Export limit exceeded: 97301 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (97301 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-24375 1 Jfinalcms Project 1 Jfinalcms 2025-04-30 7.5 High
SQL injection vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to obtain sensitive information via /admin/admin name parameter.
CVE-2024-25164 1 Idurarapp 1 Idurar 2025-04-30 7.5 High
iA Path Traversal vulnerability exists in iDURAR v2.0.0, that allows unauthenticated attackers to expose sensitive files via the download functionality.
CVE-2024-26470 1 Fullstackhero 1 .net 9 Starter Kit 2025-04-30 8.1 High
A host header injection vulnerability in the forgot password function of FullStackHero's WebAPI Boilerplate v1.0.0 and v1.0.1 allows attackers to leak the password reset token via a crafted request.
CVE-2024-42772 2 Jayesh, Kashipara 2 Hotel Management System, Hotel Management System 2025-04-30 7.5 High
An Incorrect Access Control vulnerability was found in /admin/rooms.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to view valid hotel room entries in administrator section.
CVE-2024-42774 2 Jayesh, Kashipara 2 Hotel Management System, Hotel Management System 2025-04-30 7.5 High
An Incorrect Access Control vulnerability was found in /admin/delete_room.php in Kashipara Hotel Management System v1.0, which allows an unauthenticated attacker to delete valid hotel room entries in the administrator section.
CVE-2024-42776 2 Jayesh, Kashipara 2 Hotel Management System, Hotel Management System 2025-04-30 7.2 High
Kashipara Hotel Management System v1.0 is vulnerable to Incorrect Access Control via /admin/users.php.
CVE-2024-42767 2 Jayesh, Kashipara 2 Hotel Management System, Hotel Management System 2025-04-30 7.2 High
Kashipara Hotel Management System v1.0 is vulnerable to Unrestricted File Upload RCE via /admin/add_room_controller.php.
CVE-2024-24334 1 Rt-thread 1 Rt-thread 2025-04-30 8.4 High
A heap buffer overflow occurs in dfs_v2 dfs_file in RT-Thread through 5.0.2.
CVE-2024-23722 2 Fluent, Treasuredata 2 Fluent Bit, Fluent Bit 2025-04-30 7.5 High
In Fluent Bit 2.1.8 through 2.2.1, a NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-urlencoded. It crashes and does not restart. This could result in logs not being delivered properly.
CVE-2024-32391 1 Maccms 1 Maccms 2025-04-30 7.3 High
Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload.
CVE-2024-29434 1 Alldata 1 Alldata 2025-04-30 8.3 High
An issue in the system image upload interface of Alldata v0.4.6 allows attackers to execute a directory traversal when uploading a file.
CVE-2025-30093 1 Wisc 1 Htcondor 2025-04-30 8.1 High
HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, and 24.6.x before 24.6.1 allows authenticated attackers to bypass authorization restrictions.
CVE-2024-57519 1 Open5gs 1 Open5gs 2025-04-30 7.5 High
An issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in lib/dbi/subscription.c file.
CVE-2024-42991 1 Mingsoft 1 Mcms 2025-04-30 8.1 High
MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.
CVE-2024-20057 2 Google, Mediatek 38 Android, Mt6761, Mt6765 and 35 more 2025-04-30 7.2 High
In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08587881; Issue ID: ALPS08587881.
CVE-2025-29017 1 Codeastro 1 Internet Banking System 2025-04-30 8.8 High
A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the profile_pic parameter within pages_view_client.php.
CVE-2024-37765 1 Machform 1 Machform 2025-04-30 8.8 High
Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.
CVE-2024-48951 1 Logpoint 2 Logpoint, Siem 2025-04-30 7.5 High
An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoint's API Token leading to authentication bypass.
CVE-2024-48953 1 Logpoint 2 Logpoint, Siem 2025-04-30 7.5 High
An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed unauthenticated users to register their own authentication plugins in Logpoint, resulting in unauthorized access.
CVE-2021-25966 1 Orchardcore 1 Orchard Core 2025-04-30 8.8 High
In “Orchard core CMS” application, versions 1.0.0-beta1-3383 to 1.0.0 are vulnerable to an improper session termination after password change. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was changed.