Search

Search Results (373145 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-3834 1 Bugfinder 1 Ex-rate 2025-08-21 3.5 Low
A vulnerability was found in Bug Finder EX-RATE 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /user/ticket/create of the component Ticket Handler. The manipulation of the argument message leads to cross site scripting. The attack may be launched remotely. The identifier of this vulnerability is VDB-235160. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2023-3847 1 Moosocial 1 Moodating 2025-08-21 3.5 Low
A vulnerability classified as problematic was found in mooSocial mooDating 1.2. This vulnerability affects unknown code of the file /users of the component URL Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. VDB-235198 is the identifier assigned to this vulnerability. NOTE: We tried to contact the vendor early about the disclosure but the official mail address was not working properly.
CVE-2023-3858 1 Phpscriptpoint 1 Car Listing 2025-08-21 3.5 Low
A vulnerability has been found in phpscriptpoint Car Listing 1.6 and classified as problematic. This vulnerability affects unknown code of the file /search.php. The manipulation of the argument country/state/city leads to cross site scripting. The attack can be initiated remotely. VDB-235210 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-54411 1 Discourse 1 Discourse 2025-08-21 N/A
Discourse is an open-source discussion platform. Welcome banner user name string for logged in users can be vulnerable to XSS attacks, which affect the user themselves or an admin impersonating them. Admins can temporarily alter the welcome_banner.header.logged_in_members site text to remove the preferred_display_name placeholder, or not impersonate any users for the time being. This vulnerability is fixed in 3.5.0.beta8.
CVE-2025-53191 1 Abb 3 Aspect Enterprise, Matrix Series, Nexus Series 2025-08-21 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-53190 1 Abb 3 Aspect Enterprise, Matrix Series, Nexus Series 2025-08-21 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-53189 1 Abb 3 Aspect Enterprise, Matrix Series, Nexus Series 2025-08-21 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-53188 1 Abb 3 Aspect Enterprise, Matrix Series, Nexus Series 2025-08-21 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-57832 2025-08-21 N/A
Not used
CVE-2025-57831 2025-08-21 N/A
Not used
CVE-2025-57830 2025-08-21 N/A
Not used
CVE-2025-57829 2025-08-21 N/A
Not used
CVE-2025-57828 2025-08-21 N/A
Not used
CVE-2025-57827 2025-08-21 N/A
Not used
CVE-2025-57826 2025-08-21 N/A
Not used
CVE-2025-57825 2025-08-21 N/A
Not used
CVE-2025-57824 2025-08-21 N/A
Not used
CVE-2024-27349 1 Apache 2 Hugegraph, Hugegraph-server 2025-08-21 9.1 Critical
Authentication Bypass by Spoofing vulnerability in Apache HugeGraph-Server.This issue affects Apache HugeGraph-Server: from 1.0.0 before 1.3.0. Users are recommended to upgrade to version 1.3.0, which fixes the issue.
CVE-2024-34449 1 B3log 1 Vditor 2025-08-21 6.1 Medium
Vditor 3.10.3 allows XSS via an attribute of an A element. NOTE: the vendor indicates that a user is supposed to mitigate this via sanitize=true.
CVE-2024-6184 1 Ruijie 2 Rg-uac, Rg-uac Firmware 2025-08-21 6.3 Medium
A vulnerability classified as critical was found in Ruijie RG-UAC 1.0. Affected by this vulnerability is an unknown functionality of the file /view/systemConfig/reboot/reboot_commit.php. The manipulation of the argument servicename leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-269155. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.