Search Results (373668 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-25099 1 Afkmods 1 Qsf-portal 2025-04-10 5.5 Medium
A vulnerability classified as critical was found in Arthmoor QSF-Portal. This vulnerability affects unknown code of the file index.php. The manipulation of the argument a leads to path traversal. The patch is identified as ea4f61e23ecb83247d174bc2e2cbab521c751a7d. It is recommended to apply a patch to fix this issue. VDB-217558 is the identifier assigned to this vulnerability.
CVE-2022-22470 1 Ibm 1 Security Verify Governance 2025-04-10 4.1 Medium
IBM Security Verify Governance 10.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 225232.
CVE-2018-25068 1 Globalpom-utils Project 1 Globalpom-utils 2025-04-10 6.3 Medium
A vulnerability has been found in devent globalpom-utils up to 4.5.0 and classified as critical. This vulnerability affects the function createTmpDir of the file globalpomutils-fileresources/src/main/java/com/anrisoftware/globalpom/fileresourcemanager/FileResourceManagerProvider.java. The manipulation leads to insecure temporary file. The attack can be initiated remotely. Upgrading to version 4.5.1 is able to address this issue. The patch is identified as 77a820bac2f68e662ce261ecb050c643bd7ee560. It is recommended to upgrade the affected component. VDB-217570 is the identifier assigned to this vulnerability.
CVE-2015-10019 1 Mysimplifiedsql Project 1 Mysimplifiedsql 2025-04-10 3.5 Low
A vulnerability, which was classified as problematic, has been found in foxoverflow MySimplifiedSQL. This issue affects some unknown processing of the file MySimplifiedSQL_Examples.php. The manipulation of the argument FirstName/LastName leads to cross site scripting. The attack may be initiated remotely. The patch is named 3b7481c72786f88041b7c2d83bb4f219f77f1293. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217595.
CVE-2025-2196 1 Mrcms 1 Mrcms 2025-04-10 3.5 Low
A vulnerability was found in MRCMS 3.1.2. It has been declared as problematic. Affected by this vulnerability is the function upload of the file /admin/file/upload.do of the component org.marker.mushroom.controller.FileController. The manipulation of the argument path leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2024-28983 1 Hitachi 1 Pentaho Business Analytics Server 2025-04-10 8.8 High
Hitachi Vantara Pentaho Business Analytics Server prior to versions 10.1.0.0 and 9.3.0.7, including 8.3.x allow a malicious URL to inject content into the Analyzer plugin interface.
CVE-2025-2873 2025-04-10 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Further investigation showed that it was not a security issue. The issue relates to a session attribute used for login redirection. It poses no security risk and does not expose sensitive data. No vulnerability present.
CVE-2025-3023 2025-04-09 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-2845 2025-04-09 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-40539 2025-04-09 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-40223 2025-04-09 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-40159 2025-04-09 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2022-47656 1 Gpac 1 Gpac 2025-04-09 7.8 High
GPAC MP4box 2.1-DEV-rev617-g85ce76efd is vulnerable to Buffer Overflow in gf_hevc_read_sps_bs_internal function of media_tools/av_parsers.c:8273
CVE-2022-47523 1 Zohocorp 3 Manageengine Access Manager Plus, Manageengine Pam360, Manageengine Password Manager Pro 2025-04-09 9.8 Critical
Zoho ManageEngine Access Manager Plus before 4309, Password Manager Pro before 12210, and PAM360 before 5801 are vulnerable to SQL Injection.
CVE-2022-47095 1 Gpac 1 Gpac 2025-04-09 7.8 High
GPAC MP4box 2.1-DEV-rev574-g9d5bb184b is vulnerable to Buffer overflow in hevc_parse_vps_extension function of media_tools/av_parsers.c
CVE-2022-46762 1 Huawei 2 Emui, Harmonyos 2025-04-09 7.5 High
The memory management module has a logic bypass vulnerability.Successful exploitation of this vulnerability may affect data confidentiality.
CVE-2022-46761 1 Huawei 2 Emui, Harmonyos 2025-04-09 7.5 High
The system has a vulnerability that may cause dynamic hiding and restoring of app icons.Successful exploitation of this vulnerability may cause malicious hiding of app icons.
CVE-2022-45913 1 Zimbra 1 Collaboration 2025-04-09 6.1 Medium
An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur via one of attributes in webmail URLs to execute arbitrary JavaScript code, leading to information disclosure.
CVE-2022-45911 1 Zimbra 1 Collaboration 2025-04-09 6.1 Medium
An issue was discovered in Zimbra Collaboration (ZCS) 9.0. XSS can occur on the Classic UI login page by injecting arbitrary JavaScript code in the username field. This occurs before the user logs into the system, which means that even if the attacker executes arbitrary JavaScript, they will not get any sensitive information.
CVE-2022-44939 1 Echatserver 1 Easy Chat Server 2025-04-09 7.8 High
Efs Software Easy Chat Server Version 3.1 was discovered to contain a DLL hijacking vulnerability via the component TextShaping.dll. This vulnerability allows attackers to execute arbitrary code via a crafted DLL.