Export limit exceeded: 43077 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 43077 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (43077 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-67461 | 2 Apple, Zoom | 3 Macos, Rooms, Zoom | 2025-12-30 | 5 Medium |
| External control of file name or path in Zoom Rooms for macOS before version 6.6.0 may allow an authenticated user to conduct a disclosure of information via local access. | ||||
| CVE-2025-14961 | 2 Code-projects, Fabian | 2 Simple Blood Donor Management System, Simple Blood Donor Management System | 2025-12-30 | 7.3 High |
| A vulnerability was detected in code-projects Simple Blood Donor Management System 1.0. The affected element is an unknown function of the file /editedcampaign.php. The manipulation of the argument campaignname results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. | ||||
| CVE-2025-14960 | 2 Code-projects, Fabian | 2 Simple Blood Donor Management System, Simple Blood Donor Management System | 2025-12-30 | 7.3 High |
| A security vulnerability has been detected in code-projects Simple Blood Donor Management System 1.0. Impacted is an unknown function of the file /editeddonor.php. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. | ||||
| CVE-2025-63498 | 2 Alinto, Debian | 2 Sogo, Debian Linux | 2025-12-30 | 6.1 Medium |
| alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter. | ||||
| CVE-2025-66575 | 1 Veepn | 1 Veepn | 2025-12-30 | 7.8 High |
| VeeVPN 1.6.1 contains an unquoted service path vulnerability in the VeePNService that allows remote attackers to execute code during startup or reboot with escalated privileges. Attackers can exploit this by providing a malicious service name, allowing them to inject commands and run as LocalSystem. | ||||
| CVE-2025-13742 | 1 Pretix | 1 Pretix | 2025-12-30 | 6.1 Medium |
| Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used in an email template, it will be replaced with the buyer's name for the final email. If the name of the attendee contained HTML or Markdown formatting, this was rendered as HTML in the resulting email. This way, a user could inject links or other formatted text through a maliciously formatted name. Since pretix applies a strict allow list approach to allowed HTML tags, this could not be abused for XSS or similarly dangerous attack chains. However, it can be used to manipulate emails in a way that makes user-provided content appear in a trustworthy and credible way, which can be abused for phishing. | ||||
| CVE-2025-65681 | 1 Edly | 1 Tutor | 2025-12-30 | 3.3 Low |
| An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers to gain access to sensitive information due to the absence of proper cache-control HTTP headers and client-side session checks. | ||||
| CVE-2024-58323 | 1 Kentico | 1 Xperience | 2025-12-30 | 5.4 Medium |
| A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the Checkbox form component. This allows malicious scripts to execute in users' browsers by exploiting HTML support in the form builder. | ||||
| CVE-2024-58322 | 1 Kentico | 1 Xperience | 2025-12-30 | 5.4 Medium |
| A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious code into shipping options configuration. This could lead to potential theft of sensitive data by executing malicious scripts in users' browsers. | ||||
| CVE-2024-58321 | 1 Kentico | 1 Xperience | 2025-12-30 | 5.4 Medium |
| A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via form validation rule configuration. Attackers can exploit this vulnerability to execute malicious scripts that will run in users' browsers. | ||||
| CVE-2024-58319 | 1 Kentico | 1 Xperience | 2025-12-30 | 6.1 Medium |
| A reflected cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the Pages dashboard widget configuration dialog. Attackers can exploit this vulnerability to execute malicious scripts in administrative users' browsers. | ||||
| CVE-2024-58318 | 1 Kentico | 1 Xperience | 2025-12-30 | 6.1 Medium |
| A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via the rich text editor component for page and form builders. Attackers can exploit this vulnerability by entering malicious URIs, potentially allowing malicious scripts to execute in users' browsers. | ||||
| CVE-2023-53738 | 1 Kentico | 1 Xperience | 2025-12-30 | 5.4 Medium |
| A reflected cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts via page preview URLs. Attackers can exploit this vulnerability to execute arbitrary scripts in users' browsers during page preview interactions. | ||||
| CVE-2023-53737 | 1 Kentico | 1 Xperience | 2025-12-30 | 4.8 Medium |
| A stored cross-site scripting vulnerability in Kentico Xperience allows global administrators to inject malicious payloads via the Localization application. Attackers can execute scripts that could affect multiple parts of the administration interface. | ||||
| CVE-2023-53736 | 1 Kentico | 1 Xperience | 2025-12-30 | 5.4 Medium |
| A reflected cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts in the administration interface. Attackers can exploit this vulnerability to execute arbitrary scripts within the administrative context. | ||||
| CVE-2022-50686 | 1 Kentico | 1 Xperience | 2025-12-30 | 7.5 High |
| An information disclosure vulnerability in Kentico Xperience allows attackers to view sensitive stack trace details via Portal Engine form control error messages. Detailed error messages can expose internal system information and potentially reveal implementation details to unauthorized users. | ||||
| CVE-2022-50685 | 1 Kentico | 1 Xperience | 2025-12-30 | 5.4 Medium |
| A stored cross-site scripting vulnerability in Kentico Xperience allows authenticated users to inject malicious scripts via XML file uploads as page attachments or metafiles. Attackers can upload malicious XML files that enable stored XSS, allowing malicious scripts to execute in users' browsers. | ||||
| CVE-2022-50684 | 1 Kentico | 1 Xperience | 2025-12-30 | 6.1 Medium |
| An HTML injection vulnerability in Kentico Xperience allows attackers to inject malicious HTML values into form submission emails via unencoded form fields. Unencoded form values could enable HTML content execution in recipient email clients, potentially compromising email security. | ||||
| CVE-2022-50683 | 1 Kentico | 1 Xperience | 2025-12-30 | 5.4 Medium |
| A stored cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via form redirect URL configuration. This allows malicious scripts to execute in users' browsers through unvalidated form configuration settings. | ||||
| CVE-2022-50681 | 1 Kentico | 1 Xperience | 2025-12-30 | 6.1 Medium |
| A reflected cross-site scripting vulnerability in Kentico Xperience allows attackers to inject malicious scripts via administration input fields in the Rich text editor component. Attackers can exploit this vulnerability to execute arbitrary scripts in users' browsers. | ||||