Export limit exceeded: 361897 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (361897 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-22926 | 1 Os4ed | 1 Opensis | 2025-04-30 | 9.8 Critical |
| An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename. | ||||
| CVE-2024-20059 | 2 Google, Mediatek | 26 Android, Mt6580, Mt6739 and 23 more | 2025-04-30 | 6.7 Medium |
| In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue ID: ALPS08541749. | ||||
| CVE-2024-38985 | 1 Janrywang | 1 Depath | 2025-04-30 | 9.8 Critical |
| janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() method at setIn (lib/index.js:90). This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties. | ||||
| CVE-2024-20060 | 2 Google, Mediatek | 26 Android, Mt6580, Mt6739 and 23 more | 2025-04-30 | 5.9 Medium |
| In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue ID: ALPS08541754. | ||||
| CVE-2024-37765 | 1 Machform | 1 Machform | 2025-04-30 | 8.8 High |
| Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page. | ||||
| CVE-2024-37764 | 1 Machform | 1 Machform | 2025-04-30 | 5.4 Medium |
| MachForm up to version 19 is affected by an authenticated stored cross-site scripting. | ||||
| CVE-2024-37763 | 1 Machform | 1 Machform | 2025-04-30 | 5.4 Medium |
| MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid sessions whom can view compiled forms results. | ||||
| CVE-2024-37762 | 1 Machform | 1 Machform | 2025-04-30 | 9.9 Critical |
| MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution. | ||||
| CVE-2024-48951 | 1 Logpoint | 2 Logpoint, Siem | 2025-04-30 | 7.5 High |
| An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoint's API Token leading to authentication bypass. | ||||
| CVE-2024-48952 | 1 Logpoint | 1 Soar | 2025-04-30 | 6.4 Medium |
| An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints without authentication. This static key vulnerability enables attackers to create custom JWT secret keys for unauthorized access to these endpoints. | ||||
| CVE-2024-48953 | 1 Logpoint | 2 Logpoint, Siem | 2025-04-30 | 7.5 High |
| An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed unauthenticated users to register their own authentication plugins in Logpoint, resulting in unauthorized access. | ||||
| CVE-2024-51004 | 1 Netgear | 4 R7000p, R7000p Firmware, R8500 and 1 more | 2025-04-30 | 5.7 Medium |
| Netgear R8500 v1.0.2.160 and R7000P v1.3.3.154 were discovered to multiple stack overflow vulnerabilities in the component usb_device.cgi via the cifs_user, read_access, and write_access parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request. | ||||
| CVE-2024-51002 | 1 Netgear | 9 R6400 Firmware, R6400v2, R6400v2 Firmware and 6 more | 2025-04-30 | 5.7 Medium |
| Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the l2tp_user_ip parameter at l2tp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | ||||
| CVE-2021-25963 | 1 Shuup | 1 Shuup | 2025-04-30 | 6.1 Medium |
| In Shuup, versions 1.6.0 through 2.10.8 are vulnerable to reflected Cross-Site Scripting (XSS) that allows execution of arbitrary javascript code on a victim browser. This vulnerability exists due to the error page contents not escaped. | ||||
| CVE-2021-25964 | 1 Janeczku | 1 Calibre-web | 2025-04-30 | 5.4 Medium |
| In “Calibre-web” application, v0.6.0 to v0.6.12, are vulnerable to Stored XSS in “Metadata”. An attacker that has access to edit the metadata information, can inject JavaScript payload in the description field. When a victim tries to open the file, XSS will be triggered. | ||||
| CVE-2021-25966 | 1 Orchardcore | 1 Orchard Core | 2025-04-30 | 8.8 High |
| In “Orchard core CMS” application, versions 1.0.0-beta1-3383 to 1.0.0 are vulnerable to an improper session termination after password change. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was changed. | ||||
| CVE-2024-44739 | 2 Oretnom23, Sourcecodester | 2 Simple Forum Website, Simple Forum Website | 2025-04-30 | 8.8 High |
| Sourcecodester Simple Forum Website v1.0 has a SQL injection vulnerability in /php-sqlite-forum/?page=manage_user&id=. | ||||
| CVE-2024-34833 | 1 Oretnom23 | 1 Payroll Management System | 2025-04-30 | 9.8 Critical |
| Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality to upload a malicious PHP file instead. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as the user running the web server. | ||||
| CVE-2024-25239 | 2 Sourcecodester, Walterjnr1 | 2 Employee Management System, Employee Management System | 2025-04-30 | 9.8 Critical |
| SQL Injection vulnerability in Sourcecodester Employee Management System v1.0 allows attackers to run arbitrary SQL commands via crafted POST request to /emloyee_akpoly/Account/login.php. | ||||
| CVE-2024-52945 | 1 Veritas | 1 Netbackup | 2025-04-30 | 7.8 High |
| An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup components running on a Windows Operating System. If a user executes specific NetBackup commands or an attacker uses social engineering techniques to impel the user to execute the commands, a malicious DLL could be loaded, resulting in execution of the attacker's code in the user's security context. | ||||