Latest CVE Feed
-
7.8
HIGHCVE-2024-7672
A maliciously crafted DWF file, when parsed in dwfcore.dll through Autodesk Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrar... Read more
- Published: Sep. 30, 2024
- Modified: Aug. 26, 2025
-
4.9
MEDIUMCVE-2024-38360
Discourse is an open source platform for community discussion. In affected versions by creating replacement words with an almost unlimited number of characters, a moderator can reduce the availability of a Discourse instance. This issue has been addressed... Read more
Affected Products : discourse- Published: Jul. 15, 2024
- Modified: Aug. 26, 2025
-
8.8
HIGHCVE-2024-6714
An issue was discovered in provd before version 0.1.5 with a setuid binary, which allows a local attacker to escalate their privilege.... Read more
- Published: Jul. 23, 2024
- Modified: Aug. 26, 2025
-
4.3
MEDIUMCVE-2024-55893
TYPO3 is a free and open source Content Management Framework. A vulnerability has been identified in the backend user interface functionality involving deep links. Specifically, this functionality is susceptible to Cross-Site Request Forgery (CSRF). Addit... Read more
Affected Products : typo3- Published: Jan. 14, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.7
MEDIUMCVE-2024-24912
A local privilege escalation vulnerability has been identified in Harmony Endpoint Security Client for Windows versions E88.10 and below. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged code on the targ... Read more
- Published: May. 01, 2024
- Modified: Aug. 26, 2025
-
6.1
MEDIUMCVE-2024-55892
TYPO3 is a free and open source Content Management Framework. Applications that use `TYPO3\CMS\Core\Http\Uri` to parse externally provided URLs (e.g., via a query parameter) and validate the host of the parsed URL may be vulnerable to open redirect or SSR... Read more
Affected Products : typo3- Published: Jan. 14, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Server-Side Request Forgery
-
7.5
HIGHCVE-2024-32979
Nautobot is a Network Source of Truth and Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. It was discovered that due to improper handling and escaping of user-provided query para... Read more
Affected Products : nautobot- Published: May. 01, 2024
- Modified: Aug. 26, 2025
-
5.3
MEDIUMCVE-2024-55891
TYPO3 is a free and open source Content Management Framework. It has been discovered that the install tool password has been logged as plaintext in case the password hashing mechanism used for the password was incorrect. Users are advised to update to TYP... Read more
Affected Products : typo3- Published: Jan. 14, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Misconfiguration
-
6.1
MEDIUMCVE-2025-27506
NocoDB is software for building databases as spreadsheets. The API endpoint related to the password reset function is vulnerable to Reflected Cross-Site-Scripting. The endpoint /api/v1/db/auth/password/reset/:tokenId is vulnerable to Reflected Cross-Site-... Read more
- Published: Mar. 06, 2025
- Modified: Aug. 26, 2025
- Vuln Type: Cross-Site Scripting
-
4.2
MEDIUMCVE-2024-32963
Navidrome is an open source web-based music collection server and streamer. In affected versions of Navidrome are subject to a parameter tampering vulnerability where an attacker has the ability to manipulate parameter values in the HTTP requests. The att... Read more
Affected Products : navidrome- Published: May. 01, 2024
- Modified: Aug. 26, 2025
-
7.6
HIGHCVE-2023-49781
NocoDB is software for building databases as spreadsheets. Prior to 0.202.9, a stored cross-site scripting vulnerability exists within the Formula virtual cell comments functionality. The nc-gui/components/virtual-cell/Formula.vue displays a v-html tag wi... Read more
- Published: May. 14, 2024
- Modified: Aug. 26, 2025
-
5.7
MEDIUMCVE-2023-50717
NocoDB is software for building databases as spreadsheets. Starting in verson 0.202.6 and prior to version 0.202.10, an attacker can upload a html file with malicious content. If user tries to open that file in browser malicious scripts can be executed le... Read more
- Published: May. 14, 2024
- Modified: Aug. 26, 2025
-
6.5
MEDIUMCVE-2023-50718
NocoDB is software for building databases as spreadsheets. Prior to version 0.202.10, an authenticated attacker with create access could conduct a SQL Injection attack on MySQL DB using unescaped `table_name`. This vulnerability may result in leakage of s... Read more
- Published: May. 14, 2024
- Modified: Aug. 26, 2025
-
9.1
CRITICALCVE-2022-2339
With this SSRF vulnerability, an attacker can reach internal addresses to make a request as the server and read it's contents. This attack can lead to leak of sensitive information.... Read more
- EPSS Score: %0.72
- Published: Jul. 07, 2022
- Modified: Aug. 26, 2025
-
6.5
MEDIUMCVE-2023-5104
Improper Input Validation in GitHub repository nocodb/nocodb prior to 0.96.0.... Read more
- EPSS Score: %0.62
- Published: Sep. 21, 2023
- Modified: Aug. 26, 2025
-
7.3
HIGHCVE-2022-3423
Allocation of Resources Without Limits or Throttling in GitHub repository nocodb/nocodb prior to 0.92.0. ... Read more
- EPSS Score: %1.40
- Published: Oct. 07, 2022
- Modified: Aug. 26, 2025
-
6.5
MEDIUMCVE-2023-43794
Nocodb is an open source Airtable alternative. Affected versions of nocodb contain a SQL injection vulnerability, that allows an authenticated attacker with creator access to query the underlying database. By supplying a specially crafted payload to the g... Read more
- EPSS Score: %0.22
- Published: Oct. 17, 2023
- Modified: Aug. 26, 2025
-
8.0
HIGHCVE-2022-22121
In NocoDB, versions 0.81.0 through 0.83.8 are affected by CSV Injection vulnerability (Formula Injection). A low privileged attacker can create a new table to inject payloads in the table rows. When an administrator accesses the User Management endpoint a... Read more
- EPSS Score: %0.43
- Published: Jan. 10, 2022
- Modified: Aug. 26, 2025
-
9.1
CRITICALCVE-2022-2062
Generation of Error Message Containing Sensitive Information in GitHub repository nocodb/nocodb prior to 0.91.7+.... Read more
- EPSS Score: %1.15
- Published: Jun. 13, 2022
- Modified: Aug. 26, 2025
-
9.1
CRITICALCVE-2022-2064
Insufficient Session Expiration in GitHub repository nocodb/nocodb prior to 0.91.7+.... Read more
- EPSS Score: %0.30
- Published: Jun. 13, 2022
- Modified: Aug. 26, 2025