Export limit exceeded: 357940 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 357940 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (357940 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-28559 1 Niushop 1 B2b2c Multi-business 2025-05-28 8.8 High
SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the setPrice() function of the Goodsbatchset.php component.
CVE-2024-28560 1 Niushop 1 B2b2c Multi-business 2025-05-28 5.4 Medium
SQL injection vulnerability in Niushop B2B2C v.5.3.3 and before allows an attacker to escalate privileges via the deleteArea() function of the Address.php component.
CVE-2024-30187 1 Anope 1 Anope 2025-05-28 5.3 Medium
Anope before 2.0.15 does not prevent resetting the password of a suspended account.
CVE-2024-25807 1 Lycheeorg 1 Lychee 2025-05-28 6.1 Medium
Cross Site Scripting (XSS) vulnerability in Lychee 3.1.6, allows remote attackers to execute arbitrary code and obtain sensitive information via the title parameter when creating an album.
CVE-2024-26557 1 Codiad 1 Codiad 2025-05-28 5.4 Medium
Codiad v2.8.4 allows reflected XSS via the components/market/dialog.php type parameter.
CVE-2024-25808 1 Lycheeorg 1 Lychee 2025-05-28 8.3 High
Cross-site Request Forgery (CSRF) vulnerability in Lychee version 3.1.6, allows remote attackers to execute arbitrary code via the create new album function.
CVE-2024-29271 2 Givanz, Vvveb 2 Vvvebjs, Vvvebjs 2025-05-28 6.1 Medium
Reflected Cross-Site Scripting (XSS) vulnerability in VvvebJs before version 1.7.7, allows remote attackers to execute arbitrary code and obtain sensitive information via the action parameter in save.php.
CVE-2023-41504 1 Code-projects 1 Student Enrollment 2025-05-28 8.8 High
SQL Injection vulnerability in Student Enrollment In PHP 1.0 allows attackers to run arbitrary code via the Student Search function.
CVE-2023-41505 1 Code-projects 2 Student Enrollment, Student Enrollment In Php 2025-05-28 9.8 Critical
An arbitrary file upload vulnerability in the Add Student's Profile Picture function of Student Enrollment In PHP v1.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
CVE-2025-2847 1 Codezips 1 Gym Management System 2025-05-28 6.3 Medium
A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. This issue affects some unknown processing of the file /dashboard/admin/over_month.php. The manipulation of the argument mm leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-2151 1 Assimp 1 Assimp 2025-05-28 6.3 Medium
A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::GetNextLine in the library ParsingUtils.h of the component File Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-3395 1 Abb 1 Automation Builder 2025-05-28 7.1 High
Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0.
CVE-2025-3394 1 Abb 1 Automation Builder 2025-05-28 7.8 High
Incorrect Permission Assignment for Critical Resource vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0.
CVE-2024-51319 1 Zucchetti 1 Ad Hoc Infinity 2025-05-28 7.3 High
A local file include vulnerability in the /servlet/Report of Zucchetti Ad Hoc Infinity 2.4 allows an authenticated attacker to achieve Remote Code Execution by uploading a jsp web/reverse shell through /jsp/zimg_upload.jsp.
CVE-2025-5186 1 Jeesite 1 Jeesite 2025-05-28 6.3 Medium
A vulnerability was found in thinkgem JeeSite up to 5.11.1. It has been rated as critical. Affected by this issue is the function ResourceLoader.getResource of the file /cms/fileTemplate/form of the component URI Scheme Handler. The manipulation of the argument Name leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2022-37265 1 Stealjs 1 Steal 2025-05-28 9.8 Critical
Prototype pollution vulnerability in stealjs steal 2.2.4 via the alias variable in babel.js.
CVE-2025-2308 1 Hdfgroup 1 Hdf5 2025-05-28 5.3 Medium
A vulnerability, which was classified as critical, was found in HDF5 1.14.6. This affects the function H5Z__scaleoffset_decompress_one_byte of the component Scale-Offset Filter. The manipulation leads to heap-based buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The vendor plans to fix this issue in an upcoming release.
CVE-2025-2309 1 Hdfgroup 1 Hdf5 2025-05-28 5.3 Medium
A vulnerability has been found in HDF5 1.14.6 and classified as critical. This vulnerability affects the function H5T__bit_copy of the component Type Conversion Logic. The manipulation leads to heap-based buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The vendor plans to fix this issue in an upcoming release.
CVE-2025-2310 1 Hdfgroup 1 Hdf5 2025-05-28 5.3 Medium
A vulnerability was found in HDF5 1.14.6 and classified as critical. This issue affects the function H5MM_strndup of the component Metadata Attribute Decoder. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The vendor plans to fix this issue in an upcoming release.
CVE-2024-25423 2 Maxon, Nemetschek 2 Cinema 4d, Cinema 4d 2025-05-28 7 High
An issue in MAXON CINEMA 4D R2024.2.0 allows a local attacker to execute arbitrary code via a crafted c4d_base.xdl64 file.