin contains a protection mechanism failure, allowing an attacker to bypass the sandbox.