Export limit exceeded: 363455 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 363455 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (363455 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-36745 1 Oneflow 1 Oneflow 2025-03-25 7.5 High
An issue in OneFlow-Inc. Oneflow v0.9.1 allows attackers to cause a Denial of Service (DoS) via inputting a negative value into the oneflow.index_select parameter.
CVE-2024-27373 1 Samsung 10 Exynos 1280, Exynos 1280 Firmware, Exynos 1330 and 7 more 2025-03-25 6.7 Medium
An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_config_get_nl_params(), there is no input validation check on disc_attr->mesh_id_len coming from userspace, which can lead to a heap overwrite.
CVE-2023-0252 1 Webberzone 1 Contextual Related Posts 2025-03-25 5.4 Medium
The Contextual Related Posts WordPress plugin before 3.3.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
CVE-2023-0176 1 Rafflepress 1 Giveaways And Contests By Rafflepress 2025-03-25 5.4 Medium
The Giveaways and Contests by RafflePress WordPress plugin before 1.11.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2023-0170 1 Bplugins 1 Html5 Audio Player 2025-03-25 5.4 Medium
The Html5 Audio Player WordPress plugin before 2.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2023-0150 1 Cloak Front End Email Project 1 Cloak Front End Email 2025-03-25 5.4 Medium
The Cloak Front End Email WordPress plugin before 1.9.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
CVE-2023-0146 1 Naver Map Project 1 Naver Map 2025-03-25 5.4 Medium
The Naver Map WordPress plugin through 1.1.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2023-0096 1 Happyforms 1 Happyforms 2025-03-25 5.4 Medium
The Happyforms WordPress plugin before 1.22.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2023-0081 1 Monsterinsights 1 Monsterinsights 2025-03-25 5.4 Medium
The MonsterInsights WordPress plugin before 8.12.1 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2023-0072 1 Wcvendors 1 Wc Vendors Marketplace 2025-03-25 5.4 Medium
The WC Vendors Marketplace WordPress plugin before 2.4.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2023-0062 1 Wpfactory 1 Ean For Woocommerce 2025-03-25 5.4 Medium
The EAN for WooCommerce WordPress plugin before 4.4.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2022-4836 1 Pickplugins 1 Breadcrumb 2025-03-25 5.4 Medium
The Breadcrumb WordPress plugin before 1.5.33 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
CVE-2022-4826 1 Simple Tooltips Project 1 Simple Tooltips 2025-03-25 5.4 Medium
The Simple Tooltips WordPress plugin before 2.1.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
CVE-2022-4626 1 Passwordprotectwp 1 Password Protect Wordpress 2025-03-25 5.4 Medium
The PPWP WordPress plugin before 1.8.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
CVE-2022-4489 1 Pluginus 1 Husky - Products Filter Professional For Woocommerce 2025-03-25 7.2 High
The HUSKY WordPress plugin before 1.3.2 unserializes user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
CVE-2022-47327 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-03-25 5.5 Medium
In wlan driver, there is a possible missing permission check. This could lead to local information disclosure.
CVE-2022-45191 1 Microchip 2 Rn4870, Rn4870 Firmware 2025-03-25 6.5 Medium
An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of service by sending a pair confirm message with wrong values.
CVE-2022-25480 1 Realtek 3 Rtsper, Rtsper Pcie Card Reader Driver, Rtsuer 2025-03-25 7.8 High
Vulnerability in Realtek RtsPer driver for PCIe Card Reader (RtsPer.sys) before 10.0.22000.21355 and Realtek RtsUer driver for USB Card Reader (RtsUer.sys) before 10.0.22000.31274 allows writing to kernel memory beyond the SystemBuffer of the IRP.
CVE-2021-37492 1 Ravencoin 1 Ravencoin 2025-03-25 7.5 High
An issue discovered in src/wallet/wallet.cpp in Ravencoin Core 4.3.2.1 and earlier allows attackers to view sensitive information via CWallet::CreateTransactionAll() function.
CVE-2021-37491 1 Dogecoin 1 Dogecoin 2025-03-25 7.5 High
An issue discovered in src/wallet/wallet.cpp in Dogecoin Project Dogecoin Core 1.14.3 and earlier allows attackers to view sensitive information via CWallet::CreateTransaction() function.