Export limit exceeded: 23901 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 23901 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 23901 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (23901 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-10434 | 1 Tenda | 2 Ac1206, Ac1206 Firmware | 2024-11-01 | 8.8 High |
| A vulnerability was found in Tenda AC1206 up to 20241027. It has been classified as critical. This affects the function ate_Tenda_mfg_check_usb/ate_Tenda_mfg_check_usb3 of the file /goform/ate. The manipulation of the argument arg leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2024-10380 | 1 Mayurik | 1 Petrol Pump Management | 2024-11-01 | 6.3 Medium |
| A vulnerability, which was classified as critical, has been found in SourceCodester Petrol Pump Management Software 1.0. Affected by this issue is some unknown functionality of the file /admin/ajax_product.php. The manipulation of the argument drop_services leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2024-5823 | 1 Gaizhenbiao | 1 Chuanhuchatgpt | 2024-10-31 | 9.1 Critical |
| A file overwrite vulnerability exists in gaizhenbiao/chuanhuchatgpt versions <= 20240410. This vulnerability allows an attacker to gain unauthorized access to overwrite critical configuration files within the system. Exploiting this vulnerability can lead to unauthorized changes in system behavior or security settings. Additionally, tampering with these configuration files can result in a denial of service (DoS) condition, disrupting normal system operation. | ||||
| CVE-2022-30357 | 1 Ovaledge | 1 Ovaledge | 2024-10-31 | 9.8 Critical |
| OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /profile/updateProfile via the userId and email parameters. Authentication is required. | ||||
| CVE-2022-30358 | 1 Ovaledge | 1 Ovaledge | 2024-10-31 | 8.8 High |
| OvalEdge 5.2.8.0 and earlier is affected by an Account Takeover vulnerability via a POST request to /user/updatePassword via the userId and newPsw parameters. Authentication is required. | ||||
| CVE-2022-30360 | 1 Ovaledge | 1 Ovaledge | 2024-10-31 | 5.4 Medium |
| OvalEdge 5.2.8.0 and earlier is affected by multiple Stored XSS (AKA Persistent or Type II) vulnerabilities via a POST request to /profile/updateProfile via the slackid or phone parameters. Authentication is required. | ||||
| CVE-2022-30359 | 1 Ovaledge | 1 Ovaledge | 2024-10-31 | 5.4 Medium |
| OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserList. Authentication is required. The information disclosed is associated with the all registered users, including user ID, status, email address, role(s), user type, license type, and personal details such as first name, last name, gender, and user preferences. | ||||
| CVE-2022-30361 | 1 Ovaledge | 1 Ovaledge | 2024-10-31 | 4.3 Medium |
| OvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserType. No authentication is required. The information disclosed is associated with the registered user ID, status, email address, role(s), user type, license type, and personal details such as first name, last name, gender, and user preferences. | ||||
| CVE-2022-30356 | 1 Ovaledge | 1 Ovaledge | 2024-10-31 | 8.8 High |
| OvalEdge 5.2.8.0 and earlier is affected by a Privilege Escalation vulnerability via a POST request to /user/assignuserrole via the userid and role parameters . Authentication is required with OE_ADMIN role privilege. | ||||
| CVE-2024-48230 | 1 Funadmin | 1 Funadmin | 2024-10-31 | 9.8 Critical |
| funadmin 5.0.2 is vulnerable to SQL Injection via the parentField parameter in the index method of \backend\controller\auth\Auth.php. | ||||
| CVE-2024-48229 | 1 Funadmin | 1 Funadmin | 2024-10-31 | 9.8 Critical |
| funadmin 5.0.2 has a SQL injection vulnerability in the Curd one click command mode plugin. | ||||
| CVE-2024-48227 | 1 Funadmin | 1 Funadmin | 2024-10-31 | 7.5 High |
| Funadmin 5.0.2 has a logical flaw in the Curd one click command deletion function, which can result in a Denial of Service (DOS). | ||||
| CVE-2024-48223 | 1 Funadmin | 1 Funadmin | 2024-10-31 | 9.8 Critical |
| Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/fieldlist. | ||||
| CVE-2024-48222 | 1 Funadmin | 1 Funadmin | 2024-10-31 | 9.8 Critical |
| Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/edit. | ||||
| CVE-2024-48218 | 1 Funadmin | 1 Funadmin | 2024-10-31 | 9.8 Critical |
| Funadmin v5.0.2 has a SQL injection vulnerability in /curd/table/list. | ||||
| CVE-2024-48226 | 1 Funadmin | 1 Funadmin | 2024-10-31 | 9.8 Critical |
| Funadmin 5.0.2 is vulnerable to SQL Injection in curd/table/savefield. | ||||
| CVE-2024-48225 | 1 Funadmin | 1 Funadmin | 2024-10-31 | 9.1 Critical |
| Funadmin v5.0.2 has an arbitrary file deletion vulnerability in /curd/index/delfile. | ||||
| CVE-2024-48224 | 1 Funadmin | 1 Funadmin | 2024-10-31 | 7.5 High |
| Funadmin v5.0.2 has an arbitrary file read vulnerability in /curd/index/editfile. | ||||
| CVE-2024-8013 | 1 Mongodb | 2 Mongo Crypt V1.so, Mongocryptd | 2024-10-31 | 2.2 Low |
| A bug in query analysis of certain complex self-referential $lookup subpipelines may result in literal values in expressions for encrypted fields to be sent to the server as plaintext instead of ciphertext. Should this occur, no documents would be returned or written. This issue affects mongocryptd binary (v5.0 versions prior to 5.0.29, v6.0 versions prior to 6.0.17, v7.0 versions prior to 7.0.12 and v7.3 versions prior to 7.3.4) and mongo_crypt_v1.so shared libraries (v6.0 versions prior to 6.0.17, v7.0 versions prior to 7.0.12 and v7.3 versions prior to 7.3.4) released alongside MongoDB Enterprise Server versions. | ||||
| CVE-2024-10449 | 1 Codezips | 1 Hospital Appointment System | 2024-10-31 | 7.3 High |
| A vulnerability, which was classified as critical, was found in Codezips Hospital Appointment System 1.0. This affects an unknown part of the file /loginAction.php. The manipulation of the argument Username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | ||||