Search

Search Results (47189 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-0438 1 Modoboa 1 Modoboa 2025-04-03 6.5 Medium
Cross-Site Request Forgery (CSRF) in GitHub repository modoboa/modoboa prior to 2.0.4.
CVE-2025-25363 1 Thepluginpeople 1 Enterprise Mail Handler 2025-04-03 6.5 Medium
An authenticated stored cross-site scripting (XSS) vulnerability in The Plugin People Enterprise Mail Handler for Jira Data Center (JEMH) before v4.1.69-dc allows attackers with Administrator privileges to execute arbitrary Javascript in context of a user's browser via injecting a crafted payload into the HTML field of a template.
CVE-2024-57062 1 Soundcloud 1 Soundcloud 2025-04-03 6.7 Medium
An issue in SoundCloud IOS application v.7.65.2 allows a local attacker to escalate privileges and obtain sensitive information via the session handling component.
CVE-2025-28010 1 Modx 1 Modx 2025-04-03 5.4 Medium
A cross-site scripting (XSS) vulnerability has been identified in MODX prior to 3.1.0. The vulnerability allows authenticated users to upload SVG files containing malicious JavaScript code as profile images, which gets executed in victims' browsers when viewing the profile image.
CVE-2025-25598 1 Inovalogic 1 Customer Monitor 2025-04-03 8.8 High
Incorrect access control in the scheduled tasks console of Inova Logic CUSTOMER MONITOR (CM) v3.1.757.1 allows attackers to escalate privileges via placing a crafted executable into a scheduled task.
CVE-2024-55060 1 Rafed-system 1 Rafed Cms Website 2025-04-03 6.1 Medium
A cross-site scripting (XSS) vulnerability in the component index.php of Rafed CMS Website v1.44 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2025-26163 1 Cmsol 1 Auto Atendimento 2025-04-03 9.8 Critical
CM Soluces Informatica Ltda Auto Atendimento 1.x.x was discovered to contain a SQL injection via the CPF parameter.
CVE-2025-30022 1 Cmsol 1 Auto Atendimento 2025-04-03 6.8 Medium
CM Soluces Informatica Ltda Auto Atendimento 1.x.x was discovered to contain a SQL injection via the DATANASC parameter.
CVE-2024-57211 1 Totolink 2 A6000r, A6000r Firmware 2025-04-03 8 High
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the modifyOne parameter in the enable_wsh function.
CVE-2024-57212 1 Totolink 2 A6000r, A6000r Firmware 2025-04-03 5.1 Medium
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the opmode parameter in the action_reboot function.
CVE-2024-57213 1 Totolink 2 A6000r, A6000r Firmware 2025-04-03 6.3 Medium
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the newpasswd parameter in the action_passwd function.
CVE-2024-57214 1 Totolink 2 A6000r, A6000r Firmware 2025-04-03 6.3 Medium
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the devname parameter in the reset_wifi function.
CVE-2025-29032 1 Tendacn 2 Ac9, Ac9 Firmware 2025-04-03 5.9 Medium
Tenda AC9 v15.03.05.19(6318) was discovered to contain a buffer overflow via the formWifiWpsOOB function.
CVE-2025-25871 1 Openpanel 1 Openpanel 2025-04-03 8 High
An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function
CVE-2025-25872 1 Openpanel 1 Openpanel 2025-04-03 5.5 Medium
An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function
CVE-2025-25873 1 Openpanel 1 Openadmin 2025-04-03 5.5 Medium
Cross Site Request Forgery vulnerability in Open Panel OpenAdmin v.0.3.4 allows a remote attacker to escalate privileges via the Change Root Password function
CVE-2024-29409 1 Nestjs 1 Nest 2025-04-03 5.5 Medium
File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Type header.
CVE-2025-2094 1 Totolink 2 Ex1800t, Ex1800t Firmware 2025-04-03 6.3 Medium
A vulnerability was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. It has been rated as critical. Affected by this issue is the function setWiFiExtenderConfig of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument apcliKey/key leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-2095 1 Totolink 2 Ex1800t, Ex1800t Firmware 2025-04-03 6.3 Medium
A vulnerability classified as critical has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This affects the function setDmzCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument ip leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-2097 1 Totolink 2 Ex1800t, Ex1800t Firmware 2025-04-03 8.8 High
A vulnerability, which was classified as critical, has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316. This issue affects the function setRptWizardCfg of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument loginpass leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.