Search

Search Results (360043 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-48231 1 Funadmin 1 Funadmin 2025-06-10 7.2 High
Funadmin 5.0.2 is vulnerable to SQL Injection via the selectFields parameter in the index method of \backend\controller\auth\Auth.php.
CVE-2024-48424 1 Assimp 1 Assimp 2025-06-10 5.5 Medium
A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the processing of OpenGEX files.
CVE-2024-48425 1 Assimp 1 Assimp 2025-06-10 5.5 Medium
A segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the Assimp library during fuzz testing using AddressSanitizer. The crash occurs due to a read access violation at address 0x000000000460, which points to the zero page, indicating a null or invalid pointer dereference.
CVE-2024-48228 1 Funadmin 1 Funadmin 2025-06-10 6.1 Medium
An issue was found in funadmin 5.0.2. The selectfiles method in \backend\controller\sys\Attachh.php directly stores the passed parameters and values into the param parameter without filtering, resulting in Cross Site Scripting (XSS).
CVE-2024-48178 1 Newbee-mall Project 1 Newbee-mall 2025-06-10 8.1 High
newbee-mall v1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via the goodsCoverImg parameter.
CVE-2024-33809 1 Pingcap 1 Tidb 2025-06-10 6.5 Medium
PingCAP TiDB v7.5.1 was discovered to contain a buffer overflow vulnerability, which could lead to database crashes and denial of service attacks.
CVE-2024-35110 1 Yzmcms 1 Yzmcms 2025-06-10 5.5 Medium
A reflected XSS vulnerability has been found in YzmCMS 7.1. The vulnerability exists in yzmphp/core/class/application.class.php: when logged-in users access a malicious link, their cookies can be captured by an attacker.
CVE-2024-31613 1 Bosscms 1 Bosscms 2025-06-10 5.4 Medium
BOSSCMS v3.10 is vulnerable to Cross Site Request Forgery (CSRF) in name="head_code" or name="foot_code."
CVE-2024-37840 1 Itsourcecode 2 Learning Management System, Learning Management System Project In Php 2025-06-10 8.8 High
SQL injection vulnerability in processscore.php in Itsourcecode Learning Management System Project In PHP With Source Code v1.0 allows remote attackers to execute arbitrary SQL commands via the LessonID parameter.
CVE-2024-33300 1 Typora 1 Typora 2025-06-10 7.3 High
Typora v1.0.0 through v1.7 version (below) Markdown editor has a cross-site scripting (XSS) vulnerability, which allows attackers to execute arbitrary code by uploading Markdown files.
CVE-2024-34401 1 Techkshetrainfo 1 Savsoft Quiz 2025-06-10 6.1 Medium
Savsoft Quiz 6.0 allows stored XSS via the index.php/quiz/insert_quiz/ quiz_name parameter.
CVE-2024-33789 1 Linksys 2 E5600, E5600 Firmware 2025-06-10 9.8 Critical
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info form endpoint.
CVE-2024-27453 1 Extremenetworks 1 Extremexos 2025-06-10 8.6 High
In Extreme XOS through 22.6.1.4, a read-only user can escalate privileges to root via a crafted HTTP POST request to the python method of the Machine-to-Machine Interface (MMI).
CVE-2024-34462 1 Alinto 1 Sogo 2025-06-10 6.1 Medium
Alinto SOGo through 5.10.0 allows XSS during attachment preview.
CVE-2024-31580 2 Linuxfoundation, Pytorch 2 Pytorch, Pytorch 2025-06-10 4 Medium
PyTorch before v2.2.0 was discovered to contain a heap buffer overflow vulnerability in the component /runtime/vararg_functions.cpp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2024-35618 1 Pingcap 1 Tidb 2025-06-10 7.5 High
PingCAP TiDB v7.5.1 was discovered to contain a NULL pointer dereference via the component SortedRowContainer.
CVE-2024-35373 2 Mocado, Mocodo 2 Mocado, Mocodo Online 2025-06-10 9.8 Critical
Mocodo Mocodo Online 4.2.6 and below is vulnerable to Remote Code Execution via /web/rewrite.php.
CVE-2024-35374 1 Mocodo 1 Mocodo Online 2025-06-10 9.8 Critical
Mocodo Mocodo Online 4.2.6 and below does not properly sanitize the sql_case input field in /web/generate.php, allowing remote attackers to execute arbitrary commands and potentially command injection, leading to remote code execution (RCE) under certain conditions.
CVE-2024-34852 1 F-logic 2 Datacube3, Datacube3 Firmware 2025-06-10 6.3 Medium
F-logic DataCube3 v1.0 is affected by command injection due to improper string filtering at the command execution point in the ./admin/transceiver_schedule.php file. An unauthenticated remote attacker can exploit this vulnerability by sending a file name containing command injection. Successful exploitation of this vulnerability may allow the attacker to execute system commands.
CVE-2024-34854 1 F-logic 2 Datacube3, Datacube3 Firmware 2025-06-10 9.8 Critical
F-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.`