Search

Search Results (370024 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-12916 1 Sangfor 1 Operation And Maintenance Security Management System 2025-12-09 6.3 Medium
A vulnerability was determined in Sangfor Operation and Maintenance Security Management System 3.0. Impacted is an unknown function of the file /fort/portal_login of the component Frontend. This manipulation of the argument loginUrl causes command injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 3.0.11 and 3.0.12 is recommended to address this issue. It is advisable to upgrade the affected component.
CVE-2022-24522 1 Microsoft 1 Skype Extension 2025-12-09 6.5 Medium
Skype Extension for Chrome Information Disclosure Vulnerability
CVE-2022-24526 1 Microsoft 1 Visual Studio Code 2025-12-09 6.1 Medium
Visual Studio Code Spoofing Vulnerability
CVE-2022-24498 1 Microsoft 22 Windows 10, Windows 10 1507, Windows 10 1607 and 19 more 2025-12-09 6.5 Medium
Windows iSCSI Target Service Information Disclosure Vulnerability
CVE-2022-24539 1 Microsoft 4 Windows Server 2016, Windows Server 2019, Windows Server 2022 and 1 more 2025-12-09 8.1 High
Windows Hyper-V Shared Virtual Hard Disks Information Disclosure Vulnerability
CVE-2022-24548 1 Microsoft 1 Malware Protection Engine 2025-12-09 5.5 Medium
Microsoft Defender Denial of Service Vulnerability
CVE-2022-26784 1 Microsoft 6 Windows Server 2012, Windows Server 2012 R2, Windows Server 2016 and 3 more 2025-12-09 6.5 Medium
Windows Cluster Shared Volume (CSV) Denial of Service Vulnerability
CVE-2025-14218 2 Code-projects, Fabian 2 Currency Exchange System, Currency Exchange System 2025-12-09 7.3 High
A security flaw has been discovered in code-projects Currency Exchange System 1.0. The affected element is an unknown function of the file /editotheraccount.php. Performing manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be exploited.
CVE-2025-14217 2 Code-projects, Fabian 2 Currency Exchange System, Currency Exchange System 2025-12-09 7.3 High
A vulnerability was identified in code-projects Currency Exchange System 1.0. Impacted is an unknown function of the file /edittrns.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.
CVE-2022-48470 1 Huawei 1 Hilink Ai Life 2025-12-09 4 Medium
Huawei HiLink AI Life product has an identity authentication bypass vulnerability. Successful exploitation of this vulnerability may allow attackers to access restricted functions.(Vulnerability ID:HWPSIRT-2022-42291) This vulnerability has been assigned a (CVE)ID:CVE-2022-48470
CVE-2025-14216 2 Code-projects, Fabian 2 Currency Exchange System, Currency Exchange System 2025-12-09 7.3 High
A vulnerability was determined in code-projects Currency Exchange System 1.0. This issue affects some unknown processing of the file /viewserial.php. This manipulation of the argument ID causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2025-14215 2 Code-projects, Fabian 2 Currency Exchange System, Currency Exchange System 2025-12-09 7.3 High
A vulnerability was found in code-projects Currency Exchange System 1.0. This vulnerability affects unknown code of the file /edit.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used.
CVE-2025-66322 1 Huawei 1 Harmonyos 2025-12-09 5.1 Medium
Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2025-66321 1 Huawei 1 Harmonyos 2025-12-09 5.1 Medium
Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2025-66320 1 Huawei 1 Harmonyos 2025-12-09 5.1 Medium
Multi-thread race condition vulnerability in the camera framework module. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2025-14221 2 Oretnom23, Sourcecodester 2 Banking System, Online Banking System 2025-12-09 3.5 Low
A vulnerability was detected in SourceCodester Online Banking System 1.0. This impacts an unknown function of the file /?page=user. The manipulation of the argument First Name/Last Name results in cross site scripting. The attack can be launched remotely. The exploit is now public and may be used.
CVE-2025-34351 1 Anyscale 1 Ray 2025-12-09 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. At the request of the MITRE TL-Root and following the CVE Program’s Dispute Policy, it has been determined that this assignment did not identify a valid vulnerability based on the vendor's product security model. Additionally, this assignment conflicts with an existing CVE (CVE-2023-48022).
CVE-2025-66551 1 Nextcloud 1 Tables 2025-12-09 6.3 Medium
Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.6 and 0.9.3, a malicious user was able to create their own table and then move a column to a victims table. This vulnerability is fixed in 0.8.6 and 0.9.3.
CVE-2025-66513 1 Nextcloud 1 Tables 2025-12-09 4.3 Medium
Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.9, 0.9.6, and 1.0.1, the information which table (numeric ID) is shared with which groups or users and the respective permissions was not limited to privileged users. This vulnerability is fixed in 0.8.9, 0.9.6, and 1.0.1.
CVE-2025-66514 1 Nextcloud 1 Mail 2025-12-09 3.5 Low
Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Prior to 5.5.3, a stored HTML injection in the Mail app's message list allowed an authenticated user to inject HTML into the email subjects. Javascript was correctly blocked by the content security policy of the Nextcloud Server code.