CVE.report search for "CVE-2025-32277"

Listed below are 50 relevant search results for "CVE-2025-32277" based on Vendor, Software, and CVE description

These results are gathered from attempted matches with listed vendor and software data, as well as a keyword search in the description of all known CVEs.

If you notice a "Not Listed" in either the vendor or software columns, the underlying source record does not currently include normalized affected-product data.

Search Results

CVE ID Vendor Software Description
CVE-2026-49448authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be b...
CVE-2026-49443authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the abil...
CVE-2026-49384JetbrainsPycharmIn JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible
CVE-2026-49377JetbrainsTeamcityIn JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
CVE-2026-49375JetbrainsTeamcityIn JetBrains TeamCity before 2026.1, 2025.11.5 reflected XSS was possible on the repository download page
CVE-2026-49372JetbrainsTeamcityIn JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible
CVE-2026-49325Improper handling of physical conditions in the bike-shutdown control of the Indian Motorcycle Scout Bobber + Tech 2025 model...
CVE-2026-49324Uncontrolled resource consumption in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 mode...
CVE-2026-49323Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcycle Sc...
CVE-2026-49322Weak authentication in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows ...
CVE-2026-49318Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model ...
CVE-2026-49317Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model ...
CVE-2026-49316Expected behavior violation in the in-vehicle network of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an ...
CVE-2026-49237AppleMacosAn issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-5199. Wh...
CVE-2026-48726ApacheAirflowA bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked logout ...
CVE-2026-48208An improper neutralization of active SVG content in OTRS or ((OTRS)) Community Edition ticket article rendering allows attack...
CVE-2026-48191An incorrect handling of permissions in STORM powered by OTRS and in OTRS (2026.x and above) Document Search Article Meta Fil...
CVE-2026-48190An incorrect handling of permissions in OTRS External Interface and the ConfigItem List module allows an authenticated custom...
CVE-2026-48189An improper Input Validation vulnerability in OTRS Customer Backend module allows to access customer information which are re...
CVE-2026-48188An improper Input Validation vulnerability in OTRS or ((OTRS)) Community Edition database layer module allows an unauthentic...
CVE-2026-48187An uncontrolled allocation of resources without limits or throttling in the e-mail handling in OTRS allows excessive allocati...
CVE-2026-47324ProjectsAndPrograms school-management-system is vulnerable to Stored Cross‑Site Scripting (XSS) in multiple attributes of s...
CVE-2026-47323Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering The CXF and Knative HeaderFilterStrategy ...
CVE-2026-47201authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Source A...
CVE-2026-46368luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed...
CVE-2026-46124In the Linux kernel, the following vulnerability has been resolved: isofs: validate block number from NFS file handle in iso...
CVE-2026-46055In the Linux kernel, the following vulnerability has been resolved: apparmor: Fix string overrun due to missing termination ...
CVE-2026-44413JetbrainsTeamcityIn JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access
CVE-2026-43899DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-bet...
CVE-2026-43347LinuxLinux KernelIn the Linux kernel, the following vulnerability has been resolved: arm64: dts: qcom: monaco: Reserve full Gunyah metadata r...
CVE-2026-43322LinuxLinux KernelIn the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Fix UAF in le_read_features_complet...
CVE-2026-43247LinuxLinux KernelIn the Linux kernel, the following vulnerability has been resolved: media: chips-media: wave5: Fix SError of kernel panic wh...
CVE-2026-43164LinuxLinux KernelIn the Linux kernel, the following vulnerability has been resolved: udplite: Fix null-ptr-deref in __udp_enqueue_schedule_sk...
CVE-2026-42960NlnetlabsUnboundNLnet Labs Unbound up to and including version 1.25.0 is vulnerable to poisoning via promiscuous records for the authority se...
CVE-2026-42879FacturaScripts is an open source accounting and invoicing software. In 2025.81 and earlier, an authenticated unrestricted fil...
CVE-2026-42877FacturaScripts is an open source accounting and invoicing software. In 2025.92 and earlier, a stored Cross-Site Scripting (XS...
CVE-2026-42849authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of stages ...
CVE-2026-42467An issue was discovered in Open-SAE-J1939 thru commit b6caf884df46435e539b1ecbf92b6c29b345bdfe (2025-11-30) in SAE_J1939_Read...
CVE-2026-42360ApacheAirflowA bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g. nested `password` / `tok...
CVE-2026-42339NewapiNew ApiNew API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. In versions 0.11.9-a...
CVE-2026-42252ApacheAirflowApache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") showed a ...
CVE-2026-42043AxiosAxiosAxios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influence t...
CVE-2026-41903FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user holding t...
CVE-2026-41882JetbrainsIntellij IdeaIn JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files ...
CVE-2026-41577authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response processor (...
CVE-2026-41321@astrojs/cloudflare is an SSR adapter for use with Cloudflare Workers targets. Prior to 13.1.10, the fetch() call for remote ...
CVE-2026-40453ApacheCamelThe fix for CVE-2025-27636 added setLowerCase(true) to HttpHeaderFilterStrategy so that case-variant header names such as 'CA...
CVE-2026-40165authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2 were ...
CVE-2026-40046Integer Overflow or Wraparound vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ MQTT. The fix for "CVE...
CVE-2026-40035RyandfirUnfurlUnfurl through 2025.08 contains an improper input validation vulnerability in config parsing that enables Flask debug mode by...
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report