A vulnerability labeled as problematic has been found in CA17 TeamsACS 1.0.1. Affected is an unknown function. The manipulation of the argument errmsg results in cross site scripting.
This vulnerability was named CVE-2024-22780. The attack may be performed from remote. There is no available exploit.
A vulnerability identified as critical has been detected in Dolibarr ERP CRM up to 19.0.0. Impacted is an unknown function. The manipulation leads to code injection.
This vulnerability is documented as CVE-2024-29477. The attack requires being on the local network. There is not any exploit available.
A vulnerability, which was classified as problematic, has been found in Ladder up to 0.0.21. This vulnerability affects unknown code of the component API. This manipulation causes information disclosure.
This vulnerability appears as CVE-2024-27620. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability was found in ThreeTen Backport 1.6.8. It has been declared as critical. Affected by this vulnerability is the function org.threeten.bp.format.DateTimeFormatter::parse. The manipulation results in integer overflow.
This vulnerability is identified as CVE-2024-23082. The attack can only be performed from the local network. There is not any exploit available.
A vulnerability identified as problematic has been detected in JGraphT Core 1.5.2. This vulnerability affects the function org.jgrapht.alg.util.ToleranceDoubleComparator::compare. Performing a manipulation results in incorrect comparison.
This vulnerability is cataloged as CVE-2024-23078. The attack must originate from the local network. There is no exploit available.
A vulnerability marked as problematic has been reported in ImageMagick. Affected by this issue is some unknown functionality of the component VIFF Encoder. Performing a manipulation results in memory leak.
This vulnerability is cataloged as CVE-2026-61870. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability labeled as problematic has been found in parse-community parse-server up to 8.6.83/9.0.0-9.10.0-alpha.2. Affected by this vulnerability is an unknown functionality of the component FileUpload. Such manipulation of the argument content-type leads to cross site scripting.
This vulnerability is listed as CVE-2026-61448. The attack may be performed from remote. There is no available exploit.
A vulnerability identified as problematic has been detected in getgrav Grav Plugin up to 2.0.3. Affected is an unknown function of the file /grav/admin of the component Admin2. This manipulation causes information disclosure.
This vulnerability is tracked as CVE-2026-61454. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability categorized as critical has been discovered in ImageMagick up to 7.1.2-25. This impacts an unknown function of the component APNG Encoder. The manipulation results in encoding error.
This vulnerability is identified as CVE-2026-61858. The attack can be executed remotely. There is not any exploit available.
A vulnerability was found in ImageMagick. It has been rated as critical. This affects an unknown function of the component XMP Handler. The manipulation leads to use after free.
This vulnerability is referenced as CVE-2026-61857. Remote exploitation of the attack is possible. No exploit is available.
The Australian Cyber Security Centre (ACSC) issued an alert about a global exploitation campaign targeting vulnerable content management systems (CMS) and plugins. [...]
Currently trending CVE - Hype Score: 4 - scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
Currently trending CVE - Hype Score: 4 - sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
Currently trending CVE - Hype Score: 4 - In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
Currently trending CVE - Hype Score: 6 - Authentication Bypass by Spoofing vulnerability in Apache APISIX.
The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin.
This issue affects Apache APISIX: from v2.2 through v3.16.0.
Users are recommended to upgrade to ...
Currently trending CVE - Hype Score: 7 - A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to read source code from private repositories they did not have access to. The
Copilot pull request description diff summary endpoint accepted a ...