Export limit exceeded: 366356 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (366356 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-23052 | 2 5kcrm, Wukongopensource | 2 Wukong Crm, Wukongcrm | 2025-01-16 | 9.8 Critical |
| An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component. | ||||
| CVE-2024-22939 | 1 Sunkaifei | 1 Flycms | 2025-01-16 | 8.8 High |
| Cross Site Request Forgery vulnerability in FlyCms v.1.0 allows a remote attacker to execute arbitrary code via the system/article/category_edit component. | ||||
| CVE-2024-23302 | 1 Couchbase | 1 Couchbase Server | 2025-01-16 | 7.5 High |
| Couchbase Server before 7.2.4 has a private key leak in goxdcr.log. | ||||
| CVE-2024-24155 | 1 Axiosys | 1 Bento4 | 2025-01-16 | 6.5 Medium |
| Bento4 v1.5.1-628 contains a Memory leak on AP4_Movie::AP4_Movie, parsing tracks and added into m_Tracks list, but mp42aac cannot correctly delete when we got an no audio track found error. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted mp4 file. | ||||
| CVE-2024-25831 | 1 F-logic | 1 Datacube3 | 2025-01-16 | 5.4 Medium |
| F-logic DataCube3 Version 1.0 is affected by a reflected cross-site scripting (XSS) vulnerability due to improper input sanitization. An authenticated, remote attacker can execute arbitrary JavaScript code in the web management interface. | ||||
| CVE-2024-25833 | 1 F-logic | 1 Datacube3 | 2025-01-16 | 9.8 Critical |
| F-logic DataCube3 v1.0 is vulnerable to unauthenticated SQL injection, which could allow an unauthenticated malicious actor to execute arbitrary SQL queries in database. | ||||
| CVE-2024-1977 | 1 Josephlopreste | 1 Restaurant Solutions - Checklist | 2025-01-16 | 4.4 Medium |
| The Restaurant Solutions – Checklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Checklist points in version 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. | ||||
| CVE-2024-4202 | 1 Progress | 1 Telerik Reporting | 2025-01-16 | 7.7 High |
| In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.514), a code execution attack is possible through an insecure instantiation vulnerability. | ||||
| CVE-2023-31225 | 1 Huawei | 1 Emui | 2025-01-16 | 3.3 Low |
| The Gallery app has the risk of hijacking attacks. Successful exploitation of this vulnerability may cause download failures and affect product availability. | ||||
| CVE-2023-30145 | 1 Tuzitio | 1 Camaleon Cms | 2025-01-16 | 9.8 Critical |
| Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter. | ||||
| CVE-2021-46886 | 1 Huawei | 1 Emui | 2025-01-16 | 7.5 High |
| The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability. | ||||
| CVE-2021-46885 | 1 Huawei | 1 Emui | 2025-01-16 | 7.5 High |
| The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability. | ||||
| CVE-2021-46884 | 1 Huawei | 1 Emui | 2025-01-16 | 7.5 High |
| The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability. | ||||
| CVE-2021-46883 | 1 Huawei | 1 Emui | 2025-01-16 | 7.5 High |
| The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability. | ||||
| CVE-2021-46882 | 1 Huawei | 1 Emui | 2025-01-16 | 7.5 High |
| The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability. | ||||
| CVE-2021-46881 | 1 Huawei | 1 Emui | 2025-01-16 | 7.5 High |
| The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability. | ||||
| CVE-2024-1800 | 1 Progress | 1 Telerik Report Server | 2025-01-16 | 9.9 Critical |
| In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deserialization vulnerability. | ||||
| CVE-2024-4357 | 1 Progress | 1 Telerik Reporting | 2025-01-16 | 6.5 Medium |
| An information disclosure vulnerability exists in Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, allows low-privilege attacker to read systems file via XML External Entity Processing. | ||||
| CVE-2024-4837 | 1 Progress | 1 Telerik Report Server | 2025-01-16 | 5.3 Medium |
| In Progress Telerik Report Server, version 2024 Q1 (10.0.24.305) or earlier, on IIS, an unauthenticated attacker can gain access to Telerik Report Server restricted functionality via a trust boundary violation vulnerability. | ||||
| CVE-2024-5806 | 1 Progress | 1 Moveit Transfer | 2025-01-16 | 9.1 Critical |
| Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Authentication Bypass.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.11, from 2023.1.0 before 2023.1.6, from 2024.0.0 before 2024.0.2. | ||||