Search Results (323689 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-12611 1 Dasinfomedia 1 School Management System 2025-07-07 5.3 Medium
The School Management System for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'title' parameter in all versions up to, and including, 93.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
CVE-2025-25929 1 Openmrs 1 Openmrs 2025-07-07 5.4 Medium
A reflected cross-site scripting (XSS) vulnerability in the component /legacyui/quickReportServlet of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary JavaScript in the context of a user's browser via a crafted payload injected into the reportType parameter.
CVE-2025-25680 1 Lsc 2 Ptz Dual Band Camera, Ptz Dual Band Camera Firmware 2025-07-07 7.7 High
LSC Smart Connect LSC Indoor PTZ Camera 7.6.32 is contains a RCE vulnerability in the tuya_ipc_direct_connect function of the anyka_ipc process. The vulnerability allows arbitrary code execution through the Wi-Fi configuration process when a specially crafted QR code is presented to the camera.
CVE-2022-22017 1 Microsoft 3 Remote Desktop Client, Windows 11, Windows Server 2022 2025-07-07 8.8 High
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2019-0887 1 Microsoft 10 Remote Desktop Client, Windows 10, Windows 11 21h2 and 7 more 2025-07-07 8.0 High
A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
CVE-2021-38665 1 Microsoft 21 Remote Desktop, Remote Desktop Client, Windows 10 and 18 more 2025-07-07 7.4 High
Remote Desktop Protocol Client Information Disclosure Vulnerability
CVE-2022-22015 1 Microsoft 10 Remote Desktop Client, Windows 10, Windows 11 and 7 more 2025-07-07 6.5 Medium
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
CVE-2021-34535 1 Microsoft 17 Remote Desktop Client, Windows 10, Windows 10 1507 and 14 more 2025-07-07 8.8 High
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2022-26940 1 Microsoft 3 Remote Desktop Client, Windows 11, Windows Server 2022 2025-07-07 6.5 Medium
Remote Desktop Protocol Client Information Disclosure Vulnerability
CVE-2024-49105 1 Microsoft 17 Remote Desktop Client, Windows 10 1507, Windows 10 1607 and 14 more 2025-07-07 8.4 High
Remote Desktop Client Remote Code Execution Vulnerability
CVE-2021-1669 1 Microsoft 14 Remote Desktop, Remote Desktop Client, Windows 10 and 11 more 2025-07-07 8.8 High
Windows Remote Desktop Security Feature Bypass Vulnerability
CVE-2022-23302 6 Apache, Broadcom, Netapp and 3 more 44 Log4j, Brocade Sannav, Snapmanager and 41 more 2025-07-07 8.8 High
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104. Note this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
CVE-2024-56810 3 Ibm, Linux, Microsoft 3 Entirex, Linux Kernel, Windows 2025-07-07 3.3 Low
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
CVE-2024-56811 3 Ibm, Linux, Microsoft 3 Entirex, Linux Kernel, Windows 2025-07-07 3.3 Low
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
CVE-2025-25928 1 Openmrs 1 Openmrs 2025-07-07 8 High
A Cross-Site Request Forgery (CSRF) in the component /admin/users/user.form of Openmrs 2.4.3 Build 0ff0ed allows attackers to execute arbitrary operations via a crafted request. In this case, an attacker could elevate a low-privileged account to an administrative role by leveraging the CSRF vulnerability at the /admin/users/user.form endpoint.
CVE-2024-56812 3 Ibm, Linux, Microsoft 3 Entirex, Linux Kernel, Windows 2025-07-07 3.3 Low
IBM EntireX 11.1 could allow a local user to obtain sensitive information when a detailed technical error message is returned. This information could be used in further attacks against the system.
CVE-2024-57046 1 Netgear 2 Dgn2200, Dgn2200 Firmware 2025-07-07 8.8 High
A vulnerability in the Netgear DGN2200 router with firmware version v1.0.0.46 and earlier permits unauthorized individuals to bypass the authentication. When adding "?x=1.gif" to the the requested url, it will be recognized as passing the authentication.
CVE-2024-52726 1 Crmeb 1 Crmeb 2025-07-07 7.5 High
CRMEB v5.4.0 is vulnerable to Arbitrary file read in the save_basics function which allows an attacker to obtain sensitive information
CVE-2024-5285 1 Tipsandtricks-hq 1 Wp Affiliate Platform 2025-07-07 5.5 Medium
The wp-affiliate-platform WordPress plugin before 6.5.2 does not have CSRF check in place when deleting affiliates, which could allow attackers to make a logged in user change delete them via a CSRF attack
CVE-2024-52871 1 Flagsmith 1 Flagsmith 2025-07-07 7.5 High
In Flagsmith before 2.134.1, it is possible to bypass the ALLOW_REGISTRATION_WITHOUT_INVITE setting.