Export limit exceeded: 365947 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (365947 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-1279 | 2 Strangerstudios, Wordpress | 2 Paid Memberships Pro, Paid Memberships Pro | 2025-03-28 | 4.3 Medium |
| The Paid Memberships Pro WordPress plugin before 2.12.9 does not prevent user with at least the contributor role from leaking other users' sensitive metadata. | ||||
| CVE-2023-52715 | 1 Huawei | 1 Harmonyos | 2025-03-28 | 7.5 High |
| The SystemUI module has a vulnerability in permission management. Impact: Successful exploitation of this vulnerability may affect availability. | ||||
| CVE-2023-49930 | 1 Couchbase | 1 Couchbase Server | 2025-03-28 | 9.8 Critical |
| An issue was discovered in Couchbase Server before 7.2.4. cURL calls to /diag/eval are not sufficiently restricted. | ||||
| CVE-2023-33528 | 1 Halo | 1 Halo | 2025-03-28 | 6.1 Medium |
| halo v1.6.0 is vulnerable to Cross Site Scripting (XSS). | ||||
| CVE-2022-44029 | 1 Netscout | 1 Ngeniusone | 2025-03-28 | 6.1 Medium |
| An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 6 of 6. | ||||
| CVE-2022-44025 | 1 Netscout | 1 Ngeniusone | 2025-03-28 | 6.1 Medium |
| An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 2 of 6. | ||||
| CVE-2025-0625 | 1 Campcodes | 1 School Management Software | 2025-03-28 | 3.1 Low |
| A vulnerability, which was classified as problematic, was found in CampCodes School Management Software 1.0. This affects an unknown part of the component Attachment Handler. The manipulation leads to improper control of resource identifiers. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2025-25765 | 1 Mrcms | 1 Mrcms | 2025-03-28 | 4 Medium |
| MRCMS v3.1.2 was discovered to contain an arbitrary file write vulnerability via the component /file/save.do. | ||||
| CVE-2025-25389 | 1 Phpgurukul | 1 Land Record System | 2025-03-28 | 9.8 Critical |
| A SQL Injection vulnerability was found in /admin/forgot-password.php in Phpgurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the contactno POST request parameter. | ||||
| CVE-2025-23057 | 1 Arubanetworks | 1 Fabric Composer | 2025-03-28 | 5.5 Medium |
| A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web browser within the context of the compromised interface. | ||||
| CVE-2025-23056 | 1 Arubanetworks | 1 Fabric Composer | 2025-03-28 | 5.5 Medium |
| A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web browser within the context of the compromised interface. | ||||
| CVE-2025-23055 | 1 Arubanetworks | 1 Fabric Composer | 2025-03-28 | 5.5 Medium |
| A vulnerability in the web management interface of HPE Aruba Networking Fabric Composer could allow an authenticated remote attacker to conduct a stored cross-site scripting (XSS) attack. If successfully exploited, a threat actor could run arbitrary script code in a victim's web browser within the context of the compromised interface. | ||||
| CVE-2025-25766 | 1 Mrcms | 1 Mrcms | 2025-03-28 | 4.8 Medium |
| An arbitrary file upload vulnerability in the component /file/savefile.do of MRCMS v3.1.2 allows attackers to execute arbitrary code via uploading a crafted .jsp file. | ||||
| CVE-2025-25876 | 1 Angeljudesuarez | 1 Simple Chatbox | 2025-03-28 | 7.2 High |
| A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /delete.php. The attack can use SQL injection to obtain sensitive data. | ||||
| CVE-2025-25875 | 1 Angeljudesuarez | 1 Simple Chatbox | 2025-03-28 | 6.4 Medium |
| A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /message.php. The attack can use SQL injection to obtain sensitive data. | ||||
| CVE-2025-25388 | 1 Phpgurukul | 1 Land Record System | 2025-03-28 | 9.8 Critical |
| A SQL Injection vulnerability was found in /admin/edit-propertytype.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the editid GET request parameter. | ||||
| CVE-2025-25387 | 1 Phpgurukul | 1 Land Record System | 2025-03-28 | 7.2 High |
| A SQL Injection vulnerability was found in /admin/manage-propertytype.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the propertytype POST request parameter. | ||||
| CVE-2025-1159 | 1 Campcodes | 1 School Management Software | 2025-03-28 | 3.5 Low |
| A vulnerability was found in CampCodes School Management Software 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /academic-calendar. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2024-46429 | 1 Tenda | 2 W18e, W18e Firmware | 2025-03-28 | 8.8 High |
| A hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using a default guest account with administrative privileges. | ||||
| CVE-2024-1547 | 3 Debian, Mozilla, Redhat | 8 Debian Linux, Firefox, Thunderbird and 5 more | 2025-03-28 | 6.5 Medium |
| Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown). This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8. | ||||