Search Results (326098 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-35095 1 Swftools 1 Swftools 2025-05-23 5.5 Medium
SWFTools commit 772e55a2 was discovered to contain a segmentation violation via InfoOutputDev::type3D1 at /pdf/InfoOutputDev.cc.
CVE-2022-35094 1 Swftools 1 Swftools 2025-05-23 5.5 Medium
SWFTools commit 772e55a2 was discovered to contain a heap-buffer overflow via DCTStream::readHuffSym(DCTHuffTable*) at /xpdf/Stream.cc.
CVE-2022-35093 1 Swftools 1 Swftools 2025-05-23 5.5 Medium
SWFTools commit 772e55a2 was discovered to contain a global buffer overflow via DCTStream::transformDataUnit at /xpdf/Stream.cc.
CVE-2024-43687 1 Microchip 2 Timeprovider 4100, Timeprovider 4100 Firmware 2025-05-23 6.1 Medium
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip TimeProvider 4100 (banner config modules) allows Cross-Site Scripting (XSS).This issue affects TimeProvider 4100: from 1.0 before 2.4.7.
CVE-2024-25844 1 Common-services 1 So Flexibilite 2025-05-23 7.5 High
An issue was discovered in Common-Services "So Flexibilite" (soflexibilite) module for PrestaShop before version 4.1.26, allows remote attackers to escalate privileges and obtain sensitive information via debug file.
CVE-2024-57665 1 Heyewei 1 Jfinalcms 2025-05-23 9.8 Critical
JFinalCMS 1.0 is vulnerable to SQL Injection in rc/main/java/com/cms/entity/Content.java. The cause of the vulnerability is that the title parameter is controllable and is concatenated directly into filterSql without filtering.
CVE-2024-55415 1 Thecontrolgroup 1 Voyager 2025-05-23 5.7 Medium
DevDojo Voyager through 1.8.0 is vulnerable to path traversal at the /admin/compass.
CVE-2025-0792 1 Esafenet 1 Cdg 2025-05-23 6.3 Medium
A vulnerability, which was classified as critical, was found in ESAFENET CDG V5. Affected is an unknown function of the file /sdTodoDetail.jsp. The manipulation of the argument flowId leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2024-25858 1 Foxit 2 Pdf Editor, Pdf Reader 2025-05-23 8.4 High
In Foxit PDF Reader before 2024.1 and PDF Editor before 2024.1, code execution via JavaScript could occur because of an unoptimized prompt message for users to review parameters of commands.
CVE-2024-24278 2 Microsoft, Teamwire 2 Windows, Teamwire 2025-05-23 7.5 High
An issue in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the message function.
CVE-2024-21805 1 Skygroup 1 Skysea Client View 2025-05-23 7.8 High
Improper access control vulnerability exists in the specific folder of SKYSEA Client View versions from Ver.16.100 prior to Ver.19.2. If this vulnerability is exploited, an arbitrary file may be placed in the specific folder by a user who can log in to the PC where the product's Windows client is installed. In case the file is a specially crafted DLL file, arbitrary code may be executed with SYSTEM privilege.
CVE-2024-24964 1 Skygroup 1 Skysea Client View 2025-05-23 6.3 Medium
Improper access control vulnerability exists in the resident process of SKYSEA Client View versions from Ver.11.220 prior to Ver.19.2. If this vulnerability is exploited, an arbitrary process may be executed with SYSTEM privilege by a user who can log in to the PC where the product's Windows client is installed.
CVE-2024-2020 1 Codepeople 1 Calculated Fields Form 2025-05-23 7.2 High
The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form page href parameter in all versions up to, and including, 5.1.56 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Exploitation requires the professional version or higher.
CVE-2024-28662 1 Piwigo 1 Piwigo 2025-05-23 5.4 Medium
A Cross Site Scripting vulnerability exists in Piwigo before 14.3.0 script because of missing sanitization in create_tag in admin/include/functions.php.
CVE-2025-0791 1 Esafenet 1 Cdg 2025-05-23 6.3 Medium
A vulnerability, which was classified as critical, has been found in ESAFENET CDG V5. This issue affects some unknown processing of the file /sdDoneDetail.jsp. The manipulation of the argument flowId leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2024-25934 1 Formfacade 1 Formfacade 2025-05-23 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FormFacade allows Stored XSS.This issue affects FormFacade: from n/a through 1.0.0.
CVE-2024-24539 1 Fusionpbx 1 Fusionpbx 2025-05-23 5.3 Medium
FusionPBX before 5.2.0 does not validate a session.
CVE-2024-23721 1 Draytek 2 Vigor3910, Vigor3910 Firmware 2025-05-23 7.5 High
A Directory Traversal issue was discovered in process_post on Draytek Vigor3910 4.3.2.5 devices. When sending a certain POST request, it calls the function and exports information.
CVE-2025-0790 1 Esafenet 1 Cdg 2025-05-23 3.5 Low
A vulnerability classified as problematic was found in ESAFENET CDG V5. This vulnerability affects unknown code of the file /doneDetail.jsp. The manipulation of the argument curpage leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-0789 1 Esafenet 1 Cdg 2025-05-23 6.3 Medium
A vulnerability classified as critical has been found in ESAFENET CDG V5. This affects an unknown part of the file /doneDetail.jsp. The manipulation of the argument flowId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.