Search Results (369876 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-24720 1 Readium 1 Readium-js 2025-02-11 9.8 Critical
An arbitrary file upload vulnerability in readium-js v0.32.0 allows attackers to execute arbitrary code via uploading a crafted EPUB file.
CVE-2023-22614 1 Insyde 1 Insydeh2o 2025-02-11 8.8 High
An issue was discovered in ChipsetSvcSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There is insufficient input validation in BIOS Guard updates. An attacker can induce memory corruption in SMM by supplying malformed inputs to the BIOS Guard SMI handler.
CVE-2023-22613 1 Insyde 1 Insydeh2o 2025-02-11 8.8 High
An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. It is possible to write to an attacker-controlled address. An attacker could invoke an SMI handler with a malformed pointer in RCX that overlaps SMRAM, resulting in SMM memory corruption.
CVE-2022-47465 2 Google, Unisoc 14 Android, S8000, Sc7731e and 11 more 2025-02-11 5.5 Medium
In vdsp service, there is a missing permission check. This could lead to local denial of service in vdsp service.
CVE-2021-46879 1 Treasuredata 1 Fluent Bit 2025-02-11 7.8 High
An issue was discovered in Treasure Data Fluent Bit 1.7.1, a wrong variable is used to get the msgpack data resulting in a heap overflow in flb_msgpack_gelf_value_ext. An attacker can craft a malicious file and tick the victim to open the file with the software, triggering a heap overflow and execute arbitrary code on the target system.
CVE-2020-36073 1 Tailor Management System Project 1 Tailor Management System 2025-02-11 8.8 High
SQL injection vulnerability found in Tailor Management System v.1 allows a remote attacker to execute arbitrary code via the detail parameter of the document.php page.
CVE-2023-1712 1 Deepset 1 Haystack 2025-02-11 9.8 Critical
Use of Hard-coded, Security-relevant Constants in GitHub repository deepset-ai/haystack prior to 0.1.30.
CVE-2023-1699 1 Rapid7 1 Nexpose 2025-02-11 4.3 Medium
Rapid7 Nexpose versions 6.6.186 and below suffer from a forced browsing vulnerability.  This vulnerability allows an attacker to manipulate URLs to forcefully browse to and access administrative pages. This vulnerability is fixed in version 6.6.187.  
CVE-2018-19873 5 Canonical, Debian, Opensuse and 2 more 6 Ubuntu Linux, Debian Linux, Backports and 3 more 2025-02-11 9.8 Critical
An issue was discovered in Qt before 5.11.3. QBmpHandler has a buffer overflow via BMP data.
CVE-2023-28731 1 Acymailing 1 Acymailing 2025-02-11 9.8 Critical
AnyMailing Joomla Plugin is vulnerable to unauthenticated remote code execution, when being granted access to the campaign's creation on front-office due to unrestricted file upload allowing PHP code to be injected. This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.
CVE-2023-28732 1 Acymailing 1 Acymailing 2025-02-11 6.5 Medium
Missing access control in AnyMailing Joomla Plugin allows to list and access files containing sensitive information from the plugin itself and access to system files via path traversal, when being granted access to the campaign's creation on front-office. This issue affects AnyMailing Joomla Plugin in versions below 8.3.0.
CVE-2024-43322 1 Zephyr-one 1 Zephyr Project Manager 2025-02-11 5.4 Medium
Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.100.
CVE-2024-38761 2 Dylanjames, Zephyr-one 2 Zephyr Project Manager, Zephyr Project Manager 2025-02-11 7.5 High
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.99.
CVE-2023-28733 1 Acymailing 1 Acymailing 2025-02-11 7.2 High
AnyMailing Joomla Plugin is vulnerable to stored cross site scripting (XSS) in templates and emails of AcyMailing, exploitable without authentication when access is granted to the campaign's creation on front-office. This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.
CVE-2023-27718 1 Dlink 2 Dir878, Dir878 Firmware 2025-02-11 9.8 Critical
D-Link DIR878 1.30B08 was discovered to contain a stack overflow in the sub_498308 function. This vulnerability allows attackers to cause a Denial of Service (DoS) or execute arbitrary code via a crafted payload.
CVE-2022-43473 1 Zohocorp 3 Manageengine Opmanager, Manageengine Opmanager Msp, Manageengine Opmanager Plus 2025-02-11 5.8 Medium
A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability.
CVE-2023-1737 1 Young Entrepreneur E-negosyo System Project 1 Young Entrepreneur E-negosyo System 2025-02-11 7.3 High
A vulnerability, which was classified as critical, was found in SourceCodester Young Entrepreneur E-Negosyo System 1.0. This affects an unknown part of the file login.php. The manipulation of the argument U_USERNAME leads to sql injection. It is possible to initiate the attack remotely. The identifier VDB-224625 was assigned to this vulnerability.
CVE-2022-47190 1 Generex 2 Cs141, Cs141 Firmware 2025-02-11 10 Critical
Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a webshell that could allow him to execute arbitrary code as root.
CVE-2022-47191 1 Generex 2 Cs141, Cs141 Firmware 2025-02-11 4.3 Medium
Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a firmware file containing a file with modified permissions, allowing him to escalate privileges.
CVE-2022-47192 1 Generex 2 Cs141, Cs141 Firmware 2025-02-11 8.8 High
Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a backup file containing a modified "users.json" to the web server of the device, allowing him to replace the administrator password.