Search Results (372564 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-9880 2025-03-26 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-4382 1 Wielebenwir 1 Commonsbooking 2025-03-26 4.3 Medium
The CB (legacy) WordPress plugin through 0.9.4.18 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting codes, timeframes, and bookings via CSRF attacks
CVE-2024-26309 1 Archerirm 1 Archer 2025-03-26 5.3 Medium
Archer Platform 6.x before 6.14 P2 HF2 (6.14.0.2.2) contains a sensitive information disclosure vulnerability. An unauthenticated attacker could potentially obtain access to sensitive information via an internal URL.
CVE-2024-10096 2025-03-26 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-6936 1 Wolfssl 1 Wolfssl 2025-03-26 5.3 Medium
In wolfSSL prior to 5.6.6, if callback functions are enabled (via the WOLFSSL_CALLBACKS flag), then a malicious TLS client or network attacker can trigger a buffer over-read on the heap of 5 bytes (WOLFSSL_CALLBACKS is only intended for debugging).
CVE-2021-37304 1 Jeecg 1 Jeecg 2025-03-26 7.5 High
An Insecure Permissions issue in jeecg-boot 2.4.5 allows unauthenticated remote attackers to gain escalated privilege and view sensitive information via the httptrace interface.
CVE-2021-37234 1 Modern Honey Network Project 1 Modern Honey Network 2025-03-26 6.5 Medium
Incorrect Access Control vulnerability in Modern Honey Network commit 0abf0db9cd893c6d5c727d036e1f817c02de4c7b allows remote attackers to view sensitive information via crafted PUT request to Web API.
CVE-2021-36712 1 Yzmcms 1 Yzmcms 2025-03-26 5.4 Medium
Cross Site Scripting (XSS) vulnerability in yzmcms 6.1 allows attackers to steal user cookies via image clipping function.
CVE-2021-36570 1 Thedaylightstudio 1 Fuel Cms 2025-03-26 8.8 High
Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /permissions/delete/2---.
CVE-2021-36569 1 Thedaylightstudio 1 Fuel Cms 2025-03-26 8.8 High
Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /users/delete/2.
CVE-2021-36546 1 Kitesky 1 Kitecms 2025-03-26 7.5 High
Incorrect Access Control issue discovered in KiteCMS 1.1 allows remote attackers to view sensitive information via path in application URL.
CVE-2021-36545 1 Tpcms Project 1 Tpcms 2025-03-26 5.4 Medium
Cross Site Scripting (XSS) vulnerability in tpcms 3.2 allows remote attackers to run arbitrary code via the cfg_copyright or cfg_tel field in Site Configuration page.
CVE-2021-36544 1 Tpcms Project 1 Tpcms 2025-03-26 7.5 High
Incorrect Access Control issue discovered in tpcms 3.2 allows remote attackers to view sensitive information via path in application URL.
CVE-2021-36538 1 Gurock 1 Testrail 2025-03-26 5.4 Medium
Cross Site Scripting (XSS) vulnerability in Gurock TestRail before 7.1.2 allows remote authenticated attackers to run arbitrary code via the reference field in milestones or description fields in reports.
CVE-2021-36535 1 Cesanta 1 Mjs 2025-03-26 5.5 Medium
Buffer Overflow vulnerability in Cesanta mJS 1.26 allows remote attackers to cause a denial of service via crafted .js file to mjs_set_errorf.
CVE-2021-36484 1 Jizhicms 1 Jizhicms 2025-03-26 9.8 Critical
SQL injection vulnerability in JIZHICMS 1.9.5 allows attackers to run arbitrary SQL commands via add or edit article page.
CVE-2021-36444 1 Txjia 1 Imcat 2025-03-26 8.8 High
Cross Site Request Forgery (CSRF) vulnerability in imcat 5.4 allows remote attackers to gain escalated privileges via flaws one time token generation on the add administrator page.
CVE-2021-36443 1 Txjia 1 Imcat 2025-03-26 8.8 High
Cross Site Request Forgery vulnerability in imcat 5.4 allows remote attackers to escalate privilege via lack of token verification.
CVE-2021-36434 1 Jocms Project 1 Jocms 2025-03-26 9.1 Critical
SQL injection vulnerability in jocms 0.8 allows remote attackers to run arbitrary SQL commands and view sentivie information via jo_json_check function in jocms/apps/mask/inc/getmask.php.
CVE-2023-23948 1 Owncloud 1 Owncloud Client 2025-03-26 6.2 Medium
The ownCloud Android app allows ownCloud users to access, share, and edit files and folders. Version 2.21.1 of the ownCloud Android app is vulnerable to SQL injection in `FileContentProvider.kt`. This issue can lead to information disclosure. Two databases, `filelist` and `owncloud_database`, are affected. In version 3.0, the `filelist` database was deprecated. However, injections affecting `owncloud_database` remain relevant as of version 3.0.