Export limit exceeded: 370925 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (370925 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-60060 | 1 Teraterm Project | 1 Ttssh2 | 2026-07-27 | N/A |
| Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents of adjacent memory regions may be transmitted to the server, and Tera Term may behave unexpected or terminate abnormally. | ||||
| CVE-2026-58317 | 1 Teraterm Project | 1 Ttssh2 | 2026-07-27 | N/A |
| Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempts to establish an SSH connection to a server set up by an attacker, out-of-bounds read/write may occur. As a result, the contents of adjacent memory regions may be transmitted to the server, and Tera Term may behave unexpected or terminate abnormally. | ||||
| CVE-2024-23564 | 1 Hcl Software | 1 Aftermarket Epc | 2026-07-27 | 9.1 Critical |
| HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server and redirect them to their own email address by manipulating the server's response. The application includes checks in the initial requests to verify the validity of the provided UserId, but similar validation is not applied to Email requests when sending passwords to user emails. | ||||
| CVE-2024-23567 | 1 Hclsoftware | 1 Aftermarket Epc | 2026-07-27 | 4.3 Medium |
| HCL Aftermarket EPC is affected by Sensitive Information in GET method & in URL which allows application to pass sensitive data via URL parameters during normal usage. Data passed in this manner can be exposed because it may end up stored in unintended locations, including server logs, local browser history and proxy logs. | ||||
| CVE-2024-23573 | 1 Hclsoftware | 1 Aftermarket Epc | 2026-07-27 | 3.7 Low |
| HCL Aftermarket EPC is vulnerable to attack since the Application is vulnerable to Lucky 13. that makes the SS LLUCKY13 possible affects the TLS1.1and 1.2 and DTLS1.0 or 1.2 implementations . It also affects previous versions such as SSL3.0 and TLS1.0. This can also be considered a type of man-in-the-middle attack. | ||||
| CVE-2024-23571 | 1 Hclsoftware | 1 Aftermarket Epc | 2026-07-27 | 4.3 Medium |
| HCL Aftermarket EPC is vulnerable to attack since the application does not have an appropriate caching policy specifying the extent to which the page and its form fields should be cached. If sensitive information in application responses is stored in the local cache, then this may be retrieved by other users who have access to the same computer at a future time. | ||||
| CVE-2024-42214 | 1 Hclsoftware | 1 Aftermarket Epc | 2026-07-27 | 5.3 Medium |
| HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the methods that are supported by the Web server which allows an attacker to narrow and intensify their efforts. | ||||
| CVE-2024-23569 | 1 Hclsoftware | 1 Aftermarket Epc | 2026-07-27 | 4.3 Medium |
| HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header | ||||
| CVE-2026-8505 | 1 Ibm | 1 Langflow Oss | 2026-07-27 | 9.8 Critical |
| IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the WEBHOOK_AUTH_ENABLE configuration is set to False (which is the default setting). This allows a remote attacker who knows a flow's UUID to execute it as if they were the owner, potentially leading to Remote Code Execution (RCE). | ||||
| CVE-2026-65448 | 2026-07-27 | 6.5 Medium | ||
| Unauthenticated Cross Site Scripting (XSS) in Anti Spam and list cleaner – AcyChecker <= 1.8.1 versions. | ||||
| CVE-2026-65447 | 2026-07-27 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.6 versions. | ||||
| CVE-2026-65446 | 2026-07-27 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Kali Forms <= 2.4.18 versions. | ||||
| CVE-2026-65445 | 2026-07-27 | 6.5 Medium | ||
| Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions. | ||||
| CVE-2026-65443 | 2026-07-27 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in BackWPup <= 5.7.4 versions. | ||||
| CVE-2026-65442 | 2026-07-27 | 7.2 High | ||
| Unauthenticated Server Side Request Forgery (SSRF) in FormCraft <= 3.9.15 versions. | ||||
| CVE-2026-65441 | 2026-07-27 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.3 versions. | ||||
| CVE-2026-65440 | 2026-07-27 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in GetGenie <= 4.4.3 versions. | ||||
| CVE-2026-65439 | 2026-07-27 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <=3.5.45 versions. | ||||
| CVE-2026-65438 | 2026-07-27 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Message Filter for Contact Form 7 <= 1.6.3.9 versions. | ||||
| CVE-2026-65437 | 2026-07-27 | 7.1 High | ||
| Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions. | ||||