Search

Search Results (365306 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-30891 1 Tenda 2 Ac18, Ac18 Firmware 2025-04-10 8.8 High
A command injection vulnerability exists in /goform/exeCommand in Tenda AC18 v15.03.05.05, which allows attackers to construct cmdinput parameters for arbitrary command execution.
CVE-2024-31649 1 Oretnom23 1 Cosmetics And Beauty Product Online Store 2025-04-10 5.4 Medium
A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Product Name parameter.
CVE-2024-31650 1 Oretnom23 1 Cosmetics And Beauty Product Online Store 2025-04-10 9.6 Critical
A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Last Name parameter.
CVE-2024-31652 1 Oretnom23 1 Cosmetics And Beauty Product Online Store 2025-04-10 6.1 Medium
A cross-site scripting (XSS) in Cosmetics and Beauty Product Online Store v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search parameter.
CVE-2022-43932 1 Synology 1 Router Manager 2025-04-10 7.5 High
Improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability in CGI component in Synology Router Manager (SRM) before 1.2.5-8227-6 and 1.3.1-9346-3 allows remote attackers to read arbitrary files via unspecified vectors.
CVE-2024-24100 1 Carmelo 1 Computer Book Store 2025-04-10 8.3 High
Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via PublisherID.
CVE-2020-36640 1 Bonitasoft 1 Webservice Connector 2025-04-10 5.5 Medium
A vulnerability, which was classified as problematic, was found in bonitasoft bonita-connector-webservice up to 1.3.0. This affects the function TransformerConfigurationException of the file src/main/java/org/bonitasoft/connectors/ws/SecureWSConnector.java. The manipulation leads to xml external entity reference. Upgrading to version 1.3.1 is able to address this issue. The patch is named a12ad691c05af19e9061d7949b6b828ce48815d5. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217443.
CVE-2024-24096 2 Carmelo, Code-projects 2 Computer Book Store, Computer Book Store 2025-04-10 7.8 High
Code-projects Computer Book Store 1.0 is vulnerable to SQL Injection via BookSBIN.
CVE-2018-25065 1 Wikimedia 1 Mediawiki-extensions-i18ntags 2025-04-10 3.5 Low
A vulnerability was found in Wikimedia mediawiki-extensions-I18nTags and classified as problematic. This issue affects some unknown processing of the file I18nTags_body.php of the component Unlike Parser. The manipulation leads to cross site scripting. The attack may be initiated remotely. The identifier of the patch is b4bc3cbbb099eab50cf2b544cf577116f1867b94. It is recommended to apply a patch to fix this issue. The identifier VDB-217445 was assigned to this vulnerability.
CVE-2007-10001 1 Web-cyradm Project 1 Web-cyradm 2025-04-10 3.5 Low
A vulnerability classified as problematic has been found in web-cyradm. This affects an unknown part of the file search.php. The manipulation of the argument searchstring leads to sql injection. It is recommended to apply a patch to fix this issue. The identifier VDB-217449 was assigned to this vulnerability.
CVE-2022-48216 1 Uniswap 2 Universal Router, Universal Router Firmware 2025-04-10 7.5 High
Uniswap Universal Router before 1.1.0 mishandles reentrancy. This would have allowed theft of funds.
CVE-2022-47092 1 Gpac 1 Gpac 2025-04-10 7.1 High
GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is contains an Integer overflow vulnerability in gf_hevc_read_sps_bs_internal function of media_tools/av_parsers.c:8316
CVE-2022-47091 1 Gpac 1 Gpac 2025-04-10 7.8 High
GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow in gf_text_process_sub function of filters/load_text.c
CVE-2022-47089 1 Gpac 1 Gpac 2025-04-10 7.8 High
GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer Overflow via gf_vvc_read_sps_bs_internal function of media_tools/av_parsers.c
CVE-2022-45935 1 Apache 1 James 2025-04-10 5.5 Medium
Usage of temporary files with insecure permissions by the Apache James server allows an attacker with local access to access private user data in transit. Vulnerable components includes the SMTP stack and IMAP APPEND command. This issue affects Apache James server version 3.7.2 and prior versions.
CVE-2022-44445 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-04-10 5.5 Medium
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
CVE-2022-43844 2 Ibm, Redhat 2 Robotic Process Automation For Cloud Pak, Openshift 2025-04-10 8.8 High
IBM Robotic Process Automation for Cloud Pak 20.12 through 21.0.3 is vulnerable to broken access control. A user is not correctly redirected to the platform log out screen when logging out of IBM RPA for Cloud Pak. IBM X-Force ID: 239081.
CVE-2022-40049 1 Theme Park Ticketing System Project 1 Theme Park Ticketing System 2025-04-10 7.5 High
SQL injection vulnerability in sourcecodester Theme Park Ticketing System 1.0 allows remote attackers to view sensitive information via the id parameter to the /tpts/manage_user.php page.
CVE-2022-39073 1 Zte 2 Mf286r, Mf286r Firmware 2025-04-10 9.8 Critical
There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the vulnerability to execute arbitrary commands.
CVE-2022-39072 1 Zte 4 Mf286r, Mf286r Firmware, Mf289d and 1 more 2025-04-10 5.4 Medium
There is a SQL injection vulnerability in Some ZTE Mobile Internet products. Due to insufficient validation of the input parameters of the SNTP interface, an authenticated attacker could use the vulnerability to execute stored XSS attacks.