Search

Search Results (47013 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-25052 1 Openatom 1 Openharmony 2025-05-09 3.3 Low
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through buffer overflow.
CVE-2025-25218 1 Openatom 1 Openharmony 2025-05-09 3.3 Low
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.
CVE-2024-21402 1 Microsoft 1 365 Apps 2025-05-09 7.1 High
Microsoft Outlook Elevation of Privilege Vulnerability
CVE-2024-21396 1 Microsoft 1 Dynamics 365 2025-05-09 7.6 High
Dynamics 365 Sales Spoofing Vulnerability
CVE-2024-21327 1 Microsoft 1 Dynamics 365 2025-05-09 7.6 High
Microsoft Dynamics 365 Customer Engagement Cross-Site Scripting Vulnerability
CVE-2022-33180 1 Broadcom 1 Fabric Operating System 2025-05-09 5.5 Medium
A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5 could allow a local authenticated attacker to export out sensitive files with “seccryptocfg”, “configupload”.
CVE-2022-33179 1 Broadcom 1 Fabric Operating System 2025-05-09 8.8 High
A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, and 7.4.2j could allow a local authenticated user to break out of restricted shells with “set context” and escalate privileges.
CVE-2022-31468 1 Open-xchange 1 Ox App Suite 2025-05-09 6.1 Medium
OX App Suite through 8.2 allows XSS via an attachment or OX Drive content when a client uses the len or off parameter.
CVE-2022-28170 1 Broadcom 1 Fabric Operating System 2025-05-09 6.5 Medium
Brocade Fabric OS Web Application services before Brocade Fabric v9.1.0, v9.0.1e, v8.2.3c, v7.4.2j store server and user passwords in the debug statements. This could allow a local user to extract the passwords from a debug file.
CVE-2022-28169 1 Broadcom 1 Fabric Operating System 2025-05-09 8.8 High
Brocade Webtools in Brocade Fabric OS versions before Brocade Fabric OS versions v9.1.1, v9.0.1e, and v8.2.3c could allow a low privilege webtools, user, to gain elevated admin rights, or privileges, beyond what is intended or entitled for that user. By exploiting this vulnerability, a user whose role is not an admin can create a new user with an admin role using the operator session id. The issue was replicated after intercepting the admin, and operator authorization headers sent unencrypted and editing a user addition request to use the operator's authorization header.
CVE-2022-3327 1 Ikus-soft 1 Rdiffweb 2025-05-09 9.8 Critical
Missing Authentication for Critical Function in GitHub repository ikus060/rdiffweb prior to 2.5.0a6.
CVE-2022-35860 1 Corsair 2 K63, K63 Firmware 2025-05-09 6.8 Medium
Missing AES encryption in Corsair K63 Wireless 3.1.3 allows physically proximate attackers to inject and sniff keystrokes via 2.4 GHz radio transmissions.
CVE-2022-3607 1 Octoprint 1 Octoprint 2025-05-09 6.0 Medium
Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository octoprint/octoprint prior to 1.8.3.
CVE-2024-51478 1 Yeswiki 1 Yeswiki 2025-05-09 9.9 Critical
YesWiki is a wiki system written in PHP. Prior to 4.4.5, the use of a weak cryptographic algorithm and a hard-coded salt to hash the password reset key allows it to be recovered and used to reset the password of any account. This issue is fixed in 4.4.5.
CVE-2025-3471 1 Brainstormforce 1 Sureforms 2025-05-09 4.9 Medium
The SureForms WordPress plugin before 1.4.4 does not have proper authorisation check when updating its settings via the REST API, which could allow Contributor and above roles to perform such action
CVE-2025-45007 1 Phpgurukul 1 Time Table Generator System 2025-05-09 4.8 Medium
A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the profile.php file of PHPGurukul Timetable Generator System v1.0. This vulnerability allows remote attackers to execute arbitrary JavaScript code via the adminname POST request parameter.
CVE-2025-45020 1 Phpgurukul 1 Park Ticketing Management System 2025-05-09 7.2 High
A SQL Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary SQL code via the todate parameter in a POST request.
CVE-2025-45009 1 Phpgurukul 1 Park Ticketing Management System 2025-05-09 5.3 Medium
A HTML Injection vulnerability was discovered in the normal-search.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the searchdata parameter.
CVE-2025-45010 1 Phpgurukul 1 Park Ticketing Management System 2025-05-09 5.3 Medium
A HTML Injection vulnerability was discovered in the normal-bwdates-reports-details.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the fromdate and todate POST request parameters.
CVE-2025-45011 1 Phpgurukul 1 Park Ticketing Management System 2025-05-09 5.3 Medium
A HTML Injection vulnerability was discovered in the foreigner-search.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerability allows remote attackers to execute arbitrary code via the searchdata POST request parameter.