Export limit exceeded: 365244 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (365244 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-22547 | 1 Wayos | 2 Ibr-7150, Ibr-7150 Firmware | 2025-04-03 | 4.7 Medium |
| WayOS IBR-7150 <17.06.23 is vulnerable to Cross Site Scripting (XSS). | ||||
| CVE-2024-25385 | 1 Flvmeta | 1 Flvmeta | 2025-04-03 | 6.2 Medium |
| An issue in flvmeta v.1.2.2 allows a local attacker to cause a denial of service via the flvmeta/src/flv.c:375:21 function in flv_close. | ||||
| CVE-2024-25369 | 1 Thedaylightstudio | 1 Fuel Cms | 2025-04-03 | 6.1 Medium |
| A reflected Cross-Site Scripting (XSS) vulnerability in FUEL CMS 1.5.2allows attackers to run arbitrary code via crafted string after the group_id parameter. | ||||
| CVE-2022-25377 | 1 Appwrite | 1 Appwrite | 2025-04-03 | 7.5 High |
| The ACME-challenge endpoint in Appwrite 0.5.0 through 0.12.x before 0.12.2 allows remote attackers to read arbitrary local files via ../ directory traversal. In order to be vulnerable, APP_STORAGE_CERTIFICATES/.well-known/acme-challenge must exist on disk. (This pathname is automatically created if the user chooses to install Let's Encrypt certificates via Appwrite.) | ||||
| CVE-2024-24095 | 1 Code-projects | 1 Simple Stock System | 2025-04-03 | 9.8 Critical |
| Code-projects Simple Stock System 1.0 is vulnerable to SQL Injection. | ||||
| CVE-2024-24099 | 1 Code-projects | 1 Scholars Tracking System | 2025-04-03 | 5.4 Medium |
| Code-projects Scholars Tracking System 1.0 is vulnerable to SQL Injection under Employment Status Information Update. | ||||
| CVE-2023-41015 | 1 Code-projects | 1 Online Job Portal | 2025-04-03 | 5.5 Medium |
| code-projects.org Online Job Portal 1.0 is vulnerable to SQL Injection via /Employer/DeleteJob.php?JobId=1. | ||||
| CVE-2024-28338 | 1 Totolink | 2 A8000ru, A8000ru Firmware | 2025-04-03 | 8.0 High |
| A login bypass in TOTOLINK A8000RU V7.1cu.643_B20200521 allows attackers to login to Administrator accounts via providing a crafted session cookie. | ||||
| CVE-2023-42308 | 1 Code-projects | 1 Exam Form Submission | 2025-04-03 | 6.1 Medium |
| Cross Site Scripting (XSS) vulnerability in Manage Fastrack Subjects in Code-Projects Exam Form Submission 1.0 allows attackers to run arbitrary code via the "Subject Name" and "Subject Code" Section. | ||||
| CVE-2022-4751 | 1 Back2nature | 1 Word Balloon | 2025-04-03 | 5.4 Medium |
| The Word Balloon WordPress plugin before 4.19.3 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | ||||
| CVE-2022-4745 | 1 Wp-customerarea | 1 Wp Customer Area | 2025-04-03 | 6.1 Medium |
| The WP Customer Area WordPress plugin before 8.1.4 does not have CSRF checks when performing some actions such as chmod, mkdir and copy, which could allow attackers to make a logged-in admin perform them and create arbitrary folders, copy file for example. | ||||
| CVE-2021-29368 | 1 Cuppacms | 1 Cuppacms | 2025-04-03 | 8.8 High |
| Session fixation vulnerability in CuppaCMS thru commit 4c9b742b23b924cf4c1f943f48b278e06a17e297 on November 12, 2019 allows attackers to gain access to arbitrary user sessions. | ||||
| CVE-2020-36659 | 2 Debian, Lemonldap-ng | 2 Debian Linux, Apache\ | 2025-04-03 | 8.1 High |
| In Apache::Session::Browseable before 1.3.6, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for example, be fixed in conjunction with the CVE-2020-16093 fix. | ||||
| CVE-2020-21152 | 1 Inxedu | 1 Inxedu | 2025-04-03 | 9.8 Critical |
| SQL Injection vulnerability in inxedu 2.0.6 allows attackers to execute arbitrary commands via the functionIds parameter to /saverolefunction. | ||||
| CVE-2024-24092 | 1 Code-projects | 1 Scholars Tracking System | 2025-04-03 | 7.8 High |
| SQL Injection vulnerability in Code-projects.org Scholars Tracking System 1.0 allows attackers to run arbitrary code via login.php. | ||||
| CVE-2024-24093 | 1 Code-projects | 1 Scholars Tracking System | 2025-04-03 | 9.8 Critical |
| SQL Injection vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via Personal Information Update information. | ||||
| CVE-2024-24097 | 1 Code-projects | 1 Scholars Tracking System | 2025-04-03 | 5.4 Medium |
| Cross Site Scripting (XSS) vulnerability in Code-projects Scholars Tracking System 1.0 allows attackers to run arbitrary code via the News Feed. | ||||
| CVE-2024-12982 | 1 Phpgurukul | 1 Blood Bank \& Donor Management System | 2025-04-03 | 2.4 Low |
| A vulnerability was found in PHPGurukul Blood Bank & Donor Management System 2.4. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /bbdms/admin/update-contactinfo.php. The manipulation of the argument Address leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2025-30346 | 2 Varnish-software, Varnish Cache Project | 2 Varnish Enterprise, Varnish Cache | 2025-04-03 | 5.4 Medium |
| Varnish Cache before 7.6.2 and Varnish Enterprise before 6.0.13r10 allow client-side desync via HTTP/1 requests. | ||||
| CVE-2022-47990 | 1 Ibm | 2 Aix, Vios | 2025-04-03 | 6.2 Medium |
| IBM AIX 7.1, 7.2, 7.3 and VIOS , 3.1 could allow a non-privileged local user to exploit a vulnerability in X11 to cause a buffer overflow that could result in a denial of service or arbitrary code execution. IBM X-Force ID: 243556. | ||||