Total
19534 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2022-44097 | 1 Book Store Management System Project | 1 Book Store Management System | 2025-04-24 | 9.8 Critical |
Book Store Management System v1.0 was discovered to contain hardcoded credentials which allows attackers to escalate privileges and access the admin panel. | ||||
CVE-2022-44136 | 1 Tribalsystems | 1 Zenario | 2025-04-24 | 9.8 Critical |
Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE). | ||||
CVE-2022-37016 | 1 Broadcom | 1 Symantec Endpoint Protection | 2025-04-24 | 9.8 Critical |
Symantec Endpoint Protection (Windows) agent may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user. | ||||
CVE-2022-44290 | 1 Webtareas Project | 1 Webtareas | 2025-04-24 | 9.8 Critical |
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in deleteapprovalstages.php. | ||||
CVE-2022-44291 | 1 Webtareas Project | 1 Webtareas | 2025-04-24 | 9.8 Critical |
webTareas 2.4p5 was discovered to contain a SQL injection vulnerability via the id parameter in phasesets.php. | ||||
CVE-2024-32752 | 2025-04-24 | 9.1 Critical | ||
The iSTAR door controllers running firmware prior to version 6.6.B, does not support authenticated communications with ICU, which may allow an attacker to gain unauthorized access | ||||
CVE-2022-44367 | 1 Tenda | 2 I21, I21 Firmware | 2025-04-24 | 9.8 Critical |
Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/setUplinkInfo. | ||||
CVE-2022-44362 | 1 Tenda | 2 I21, I21 Firmware | 2025-04-24 | 9.8 Critical |
Tenda i21 V1.0.0.14(4656) is vulnerable to Buffer Overflow via /goform/AddSysLogRule. | ||||
CVE-2022-44151 | 1 Sanitization Management System Project | 1 Sanitization Management System | 2025-04-24 | 9.8 Critical |
Simple Inventory Management System v1.0 is vulnerable to SQL Injection via /ims/login.php. | ||||
CVE-2022-43325 | 1 Telosalliance | 2 Omnia Mpx Node, Omnia Mpx Node Firmware | 2025-04-24 | 9.8 Critical |
An unauthenticated command injection vulnerability in the product license validation function of Telos Alliance Omnia MPX Node 1.3.* - 1.4.* allows attackers to execute arbitrary commands via a crafted payload injected into the license input. | ||||
CVE-2022-3270 | 1 Festo | 198 Bus Module Cpx-e-ep, Bus Module Cpx-e-ep Firmware, Bus Node Cpx-fb32 and 195 more | 2025-04-24 | 9.8 Critical |
In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability. | ||||
CVE-2025-43859 | 2025-04-24 | 9.1 Critical | ||
h11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in chunked-coding message bodies can lead to request smuggling vulnerabilities under certain conditions. This issue has been patched in version 0.16.0. Since exploitation requires the combination of buggy h11 with a buggy (reverse) proxy, fixing either component is sufficient to mitigate this issue. | ||||
CVE-2025-43858 | 2025-04-24 | 9.2 Critical | ||
YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.0-beta4 and prior to 1.1.2, an unsafe conversion of arguments allows the injection of a malicious commands when starting `yt-dlp` from a commands prompt running on Windows OS with the `UseWindowsEncodingWorkaround` value defined to true (default behavior). If a user is using built-in methods from the YoutubeDL.cs file, the value is true by default and a user cannot disable it from these methods. This issue has been patched in version 1.1.2. | ||||
CVE-2022-30528 | 1 Isic.lk Project | 1 Isic.lk | 2025-04-24 | 9.8 Critical |
SQL Injection vulnerability in asith-eranga ISIC tour booking through version published on Feb 13th 2018, allows attackers to execute arbitrary commands via the username parameter to /system/user/modules/mod_users/controller.php. | ||||
CVE-2022-43333 | 1 Teleniasoftware | 1 Tvox | 2025-04-24 | 9.8 Critical |
Telenia Software s.r.l TVox before v22.0.17 was discovered to contain a remote code execution (RCE) vulnerability in the component action_export_control.php. | ||||
CVE-2022-36431 | 1 Rocketsoftware | 1 Trufusion | 2025-04-24 | 9.8 Critical |
An arbitrary file upload vulnerability in Rocket TRUfusion Enterprise before 7.9.6.1 allows unauthenticated attackers to execute arbitrary code via a crafted JSP file. Issue fixed in version 7.9.6.1. | ||||
CVE-2025-31324 | 2025-04-24 | 10 Critical | ||
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system. | ||||
CVE-2020-35605 | 2 Debian, Kovidgoyal | 2 Debian Linux, Kitty | 2025-04-24 | 9.8 Critical |
The Graphics Protocol feature in graphics.c in kitty before 0.19.3 allows remote attackers to execute arbitrary code because a filename containing special characters can be included in an error message. | ||||
CVE-2024-0864 | 2 Laragon, Leokhoa | 2 Laragon, Laragon | 2025-04-24 | 9.8 Critical |
Enabling Simple Ajax Uploader plugin included in Laragon open-source software allows for a remote code execution (RCE) attack via an improper input validation in a file_upload.php file which serves as an example. By default, Laragon is not vulnerable until a user decides to use the aforementioned plugin. | ||||
CVE-2025-29287 | 1 Mingsoft | 1 Mcms | 2025-04-24 | 9.8 Critical |
An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file. |