Export limit exceeded: 12739 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 12739 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (12739 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-3597 1 Firelightwp 1 Firelight Lightbox 2025-06-05 5.9 Medium
The Firelight Lightbox WordPress plugin before 2.3.15 does not prevent users with post writing capabilities from executing arbitrary Javascript when the jQuery Metadata library is enabled. While this feature is meant to only be available to Pro version users, it can be activated in the free version too, making it theoretically exploitable there as well.
CVE-2025-3649 1 Lightpress 1 Lightbox 2025-06-05 6.8 Medium
The LightPress Lightbox WordPress plugin before 2.3.4 does not check download links point to valid, non-Javascript URLs, allowing users with at least the contributor role to conduct Stored XSS attacks.
CVE-2025-45387 1 Osticket 1 Osticket 2025-06-05 5.4 Medium
osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php.
CVE-2024-40747 1 Joomla 1 Joomla\! 2025-06-04 6.1 Medium
Various module chromes didn't properly process inputs, leading to XSS vectors.
CVE-2024-40748 1 Joomla 1 Joomla\! 2025-06-04 7.5 High
Lack of output escaping in the id attribute of menu lists.
CVE-2024-40749 1 Joomla 1 Joomla\! 2025-06-04 7.5 High
Improper Access Controls allows access to protected views.
CVE-2024-48905 1 Sematell 1 Replyone 2025-06-04 9.1 Critical
Sematell ReplyOne 7.4.3.0 has Insecure Permissions for the /rest/sessions endpoint.
CVE-2024-48906 1 Sematell 1 Replyone 2025-06-04 6.1 Medium
Sematell ReplyOne 7.4.3.0 allows XSS via a ReplyDesk e-mail attachment name.
CVE-2024-48907 1 Sematell 1 Replyone 2025-06-04 7.5 High
Sematell ReplyOne 7.4.3.0 allows SSRF via the application server API.
CVE-2023-42866 1 Apple 6 Ipados, Iphone Os, Macos and 3 more 2025-06-03 8.8 High
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.5, iOS 16.6 and iPadOS 16.6, tvOS 16.6, Safari 16.6, watchOS 9.6. Processing web content may lead to arbitrary code execution.
CVE-2023-35792 1 Vound-software 1 Intella Connect 2025-05-30 5.4 Medium
Vound Intella Connect 2.6.0.3 is vulnerable to stored Cross-site Scripting (XSS).
CVE-2023-35791 1 Vound-software 1 Intella Connect 2025-05-30 6.1 Medium
Vound Intella Connect 2.6.0.3 has an Open Redirect vulnerability.
CVE-2022-41138 1 Zutty Project 1 Zutty 2025-05-29 9.8 Critical
In Zutty before 0.13, DECRQSS in text written to the terminal can achieve arbitrary code execution.
CVE-2024-48343 1 Esafenet 1 Cdg 2025-05-28 6.3 Medium
A SQL Injection vulnerability in ESAFENET CDG 5 and earlier allows an attacker to execute arbitrary code via the id parameter of the dataSearch.jsp page.
CVE-2025-46560 1 Vllm 1 Vllm 2025-05-28 6.5 Medium
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.8.0 and prior to 0.8.5 are affected by a critical performance vulnerability in the input preprocessing logic of the multimodal tokenizer. The code dynamically replaces placeholder tokens (e.g., <|audio_|>, <|image_|>) with repeated tokens based on precomputed lengths. Due to ​​inefficient list concatenation operations​​, the algorithm exhibits ​​quadratic time complexity (O(n²))​​, allowing malicious actors to trigger resource exhaustion via specially crafted inputs. This issue has been patched in version 0.8.5.
CVE-2025-32444 1 Vllm 1 Vllm 2025-05-28 10 Critical
vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Versions starting from 0.6.5 and prior to 0.8.5, having vLLM integration with mooncake, are vulnerable to remote code execution due to using pickle based serialization over unsecured ZeroMQ sockets. The vulnerable sockets were set to listen on all network interfaces, increasing the likelihood that an attacker is able to reach the vulnerable ZeroMQ sockets to carry out an attack. vLLM instances that do not make use of the mooncake integration are not vulnerable. This issue has been patched in version 0.8.5.
CVE-2025-3395 1 Abb 1 Automation Builder 2025-05-28 7.1 High
Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0.
CVE-2025-3394 1 Abb 1 Automation Builder 2025-05-28 7.8 High
Incorrect Permission Assignment for Critical Resource vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0.
CVE-2025-44835 1 Dlink 2 Dir-816 A2, Dir-816 A2 Firmware 2025-05-28 6.3 Medium
D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in iptablesWebsFilterRun, which allows remote attackers to execute arbitrary commands via shell.
CVE-2025-46566 1 Dataease 1 Dataease 2025-05-28 9.8 Critical
DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.9, authenticated users can complete RCE through the backend JDBC link. This issue has been patched in version 2.10.9.