Export limit exceeded: 374421 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 374421 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 374421 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (374421 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-20392 1 Google 1 Android 2025-06-05 7.8 High
In declareDuplicatePermission of ParsedPermissionUtils.java, there is a possible way to obtain a dangerous permission without user consent due to improper input validation. This could lead to local escalation of privilege during app installation or upgrade with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-213323615
CVE-2022-20389 1 Google 1 Android 2025-06-05 9.8 Critical
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257004
CVE-2022-20388 1 Google 1 Android 2025-06-05 9.8 Critical
Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227323
CVE-2024-22919 1 Swftools 1 Swftools 2025-06-05 7.8 High
swftools0.9.2 was discovered to contain a global-buffer-overflow vulnerability via the function parseExpression at swftools/src/swfc.c:2587.
CVE-2024-22851 1 Liveconfig 1 Liveconfig 2025-06-05 7.5 High
Directory Traversal Vulnerability in LiveConfig before v.2.5.2 allows a remote attacker to obtain sensitive information via a crafted request to the /static/ endpoint.
CVE-2024-22817 1 Flycms Project 1 Flycms 2025-06-05 8.8 High
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_conf_updagte
CVE-2024-22773 1 Intelbras 2 Action Rf 1200, Action Rf 1200 Firmware 2025-06-05 8.1 High
Intelbras Action RF 1200 routers 1.2.2 and earlier and Action RG 1200 routers 2.1.7 and earlier expose the Password in Cookie resulting in Login Bypass.
CVE-2024-22548 1 Flycms Project 1 Flycms 2025-06-05 5.4 Medium
FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the system website settings website name section.
CVE-2024-22496 1 Jfinalcms Project 1 Jfinalcms 2025-06-05 6.1 Medium
Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the /admin/login username parameter.
CVE-2024-22491 1 Beetl-bbs Project 1 Beetl-bbs 2025-06-05 5.4 Medium
A Stored Cross Site Scripting (XSS) vulnerability in beetl-bbs 2.0 allows attackers to run arbitrary code via the post/save content parameter.
CVE-2024-22108 1 Gttb 1 Gtb Central Console 2025-06-05 9.8 Critical
An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method setTermsHashAction at /opt/webapp/lib/PureApi/CCApi.class.php is vulnerable to an unauthenticated SQL injection via /ccapi.php that an attacker can abuse in order to change the Administrator password to a known value.
CVE-2024-22075 1 Firefly-iii 1 Firefly Iii 2025-06-05 6.1 Medium
Firefly III (aka firefly-iii) before 6.1.1 allows webhooks HTML Injection.
CVE-2024-22911 1 Swftools 1 Swftools 2025-06-05 7.8 High
A stack-buffer-underflow vulnerability was found in SWFTools v0.9.2, in the function parseExpression at src/swfc.c:2602.
CVE-2024-22895 1 Dedecms 1 Dedecms 2025-06-05 8.8 High
DedeCMS 5.7.112 has a File Upload vulnerability via uploads/dede/module_upload.php.
CVE-2024-22720 1 Kanboard 1 Kanboard 2025-06-05 4.8 Medium
Kanboard 1.2.34 is vulnerable to Html Injection in the group management feature.
CVE-2024-22699 1 Flycms Project 1 Flycms 2025-06-05 8.8 High
FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/update_group_save.
CVE-2024-22519 1 Sorenfriis 1 Opendroneid Osm 2025-06-05 8.2 High
An issue discovered in OpenDroneID OSM 3.5.1 allows attackers to impersonate other drones via transmission of crafted data packets.
CVE-2024-22380 1 Maff 1 Electronic Delivery Check System 2025-06-05 5.5 Medium
Electronic Delivery Check System (Ministry of Agriculture, Forestry and Fisheries The Agriculture and Rural Development Project Version) March, Heisei 31 era edition Ver.14.0.001.002 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.
CVE-2025-5214 1 Lopalopa 1 Responsive Online Learing Platform 2025-06-05 7.3 High
A vulnerability was found in Kashipara Responsive Online Learing Platform 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /courses/course_detail_user_new.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The name of the affected product appears to have a typo in it.
CVE-2025-5215 1 Dlink 2 Dcs-5020l, Dcs-5020l Firmware 2025-06-05 8.8 High
A vulnerability classified as critical has been found in D-Link DCS-5020L 1.01_B2. This affects the function websReadEvent of the file /rame/ptdc.cgi. The manipulation of the argument Authorization leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.