Export limit exceeded: 363739 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 363739 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (363739 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-0540 1 Gsplugins 1 Gs Filterable Portfolio 2025-03-13 5.4 Medium
The GS Filterable Portfolio WordPress plugin before 1.6.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2023-0371 1 Embedsocial 1 Embedsocial 2025-03-13 5.4 Medium
The EmbedSocial WordPress plugin before 1.1.28 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
CVE-2022-4786 1 Video.js Project 1 Video.js 2025-03-13 5.4 Medium
The Video.js WordPress plugin through 4.5.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
CVE-2022-4752 1 Opening Hours Project 1 Opening Hours 2025-03-13 5.4 Medium
The Opening Hours WordPress plugin through 2.3.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
CVE-2022-36231 1 Newspaperclub 1 Pdf Info 2025-03-13 9.8 Critical
pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3.
CVE-2024-31316 1 Google 1 Android 2025-03-13 7.8 High
In onResult of AccountManagerService.java, there is a possible way to perform an arbitrary background activity launch due to parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-30597 1 Tenda 2 Fh1203, Fh1203 Firmware 2025-03-13 6.5 Medium
Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability in the security parameter of the formWifiBasicSet function.
CVE-2024-30598 1 Tenda 2 Fh1203, Fh1203 Firmware 2025-03-13 6.5 Medium
Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability in the security_5g parameter of the formWifiBasicSet function.
CVE-2024-30599 1 Tenda 2 Fh1203, Fh1203 Firmware 2025-03-13 8.8 High
Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the deviceMac parameter of the addWifiMacFilter function.
CVE-2024-30600 1 Tenda 2 Fh1203, Fh1203 Firmware 2025-03-13 8.0 High
Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the schedEndTime parameter of the setSchedWifi function.
CVE-2024-30601 1 Tenda 2 Fh1203, Fh1203 Firmware 2025-03-13 8.0 High
Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the time parameter of the saveParentControlInfo function.
CVE-2024-30603 1 Tenda 2 Fh1203, Fh1203 Firmware 2025-03-13 6.5 Medium
Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the urls parameter of the saveParentControlInfo function.
CVE-2024-30604 1 Tenda 2 Fh1203, Fh1203 Firmware 2025-03-13 7.5 High
Tenda FH1203 v2.0.1.6 has a stack overflow vulnerability in the list1 parameter of the fromDhcpListClient function.
CVE-2024-28547 1 Tenda 2 Ac18, Ac18 Firmware 2025-03-13 6.5 Medium
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the firewallEn parameter of formSetFirewallCfg function.
CVE-2024-28537 1 Tenda 2 Ac18, Ac18 Firmware 2025-03-13 9.8 Critical
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the page parameter of fromNatStaticSetting function.
CVE-2024-28550 1 Tenda 2 Ac18, Ac18 Firmware 2025-03-13 4.3 Medium
Tenda AC18 V15.03.05.05 has a stack overflow vulnerability in the filePath parameter of formExpandDlnaFile function.
CVE-2024-28383 1 Tenda 2 Ax12, Ax12 Firmware 2025-03-13 9.8 Critical
Tenda AX12 v1.0 v22.03.01.16 was discovered to contain a stack overflow via the ssid parameter in the sub_431CF0 function.
CVE-2024-25746 1 Tenda 3 Ac9, Ac9 Firmware, Ac9v3.0 Firmware 2025-03-13 8.8 High
Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the add_white_node function.
CVE-2024-25748 1 Tenda 3 Ac9, Ac9 Firmware, Ac9v3.0 Firmware 2025-03-13 8.8 High
A Stack Based Buffer Overflow vulnerability in tenda AC9 AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the fromSetIpMacBind function.
CVE-2024-25753 1 Tenda 2 Ac9, Ac9 Firmware 2025-03-13 8.8 High
Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to execute arbitrary code via the formSetDeviceName function.