Search Results (323694 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-30135 1 Hcltech 1 Dryice Aex 2025-10-30 3.3 Low
HCL DRYiCE AEX is potentially impacted by disclosure of sensitive information in the mobile application when a snapshot is taken.
CVE-2025-56161 2 Yiovo, Yoshop 2 Firefly Mall, Yoshop 2025-10-30 7.5 High
YOSHOP 2.0 allows unauthenticated information disclosure via comment-list API endpoints in the Goods module. The Comment model eagerly loads the related User model without field filtering; because User.php defines no $hidden or $visible attributes, sensitive fields (bcrypt password hash, mobile number, pay_money, expend_money.) are exposed in JSON responses. Route names vary per deployment (e.g. /api/goods.pinglun/list), but all call the same vulnerable model logic.
CVE-2025-56162 2 Yiovo, Yoshop 2 Firefly Mall, Yoshop 2025-10-30 6.5 Medium
YOSHOP 2.0 suffers from an unauthenticated SQL injection in the goodsIds parameter of the /api/goods/listByIds endpoint. The getListByIds function concatenates user input into orderRaw('field(goods_id, ...)'), allowing attackers to: (a) enumerate or modify database data, including dumping admin password hashes; (b) write web-shell files or invoke xp_cmdshell, leading to remote code execution on servers configured with sufficient DB privileges.
CVE-2024-30130 1 Hcltech 1 Nomad Server On Domino 2025-10-30 3.7 Low
HCL Nomad server on Domino is vulnerable to the cache containing sensitive information which could potentially give an attacker the ability to acquire the sensitive information.
CVE-2024-30128 1 Hcltech 1 Nomad Server On Domino 2025-10-30 8.6 High
HCL Nomad server on Domino is affected by an open proxy vulnerability in which an unauthenticated attacker can mask their original source IP address. This may enable an attacker to trick the user into exposing sensitive information.
CVE-2024-30134 1 Hcltech 2 Traveler, Traveler For Microsoft Outlook 2025-10-30 6.7 Medium
The HCL Traveler for Microsoft Outlook executable (HTMO.exe) is being flagged as potentially Malicious Software or an Unrecognized Application.
CVE-2025-8848 1 Librechat 1 Librechat 2025-10-30 5.4 Medium
A vulnerability in danny-avila/librechat version 0.7.9 allows for HTML injection via the Accept-Language header. When a logged-in user sends an HTTP GET request with a crafted Accept-Language header, arbitrary HTML can be injected into the <html lang=""> tag of the response. This can lead to potential security risks such as cross-site scripting (XSS) attacks.
CVE-2025-11819 1 Wordpress 1 Wordpress 2025-10-30 6.4 Medium
The WP-Thumbnail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'roboshot' shortcode in all versions up to, and including, 1.1. This is due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2023-38163 1 Microsoft 1 Windows Defender Security Intelligence Updates 2025-10-30 7.8 High
Windows Defender Attack Surface Reduction Security Feature Bypass
CVE-2023-36739 1 Microsoft 1 3d Viewer 2025-10-30 7.8 High
3D Viewer Remote Code Execution Vulnerability
CVE-2023-36740 1 Microsoft 1 3d Viewer 2025-10-30 7.8 High
3D Viewer Remote Code Execution Vulnerability
CVE-2023-36777 1 Microsoft 1 Exchange Server 2025-10-30 5.7 Medium
Microsoft Exchange Server Information Disclosure Vulnerability
CVE-2023-36760 1 Microsoft 1 3d Viewer 2025-10-30 7.8 High
3D Viewer Remote Code Execution Vulnerability
CVE-2023-36761 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2025-10-30 6.5 Medium
Microsoft Word Information Disclosure Vulnerability
CVE-2023-36762 1 Microsoft 5 365 Apps, Office, Office Long Term Servicing Channel and 2 more 2025-10-30 7.3 High
Microsoft Word Remote Code Execution Vulnerability
CVE-2023-36763 1 Microsoft 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more 2025-10-30 7.5 High
Microsoft Outlook Information Disclosure Vulnerability
CVE-2023-36764 1 Microsoft 1 Sharepoint Server 2025-10-30 8.8 High
Microsoft SharePoint Server Elevation of Privilege Vulnerability
CVE-2023-36770 1 Microsoft 1 3d Builder 2025-10-30 7.8 High
3D Builder Remote Code Execution Vulnerability
CVE-2023-36771 1 Microsoft 1 3d Builder 2025-10-30 7.8 High
3D Builder Remote Code Execution Vulnerability
CVE-2023-36772 1 Microsoft 1 3d Builder 2025-10-30 7.8 High
3D Builder Remote Code Execution Vulnerability