Export limit exceeded: 369656 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (369656 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-41588 | 1 Draytek | 48 Vigor1000b, Vigor1000b Firmware, Vigor165 and 45 more | 2025-06-11 | 8 High |
| The CGI endpoints v2x00.cgi and cgiwcg.cgi of DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strncpy function. | ||||
| CVE-2024-41590 | 1 Draytek | 48 Vigor1000b, Vigor1000b Firmware, Vigor165 and 45 more | 2025-06-11 | 8 High |
| Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strcpy function on DrayTek Vigor310 devices through 4.3.2.6. | ||||
| CVE-2024-41596 | 1 Draytek | 48 Vigor1000b, Vigor1000b Firmware, Vigor165 and 45 more | 2025-06-11 | 8 High |
| Buffer Overflow vulnerabilities exist in DrayTek Vigor310 devices through 4.3.2.6 (in the Vigor management UI) because of improper retrieval and handling of the CGI form parameters. | ||||
| CVE-2025-3877 | 1 Redhat | 5 Enterprise Linux, Rhel Aus, Rhel E4s and 2 more | 2025-06-11 | 5.4 Medium |
| This CVE was marked as fixed, but due to other code landing - was not actually fixed. It was subsequently fixed in CVE-2025-5986. | ||||
| CVE-2024-27447 | 1 Pretix | 1 Pretix | 2025-06-11 | 9.8 Critical |
| pretix before 2024.1.1 mishandles file validation. | ||||
| CVE-2024-33752 | 1 Emlog | 1 Emlog | 2025-06-11 | 6.3 Medium |
| An arbitrary file upload vulnerability exists in emlog pro 2.3.0 and pro 2.3.2 at admin/views/plugin.php that could be exploited by a remote attacker to submit a special request to upload a malicious file to execute arbitrary code. | ||||
| CVE-2024-33117 | 1 Crmeb | 1 Crmeb Java | 2025-06-11 | 5.3 Medium |
| crmeb_java v1.3.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the mergeList method in class com.zbkj.front.pub.ImageMergeController. | ||||
| CVE-2025-49793 | 2025-06-11 | N/A | ||
| Not used | ||||
| CVE-2025-49792 | 2025-06-11 | N/A | ||
| Not used | ||||
| CVE-2025-49791 | 2025-06-11 | N/A | ||
| Not used | ||||
| CVE-2025-49790 | 2025-06-11 | N/A | ||
| Not used | ||||
| CVE-2025-49789 | 2025-06-11 | N/A | ||
| Not used | ||||
| CVE-2025-49788 | 2025-06-11 | N/A | ||
| Not used | ||||
| CVE-2025-49787 | 2025-06-11 | N/A | ||
| Not used | ||||
| CVE-2025-49786 | 2025-06-11 | N/A | ||
| Not used | ||||
| CVE-2025-49785 | 2025-06-11 | N/A | ||
| Not used | ||||
| CVE-2025-47102 | 2025-06-11 | N/A | ||
| This CVE ID was issued in error by its CVE Numbering Authority and does not represent a valid vulnerability. | ||||
| CVE-2025-47095 | 2025-06-11 | N/A | ||
| This CVE ID was issued in error by its CVE Numbering Authority and does not represent a valid vulnerability. | ||||
| CVE-2022-43855 | 1 Ibm | 1 Spss Statistics | 2025-06-10 | 6.2 Medium |
| IBM SPSS Statistics 26.0, 27.0.1, and 28.0 IO Module could allow a local user to create multiple files that could exhaust the file handles capacity and cause a denial of service. | ||||
| CVE-2024-3931 | 1 Totara | 2 Enterprise Lms, Totara | 2025-06-10 | 3.5 Low |
| A vulnerability was found in Totara LMS up to 18.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the file admin/roles/check.php of the component User Selector. The manipulation of the argument ID Number leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 13.46, 14.38, 15.33, 16.27, 17.21 and 18.8 is able to address this issue. It is recommended to upgrade the affected component. | ||||