Search

Search Results (365306 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-2193 1 Mrcms 1 Mrcms 2025-04-09 5.4 Medium
A vulnerability has been found in MRCMS 3.1.2 and classified as critical. This vulnerability affects the function delete of the file /admin/file/delete.do of the component org.marker.mushroom.controller.FileController. The manipulation of the argument path/name leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-2194 1 Mrcms 1 Mrcms 2025-04-09 3.5 Low
A vulnerability was found in MRCMS 3.1.2 and classified as problematic. This issue affects the function list of the file /admin/file/list.do of the component org.marker.mushroom.controller.FileController. The manipulation of the argument path leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-2195 1 Mrcms 1 Mrcms 2025-04-09 3.5 Low
A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is the function rename of the file /admin/file/rename.do of the component org.marker.mushroom.controller.FileController. The manipulation of the argument name/path leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2022-4724 1 Ikus-soft 1 Rdiffweb 2025-04-09 9.8 Critical
Improper Access Control in GitHub repository ikus060/rdiffweb prior to 2.5.5.
CVE-2022-4723 1 Ikus-soft 1 Rdiffweb 2025-04-09 6.5 Medium
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.5.
CVE-2022-4722 1 Ikus-soft 1 Rdiffweb 2025-04-09 7.2 High
Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5.
CVE-2022-4721 1 Ikus-soft 1 Rdiffweb 2025-04-09 5.4 Medium
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository ikus060/rdiffweb prior to 2.5.5.
CVE-2022-4720 1 Ikus-soft 1 Rdiffweb 2025-04-09 6.1 Medium
Open Redirect in GitHub repository ikus060/rdiffweb prior to 2.5.5.
CVE-2022-4719 1 Ikus-soft 1 Rdiffweb 2025-04-09 9.8 Critical
Business Logic Errors in GitHub repository ikus060/rdiffweb prior to 2.5.5.
CVE-2024-31108 1 Iflychat 1 Iflychat 2025-04-09 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iFlyChat Team iFlyChat – WordPress Chat iflychat allows Stored XSS.This issue affects iFlyChat – WordPress Chat: from n/a through 4.7.2.
CVE-2022-4695 1 Usememos 1 Memos 2025-04-09 5.4 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.
CVE-2022-4694 1 Usememos 1 Memos 2025-04-09 5.4 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.
CVE-2022-4692 1 Usememos 1 Memos 2025-04-09 5.4 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.0.
CVE-2022-4688 1 Usememos 1 Memos 2025-04-09 8.8 High
Improper Authorization in GitHub repository usememos/memos prior to 0.9.0.
CVE-2023-5457 1 Ailux 1 Imx6 2025-04-09 7.5 High
A CWE-1269 “Product Released in Non-Release Configuration” vulnerability in the Django web framework used by the web application (due to the “debug” configuration parameter set to “True”) allows a remote unauthenticated attacker to access critical information and have other unspecified impacts to the confidentiality, integrity, and availability of the application. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.
CVE-2022-4687 1 Usememos 1 Memos 2025-04-09 8.1 High
Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.0.
CVE-2022-4686 1 Usememos 1 Memos 2025-04-09 9.8 Critical
Authorization Bypass Through User-Controlled Key in GitHub repository usememos/memos prior to 0.9.0.
CVE-2022-4684 1 Usememos 1 Memos 2025-04-09 8.8 High
Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.
CVE-2025-3119 1 Oretnom23 1 Online Tutor Portal 2025-04-09 6.3 Medium
A vulnerability was found in SourceCodester Online Tutor Portal 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /tutor/courses/manage_course.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-3137 1 Phpgurukul 1 Online Security Guards Hiring System 2025-04-09 7.3 High
A vulnerability, which was classified as critical, was found in PHPGurukul Online Security Guards Hiring System 1.0. Affected is an unknown function of the file /admin/changeimage.php. The manipulation of the argument editid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.