Export limit exceeded: 372336 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (372336 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-33443 | 1 Onethink | 1 Onethink | 2025-04-16 | 7.1 High |
| An issue in onethink v.1.1 allows a remote attacker to execute arbitrary code via a crafted script to the AddonsController.class.php component. | ||||
| CVE-2024-29865 | 1 Logpoint | 1 Siem | 2025-04-16 | 5.4 Medium |
| Logpoint before 7.1.0 allows Self-XSS on the LDAP authentication page via the username to the LDAP login form. | ||||
| CVE-2024-33438 | 1 Cubecart | 1 Cubecart | 2025-04-16 | 8 High |
| File Upload vulnerability in CubeCart before 6.5.5 allows an authenticated user to execute arbitrary code via a crafted .phar file. | ||||
| CVE-2024-33444 | 1 Onethink | 1 Onethink | 2025-04-16 | 9.8 Critical |
| SQL injection vulnerability in onethink v.1.1 allows a remote attacker to escalate privileges via a crafted script to the ModelModel.class.php component. | ||||
| CVE-2024-31615 | 1 Thinkcmf | 1 Thinkcmf | 2025-04-16 | 9.8 Critical |
| ThinkCMF 6.0.9 is vulnerable to File upload via UeditorController.php. | ||||
| CVE-2023-49983 | 1 Oretnom23 | 1 School Fees Management System | 2025-04-16 | 6.8 Medium |
| A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter. | ||||
| CVE-2023-49982 | 2 Oretnom23, Sourcecodester | 2 School Fees Management System, School Fees Management System | 2025-04-16 | 8.8 High |
| Broken access control in the component /admin/management/users of School Fees Management System v1.0 allows attackers to escalate privileges and perform Administrative actions, including adding and deleting user accounts. | ||||
| CVE-2023-49986 | 2 Oretnom23, Sourcecodester | 2 School Fees Management System, School Fees Management System | 2025-04-16 | 4.7 Medium |
| A cross-site scripting (XSS) vulnerability in the component /admin/parent of School Fees Management System 1.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter. | ||||
| CVE-2024-27694 | 1 Flycms Project | 1 Flycms | 2025-04-16 | 7.4 High |
| FlyCms v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via the /system/share/ztree_category_edit. | ||||
| CVE-2024-25551 | 1 Oretnom23 | 1 Simple Student Attendance System | 2025-04-16 | 6.1 Medium |
| Cross Site Scripting (XSS) vulnerability in sourcecodester Simple Student Attendance System v1.0 allows attackers to execute arbitrary code via crafted GET request to web application URL. | ||||
| CVE-2024-25434 | 1 Pkp.sfu | 1 Open Journal Systems | 2025-04-16 | 5.4 Medium |
| A cross-site scripting (XSS) vulnerability in Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Publicname parameter. | ||||
| CVE-2022-34270 | 1 Rws | 1 Worldserver | 2025-04-16 | 9.8 Critical |
| An issue was discovered in RWS WorldServer before 11.7.3. Regular users can create users with the Administrator role via UserWSUserManager. | ||||
| CVE-2022-23536 | 1 Linuxfoundation | 1 Cortex | 2025-04-16 | 6.5 Medium |
| Cortex provides multi-tenant, long term storage for Prometheus. A local file inclusion vulnerability exists in Cortex versions 1.13.0, 1.13.1 and 1.14.0, where a malicious actor could remotely read local files as a result of parsing maliciously crafted Alertmanager configurations when submitted to the Alertmanager Set Configuration API. Only users of the Alertmanager service where `-experimental.alertmanager.enable-api` or `enable_api: true` is configured are affected. Affected Cortex users are advised to upgrade to patched versions 1.13.2 or 1.14.1. However as a workaround, Cortex administrators may reject Alertmanager configurations containing the `api_key_file` setting in the `opsgenie_configs` section before sending to the Set Alertmanager Configuration API. | ||||
| CVE-2022-34269 | 1 Rws | 1 Worldserver | 2025-04-16 | 8.8 High |
| An issue was discovered in RWS WorldServer before 11.7.3. An authenticated, remote attacker can perform a ws-legacy/load_dtd?system_id= blind SSRF attack to deploy JSP code to the Apache Axis service running on the localhost interface, leading to command execution. | ||||
| CVE-2024-22078 | 2 Elspec, Elspec-ltd | 3 G5 Digital Fault Recorder, G5dfr, G5dfr Firmware | 2025-04-16 | 8.8 High |
| An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Privilege escalation can occur via world writable files. The network configuration script has weak filesystem permissions. This results in write access for all authenticated users and the possibility to escalate from user privileges to administrative privileges. | ||||
| CVE-2024-22077 | 1 Elspec-ltd | 2 G5dfr, G5dfr Firmware | 2025-04-16 | 5.3 Medium |
| An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. The SQLite database file has weak permissions. | ||||
| CVE-2024-24148 | 1 Libming | 1 Libming | 2025-04-16 | 7.5 High |
| A memory leak issue discovered in parseSWF_FREECHARACTER in libming v0.4.8 allows attackers to cause a denial of service via a crafted SWF file. | ||||
| CVE-2023-49985 | 2 Oretnom23, Sourcecodester | 2 School Fees Management System, School Fees Payment System | 2025-04-16 | 6.5 Medium |
| A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cname parameter. | ||||
| CVE-2023-49984 | 2 Oretnom23, Sourcecodester | 2 School Fees Management System, School Fees Management System | 2025-04-16 | 6.1 Medium |
| A cross-site scripting (XSS) vulnerability in the component /management/settings of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter. | ||||
| CVE-2024-25770 | 1 Libming | 1 Libming | 2025-04-16 | 4.3 Medium |
| libming 0.4.8 contains a memory leak vulnerability in /libming/src/actioncompiler/listaction.c. | ||||