Export limit exceeded: 365082 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (365082 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-0055 | 1 Pyload | 1 Pyload | 2025-04-09 | 5.3 Medium |
| Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository pyload/pyload prior to 0.5.0b3.dev32. | ||||
| CVE-2024-2537 | 1 Logitech | 1 Logi Tune | 2025-04-09 | 4.4 Medium |
| Improper Control of Dynamically-Managed Code Resources vulnerability in Logitech Logi Tune on MacOS allows Local Code Inclusion. | ||||
| CVE-2023-0048 | 1 Daloradius | 1 Daloradius | 2025-04-09 | 8.8 High |
| Code Injection in GitHub repository lirantal/daloradius prior to master-branch. | ||||
| CVE-2023-0046 | 1 Daloradius | 1 Daloradius | 2025-04-09 | 7.2 High |
| Improper Restriction of Names for Files and Other Resources in GitHub repository lirantal/daloradius prior to master-branch. | ||||
| CVE-2023-0028 | 1 Linagora | 1 Twake | 2025-04-09 | 5.7 Medium |
| Cross-site Scripting (XSS) - Stored in GitHub repository linagora/twake prior to 2023.Q1.1200+. | ||||
| CVE-2022-4868 | 1 Froxlor | 1 Froxlor | 2025-04-09 | 4.3 Medium |
| Improper Authorization in GitHub repository froxlor/froxlor prior to 2.0.0-beta1. | ||||
| CVE-2022-4867 | 1 Froxlor | 1 Froxlor | 2025-04-09 | 4.3 Medium |
| Cross-Site Request Forgery (CSRF) in GitHub repository froxlor/froxlor prior to 2.0.0-beta1. | ||||
| CVE-2024-2497 | 1 Raspap | 1 Raspap | 2025-04-09 | 4.7 Medium |
| A vulnerability was found in RaspAP raspap-webgui 3.0.9 and classified as critical. This issue affects some unknown processing of the file includes/provider.php of the component HTTP POST Request Handler. The manipulation of the argument country leads to code injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-256919. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2025-20656 | 5 Google, Linuxfoundation, Mediatek and 2 more | 20 Android, Yocto, Mt6781 and 17 more | 2025-04-09 | 6.8 Medium |
| In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09625423; Issue ID: MSV-3033. | ||||
| CVE-2022-4866 | 1 Usememos | 1 Memos | 2025-04-09 | 9.0 Critical |
| Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. | ||||
| CVE-2022-4865 | 1 Usememos | 1 Memos | 2025-04-09 | 9.0 Critical |
| Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1. | ||||
| CVE-2023-0013 | 1 Sap | 1 Netweaver Application Server Abap | 2025-04-09 | 6.1 Medium |
| The ABAP Keyword Documentation of SAP NetWeaver Application Server - versions 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, for ABAP and ABAP Platform does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. On successful exploitation an attacker can cause limited impact on confidentiality and integrity of the application. | ||||
| CVE-2022-4864 | 1 Froxlor | 1 Froxlor | 2025-04-09 | 5.4 Medium |
| Argument Injection in GitHub repository froxlor/froxlor prior to 2.0.0-beta1. | ||||
| CVE-2022-43514 | 1 Siemens | 1 Automation License Manager | 2025-04-09 | 7.7 High |
| A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6 (All versions < V6.0 SP9 Upd4), TeleControl Server Basic V3 (All versions < V3.1.2). The affected component does not correctly validate the root path on folder related operations, allowing to modify files and folders outside the intended root directory. This could allow an unauthenticated remote attacker to execute file operations of files outside of the specified root folder. Chained with CVE-2022-43513 this could allow Remote Code Execution. | ||||
| CVE-2025-20658 | 2 Google, Mediatek | 19 Android, Mt2718, Mt6781 and 16 more | 2025-04-09 | 6 Medium |
| In DA, there is a possible permission bypass due to a logic error. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09474894; Issue ID: MSV-2597. | ||||
| CVE-2022-4863 | 1 Usememos | 1 Memos | 2025-04-09 | 6.5 Medium |
| Improper Handling of Insufficient Permissions or Privileges in GitHub repository usememos/memos prior to 0.9.1. | ||||
| CVE-2023-0091 | 1 Redhat | 4 Keycloak, Red Hat Single Sign On, Rhosemc and 1 more | 2025-04-09 | 3.8 Low |
| A flaw was found in Keycloak, where it did not properly check client tokens for possible revocation in its client credential flow. This flaw allows an attacker to access or modify potentially sensitive information. | ||||
| CVE-2022-47866 | 1 Lead Management System Project | 1 Lead Management System | 2025-04-09 | 9.8 Critical |
| Lead management system v1.0 is vulnerable to SQL Injection via the id parameter in removeBrand.php. | ||||
| CVE-2022-47865 | 1 Lead Management System Project | 1 Lead Management System | 2025-04-09 | 9.8 Critical |
| Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeOrder.php. | ||||
| CVE-2022-47864 | 1 Lead Management System Project | 1 Lead Management System | 2025-04-09 | 9.8 Critical |
| Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeCategories.php. | ||||