Export limit exceeded: 43068 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 43068 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (43068 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-4936 | 1 Projectworlds | 1 Online Food Ordering System | 2025-06-05 | 7.3 High |
| A vulnerability was found in projectworlds Online Food Ordering System 1.0. It has been classified as critical. Affected is an unknown function of the file /admin-page.php. The manipulation of the argument 1_price leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2025-4894 | 1 Calmkart | 1 Django-sso-server | 2025-06-05 | 3.7 Low |
| A vulnerability classified as problematic was found in calmkart Django-sso-server up to 057247929a94ffc358788a37ab99e391379a4d15. This vulnerability affects the function gen_rsa_keys of the file common/crypto.py. The manipulation leads to inadequate encryption strength. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. | ||||
| CVE-2025-4780 | 1 Phpgurukul | 1 Park Ticketing Management System | 2025-06-05 | 6.3 Medium |
| A vulnerability was found in PHPGurukul Park Ticketing Management System 2.0. It has been rated as critical. This issue affects some unknown processing of the file /foreigner-search.php. The manipulation of the argument searchdata leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2025-4770 | 1 Phpgurukul | 1 Park Ticketing Management System | 2025-06-05 | 6.3 Medium |
| A vulnerability, which was classified as critical, has been found in PHPGurukul Park Ticketing Management System 2.0. This issue affects some unknown processing of the file /view-normal-ticket.php. The manipulation of the argument viewid leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2022-34696 | 1 Microsoft | 7 Windows 10, Windows 11, Windows 8.1 and 4 more | 2025-06-05 | 7.8 High |
| Windows Hyper-V Remote Code Execution Vulnerability | ||||
| CVE-2022-34692 | 1 Microsoft | 1 Exchange Server | 2025-06-05 | 5.3 Medium |
| Microsoft Exchange Server Information Disclosure Vulnerability | ||||
| CVE-2022-34691 | 1 Microsoft | 10 Windows 10, Windows 11, Windows 7 and 7 more | 2025-06-05 | 8.8 High |
| Active Directory Domain Services Elevation of Privilege Vulnerability | ||||
| CVE-2022-33646 | 1 Microsoft | 1 Azure Batch | 2025-06-05 | 7 High |
| Azure Batch Node Agent Elevation of Privilege Vulnerability | ||||
| CVE-2022-33640 | 1 Microsoft | 2 Open Management Infrastructure, System Center Operations Manager | 2025-06-05 | 7.8 High |
| System Center Operations Manager: Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | ||||
| CVE-2022-33631 | 1 Microsoft | 4 365 Apps, Excel, Office and 1 more | 2025-06-05 | 7.3 High |
| Microsoft Excel Security Feature Bypass Vulnerability | ||||
| CVE-2025-3597 | 1 Firelightwp | 1 Firelight Lightbox | 2025-06-05 | 5.9 Medium |
| The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executing arbitrary Javascript when the jQuery Metadata library is enabled. While this feature is meant to only be available to Pro version users, it can be activated in the free version too, making it theoretically exploitable there as well. | ||||
| CVE-2025-3649 | 1 Lightpress | 1 Lightbox | 2025-06-05 | 6.8 Medium |
| The LightPress Lightbox WordPress plugin before 2.3.4 does not check download links point to valid, non-Javascript URLs, allowing users with at least the contributor role to conduct Stored XSS attacks. | ||||
| CVE-2024-13384 | 1 Robosoft | 1 Robo Gallery | 2025-06-05 | 4.8 Medium |
| The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.24 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
| CVE-2024-2869 | 1 Realestateconnected | 1 Easy Property Listings | 2025-06-05 | 4.8 Medium |
| The Easy Property Listings WordPress plugin before 3.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | ||||
| CVE-2024-6665 | 1 Optimalaccess | 1 Kbucket | 2025-06-05 | 4.8 Medium |
| The KBucket: Your Curated Content in WordPress plugin before 4.1.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | ||||
| CVE-2024-6667 | 1 Optimalaccess | 1 Kbucket | 2025-06-05 | 6.1 Medium |
| The KBucket: Your Curated Content in WordPress plugin before 4.1.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against admin. | ||||
| CVE-2024-6809 | 1 Quantumcloud | 1 Simple Video Directory | 2025-06-05 | 9.8 Critical |
| The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection. | ||||
| CVE-2024-9227 | 1 Blubrry | 1 Powerpress | 2025-06-05 | 4.8 Medium |
| The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its settings when adding a podcast, which could allow admin users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | ||||
| CVE-2025-45387 | 1 Osticket | 1 Osticket | 2025-06-05 | 5.4 Medium |
| osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php. | ||||
| CVE-2025-48999 | 1 Dataease | 1 Dataease | 2025-06-05 | 8.8 High |
| DataEase is an open source business intelligence and data visualization tool. A bypass of CVE-2025-46566's patch exists in versions prior to 2.10.10. In a malicious payload, `getUrlType()` retrieves `hostName`. Since the judgment statement returns false, it will not enter the if statement and will not be filtered. The payload can be directly concatenated at the replace location to construct a malicious JDBC statement. Version 2.10.10 contains a patch for the issue. | ||||