Export limit exceeded: 374421 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 374421 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 374421 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (374421 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-20392 | 1 Google | 1 Android | 2025-06-05 | 7.8 High |
| In declareDuplicatePermission of ParsedPermissionUtils.java, there is a possible way to obtain a dangerous permission without user consent due to improper input validation. This could lead to local escalation of privilege during app installation or upgrade with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-213323615 | ||||
| CVE-2022-20389 | 1 Google | 1 Android | 2025-06-05 | 9.8 Critical |
| Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238257004 | ||||
| CVE-2022-20388 | 1 Google | 1 Android | 2025-06-05 | 9.8 Critical |
| Summary:Product: AndroidVersions: Android SoCAndroid ID: A-238227323 | ||||
| CVE-2024-22919 | 1 Swftools | 1 Swftools | 2025-06-05 | 7.8 High |
| swftools0.9.2 was discovered to contain a global-buffer-overflow vulnerability via the function parseExpression at swftools/src/swfc.c:2587. | ||||
| CVE-2024-22851 | 1 Liveconfig | 1 Liveconfig | 2025-06-05 | 7.5 High |
| Directory Traversal Vulnerability in LiveConfig before v.2.5.2 allows a remote attacker to obtain sensitive information via a crafted request to the /static/ endpoint. | ||||
| CVE-2024-22817 | 1 Flycms Project | 1 Flycms | 2025-06-05 | 8.8 High |
| FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/email/email_conf_updagte | ||||
| CVE-2024-22773 | 1 Intelbras | 2 Action Rf 1200, Action Rf 1200 Firmware | 2025-06-05 | 8.1 High |
| Intelbras Action RF 1200 routers 1.2.2 and earlier and Action RG 1200 routers 2.1.7 and earlier expose the Password in Cookie resulting in Login Bypass. | ||||
| CVE-2024-22548 | 1 Flycms Project | 1 Flycms | 2025-06-05 | 5.4 Medium |
| FlyCms 1.0 is vulnerable to Cross Site Scripting (XSS) in the system website settings website name section. | ||||
| CVE-2024-22496 | 1 Jfinalcms Project | 1 Jfinalcms | 2025-06-05 | 6.1 Medium |
| Cross Site Scripting (XSS) vulnerability in JFinalcms 5.0.0 allows attackers to run arbitrary code via the /admin/login username parameter. | ||||
| CVE-2024-22491 | 1 Beetl-bbs Project | 1 Beetl-bbs | 2025-06-05 | 5.4 Medium |
| A Stored Cross Site Scripting (XSS) vulnerability in beetl-bbs 2.0 allows attackers to run arbitrary code via the post/save content parameter. | ||||
| CVE-2024-22108 | 1 Gttb | 1 Gtb Central Console | 2025-06-05 | 9.8 Critical |
| An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method setTermsHashAction at /opt/webapp/lib/PureApi/CCApi.class.php is vulnerable to an unauthenticated SQL injection via /ccapi.php that an attacker can abuse in order to change the Administrator password to a known value. | ||||
| CVE-2024-22075 | 1 Firefly-iii | 1 Firefly Iii | 2025-06-05 | 6.1 Medium |
| Firefly III (aka firefly-iii) before 6.1.1 allows webhooks HTML Injection. | ||||
| CVE-2024-22911 | 1 Swftools | 1 Swftools | 2025-06-05 | 7.8 High |
| A stack-buffer-underflow vulnerability was found in SWFTools v0.9.2, in the function parseExpression at src/swfc.c:2602. | ||||
| CVE-2024-22895 | 1 Dedecms | 1 Dedecms | 2025-06-05 | 8.8 High |
| DedeCMS 5.7.112 has a File Upload vulnerability via uploads/dede/module_upload.php. | ||||
| CVE-2024-22720 | 1 Kanboard | 1 Kanboard | 2025-06-05 | 4.8 Medium |
| Kanboard 1.2.34 is vulnerable to Html Injection in the group management feature. | ||||
| CVE-2024-22699 | 1 Flycms Project | 1 Flycms | 2025-06-05 | 8.8 High |
| FlyCms v1.0 contains a Cross-Site Request Forgery (CSRF) vulnerability via /system/admin/update_group_save. | ||||
| CVE-2024-22519 | 1 Sorenfriis | 1 Opendroneid Osm | 2025-06-05 | 8.2 High |
| An issue discovered in OpenDroneID OSM 3.5.1 allows attackers to impersonate other drones via transmission of crafted data packets. | ||||
| CVE-2024-22380 | 1 Maff | 1 Electronic Delivery Check System | 2025-06-05 | 5.5 Medium |
| Electronic Delivery Check System (Ministry of Agriculture, Forestry and Fisheries The Agriculture and Rural Development Project Version) March, Heisei 31 era edition Ver.14.0.001.002 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker. | ||||
| CVE-2025-5214 | 1 Lopalopa | 1 Responsive Online Learing Platform | 2025-06-05 | 7.3 High |
| A vulnerability was found in Kashipara Responsive Online Learing Platform 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /courses/course_detail_user_new.php. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The name of the affected product appears to have a typo in it. | ||||
| CVE-2025-5215 | 1 Dlink | 2 Dcs-5020l, Dcs-5020l Firmware | 2025-06-05 | 8.8 High |
| A vulnerability classified as critical has been found in D-Link DCS-5020L 1.01_B2. This affects the function websReadEvent of the file /rame/ptdc.cgi. The manipulation of the argument Authorization leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer. | ||||