Export limit exceeded: 365178 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (365178 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-4325 1 Ifeelweb 1 Post Status Notifier Lite 2025-04-09 6.1 Medium
The Post Status Notifier Lite WordPress plugin before 1.10.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which can be used against high privilege users such as admin.
CVE-2021-46871 1 Phoenixframework 1 Phoenix Html 2025-04-09 6.1 Medium
tag.ex in Phoenix Phoenix.HTML (aka phoenix_html) before 3.0.4 allows XSS in HEEx class attributes.
CVE-2017-20166 1 Ecto Project 1 Ecto 2025-04-09 9.8 Critical
Ecto 2.2.0 lacks a certain protection mechanism associated with the interaction between is_nil and raise.
CVE-2024-13744 1 Booster 1 Booster For Woocommerce 2025-04-09 8.1 High
The Booster for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the validate_product_input_fields_on_add_to_cart function in versions 4.0.1 to 7.2.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
CVE-2024-13708 1 Booster 1 Booster For Woocommerce 2025-04-09 7.2 High
The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in versions 4.0.1 to 7.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
CVE-2025-28400 1 Ruoyi 1 Ruoyi 2025-04-09 6.7 Medium
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the postID parameter in the edit method
CVE-2025-28401 1 Ruoyi 1 Ruoyi 2025-04-09 6.7 Medium
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the menuId parameter
CVE-2025-28402 1 Ruoyi 1 Ruoyi 2025-04-09 9.8 Critical
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter
CVE-2025-28403 1 Ruoyi 1 Ruoyi 2025-04-09 7.2 High
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the editSave method does not properly validate whether the requesting user has administrative privileges before allowing modifications to system configuration settings
CVE-2025-28405 1 Ruoyi 1 Ruoyi 2025-04-09 9.8 Critical
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method
CVE-2025-28406 1 Ruoyi 1 Ruoyi 2025-04-09 9.8 Critical
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter
CVE-2025-3161 1 Tenda 2 Ac10, Ac10 Firmware 2025-04-09 8.8 High
A vulnerability was found in Tenda AC10 16.03.10.13 and classified as critical. This issue affects the function ShutdownSetAdd of the file /goform/ShutdownSetAdd. The manipulation of the argument list leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2023-22899 2 Redhat, Zip4j Project 3 Migration Toolkit Applications, Migration Toolkit Runtimes, Zip4j 2025-04-09 5.9 Medium
Zip4j through 2.11.2, as used in Threema and other products, does not always check the MAC when decrypting a ZIP archive.
CVE-2022-4382 1 Linux 1 Linux Kernel 2025-04-09 6.4 Medium
A use-after-free flaw caused by a race among the superblock operations in the gadgetfs Linux driver was found. It could be triggered by yanking out a device that is running the gadgetfs side.
CVE-2022-46610 1 72crm 1 Wukong Crm 2025-04-09 8.8 High
72crm v9 was discovered to contain an arbitrary file upload vulnerability via the avatar upload function. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-46449 1 Musicpd 1 Music Player Daemon 2025-04-09 7.5 High
An issue in MPD (Music Player Daemon) v0.23.10 allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVE-2022-38492 1 Easyvista 1 Service Manager 2025-04-09 7.7 High
An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. One parameter allows SQL injection. Version 2022.1.110.1.02 fixes the vulnerability.
CVE-2022-38491 1 Easyvista 1 Service Manager 2025-04-09 8.2 High
An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Part of the application does not implement protection against brute-force attacks. Version 2022.1.133.0 corrects this issue.
CVE-2022-38490 1 Easyvista 1 Service Manager 2025-04-09 9.6 Critical
An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Some parameters allow SQL injection. Version 2022.1.110.1.02 corrects this issue.
CVE-2022-38489 1 Easyvista 1 Service Manager 2025-04-09 4.8 Medium
An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03 It is prone to stored Cross-site Scripting (XSS). Version 2022.1.110.1.02 fixes the vulnerably.