Export limit exceeded: 47013 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 47013 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (47013 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-40875 | 1 Tenda | 2 Ax1803, Ax1803 Firmware | 2025-05-07 | 7.5 High |
| Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow in the function GetParentControlInfo. | ||||
| CVE-2022-40874 | 1 Tenda | 2 Ax1803, Ax1803 Firmware | 2025-05-07 | 7.5 High |
| Tenda AX1803 v1.0.0.1 was discovered to contain a heap overflow vulnerability in the GetParentControlInfo function, which can cause a denial of service attack through a carefully constructed http request. | ||||
| CVE-2022-39978 | 1 Online Pet Shop We App Project | 1 Online Pet Shop We App | 2025-05-07 | 7.2 High |
| Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in the Product List module. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file uploaded through the picture upload point. | ||||
| CVE-2022-39977 | 1 Online Pet Shop We App Project | 1 Online Pet Shop We App | 2025-05-07 | 7.2 High |
| Online Pet Shop We App v1.0 was discovered to contain an arbitrary file upload vulnerability via the Editing function in the User module. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file uploaded through the picture upload point. | ||||
| CVE-2022-39976 | 1 School Activity Updates With Sms Notification Project | 1 School Activity Updates With Sms Notification | 2025-05-07 | 9.8 Critical |
| School Activity Updates with SMS Notification v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /modules/announcement/index.php?view=edit&id=. | ||||
| CVE-2021-38734 | 1 Sem-cms | 1 Semcms | 2025-05-07 | 9.8 Critical |
| SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Menu.php. | ||||
| CVE-2021-38733 | 1 Sem-cms | 1 Semcms | 2025-05-07 | 9.8 Critical |
| SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_BlogCat.php. | ||||
| CVE-2021-38732 | 1 Sem-cms | 1 Semcms | 2025-05-07 | 9.8 Critical |
| SEMCMS SHOP v 1.1 is vulnerable to SQL via Ant_Message.php. | ||||
| CVE-2021-38731 | 1 Sem-cms | 1 Semcms | 2025-05-07 | 9.8 Critical |
| SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Zekou.php. | ||||
| CVE-2021-38730 | 1 Sem-cms | 1 Semcms | 2025-05-07 | 9.8 Critical |
| SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Info.php. | ||||
| CVE-2021-38729 | 1 Sem-cms | 1 Semcms | 2025-05-07 | 9.8 Critical |
| SEMCMS SHOP v 1.1 is vulnerable to SQL Injection via Ant_Plist.php. | ||||
| CVE-2021-37781 | 1 Phpgurukul | 1 Employee Record Management System | 2025-05-07 | 5.4 Medium |
| Employee Record Management System v 1.2 is vulnerable to Cross Site Scripting (XSS) via editempprofile.php. | ||||
| CVE-2021-35388 | 1 Phpgurukul | 1 Hospital Management System | 2025-05-07 | 5.4 Medium |
| Hospital Management System v 4.0 is vulnerable to Cross Site Scripting (XSS) via /hospital/hms/admin/patient-search.php. | ||||
| CVE-2021-35387 | 1 Phpgurukul | 1 Hospital Management System | 2025-05-07 | 8.8 High |
| Hospital Management System v 4.0 is vulnerable to SQL Injection via file:hospital/hms/admin/view-patient.php. | ||||
| CVE-2025-47201 | 1 Intrexx | 1 Intrexx | 2025-05-07 | 4.4 Medium |
| In Intrexx Portal Server before 12.0.4, multiple Velocity-Scripts are susceptible to the execution of unrequested JavaScript code in HTML, aka XSS. | ||||
| CVE-2025-3709 | 1 Flowring | 1 Agentflow | 2025-05-07 | 9.8 Critical |
| Agentflow from Flowring Technology has an Account Lockout Bypass vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to perform password brute force attack. | ||||
| CVE-2025-3708 | 1 Le-show | 1 Le-yan | 2025-05-07 | 9.8 Critical |
| Le-show medical practice management system from Le-yan has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | ||||
| CVE-2025-3707 | 1 Sun.net | 1 Ehrd Ctms | 2025-05-07 | 6.5 Medium |
| The eHDR CTMS from Sunnet has a SQL Injection vulnerability, allowing remote attackers with regular privileges to inject arbitrary SQL command to read database contents. | ||||
| CVE-2025-3312 | 1 Phpgurukul | 1 Men Salon Management System | 2025-05-07 | 7.3 High |
| A vulnerability, which was classified as critical, has been found in PHPGurukul Men Salon Management System 1.0. This issue affects some unknown processing of the file /admin/add-customer-services.php. The manipulation of the argument sids[] leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2024-57235 | 1 Netgear | 2 Rax50, Rax50 Firmware | 2025-05-07 | 6.5 Medium |
| NETGEAR RAX5 (AX1600 WiFi Router) V1.0.2.26 was discovered to contain a command injection vulnerability via the iface parameter in the vif_enable function. | ||||