Export limit exceeded: 372336 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (372336 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-33443 1 Onethink 1 Onethink 2025-04-16 7.1 High
An issue in onethink v.1.1 allows a remote attacker to execute arbitrary code via a crafted script to the AddonsController.class.php component.
CVE-2024-29865 1 Logpoint 1 Siem 2025-04-16 5.4 Medium
Logpoint before 7.1.0 allows Self-XSS on the LDAP authentication page via the username to the LDAP login form.
CVE-2024-33438 1 Cubecart 1 Cubecart 2025-04-16 8 High
File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted .phar file.
CVE-2024-33444 1 Onethink 1 Onethink 2025-04-16 9.8 Critical
SQL injection vulnerability in onethink v.1.1 allows a remote attacker to escalate privileges via a crafted script to the ModelModel.class.php component.
CVE-2024-31615 1 Thinkcmf 1 Thinkcmf 2025-04-16 9.8 Critical
ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php.
CVE-2023-49983 1 Oretnom23 1 School Fees Management System 2025-04-16 6.8 Medium
A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.
CVE-2023-49982 2 Oretnom23, Sourcecodester 2 School Fees Management System, School Fees Management System 2025-04-16 8.8 High
Broken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to escalate privileges and perform Administrative actions, including adding and deleting user accounts.
CVE-2023-49986 2 Oretnom23, Sourcecodester 2 School Fees Management System, School Fees Management System 2025-04-16 4.7 Medium
A cross-site scripting (XSS) vulnerability in the component /admin/parent of School Fees Management System 1.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.
CVE-2024-27694 1 Flycms Project 1 Flycms 2025-04-16 7.4 High
FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the /system/share/ztree_category_edit.
CVE-2024-25551 1 Oretnom23 1 Simple Student Attendance System 2025-04-16 6.1 Medium
Cross Site Scripting (XSS) vulnerability in sourcecodester Simple Student Attendance System v1.0 allows attackers to execute arbitrary code via crafted GET request to web application URL.
CVE-2024-25434 1 Pkp.sfu 1 Open Journal Systems 2025-04-16 5.4 Medium
A cross-site scripting (XSS) vulnerability in Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Publicname parameter.
CVE-2022-34270 1 Rws 1 Worldserver 2025-04-16 9.8 Critical
An issue was discovered in RWS WorldServer before 11.7.3. Regular users can create users with the Administrator role via UserWSUserManager.
CVE-2022-23536 1 Linuxfoundation 1 Cortex 2025-04-16 6.5 Medium
Cortex provides multi-tenant, long term storage for Prometheus. A local file inclusion vulnerability exists in Cortex versions 1.13.0, 1.13.1 and 1.14.0, where a malicious actor could remotely read local files as a result of parsing maliciously crafted Alertmanager configurations when submitted to the Alertmanager Set Configuration API. Only users of the Alertmanager service where `-experimental.alertmanager.enable-api` or `enable_api: true` is configured are affected. Affected Cortex users are advised to upgrade to patched versions 1.13.2 or 1.14.1. However as a workaround, Cortex administrators may reject Alertmanager configurations containing the `api_key_file` setting in the `opsgenie_configs` section before sending to the Set Alertmanager Configuration API.
CVE-2022-34269 1 Rws 1 Worldserver 2025-04-16 8.8 High
An issue was discovered in RWS WorldServer before 11.7.3. An authenticated, remote attacker can perform a ws-legacy/load_dtd?system_id= blind SSRF attack to deploy JSP code to the Apache Axis service running on the localhost interface, leading to command execution.
CVE-2024-22078 2 Elspec, Elspec-ltd 3 G5 Digital Fault Recorder, G5dfr, G5dfr Firmware 2025-04-16 8.8 High
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Privilege escalation can occur via world writable files. The network configuration script has weak filesystem permissions. This results in write access for all authenticated users and the possibility to escalate from user privileges to administrative privileges.
CVE-2024-22077 1 Elspec-ltd 2 G5dfr, G5dfr Firmware 2025-04-16 5.3 Medium
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The SQLite database file has weak permissions.
CVE-2024-24148 1 Libming 1 Libming 2025-04-16 7.5 High
A memory leak issue discovered in parseSWF_FREECHARACTER in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file.
CVE-2023-49985 2 Oretnom23, Sourcecodester 2 School Fees Management System, School Fees Payment System 2025-04-16 6.5 Medium
A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cname parameter.
CVE-2023-49984 2 Oretnom23, Sourcecodester 2 School Fees Management System, School Fees Management System 2025-04-16 6.1 Medium
A cross-site scripting (XSS) vulnerability in the component /management/settings of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.
CVE-2024-25770 1 Libming 1 Libming 2025-04-16 4.3 Medium
libming 0.4.8 contains a memory leak vulnerability in /libming/src/actioncompiler/listaction.c.