Search Results (323552 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-41767 1 Mediawiki 1 Mediawiki 2025-04-14 5.3 Medium
An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. When changes made by an IP address are reassigned to a user (using reassignEdits.php), the changes will still be attributed to the IP address on Special:Contributions when doing a range lookup.
CVE-2022-41765 1 Mediawiki 1 Mediawiki 2025-04-14 5.3 Medium
An issue was discovered in MediaWiki before 1.35.8, 1.36.x and 1.37.x before 1.37.5, and 1.38.x before 1.38.3. HTMLUserTextField exposes the existence of hidden users.
CVE-2022-37313 1 Open-xchange 1 Open-xchange Appsuite 2025-04-14 5.3 Medium
OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record.
CVE-2022-37312 1 Open-xchange 1 Open-xchange Appsuite 2025-04-14 5.3 Medium
OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large request body containing a redirect URL to the deferrer servlet.
CVE-2022-37311 1 Open-xchange 1 Open-xchange Appsuite 2025-04-14 5.3 Medium
OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large location request parameter to the redirect servlet.
CVE-2022-37310 1 Open-xchange 1 Open-xchange Appsuite 2025-04-14 6.1 Medium
OX App Suite through 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#!!&app=io.ox/files&cap= URI.
CVE-2022-37309 1 Open-xchange 1 Open-xchange Appsuite 2025-04-14 6.1 Medium
OX App Suite through 7.10.6 allows XSS via script code within a contact that has an e-mail address but lacks a name.
CVE-2022-37308 1 Open-xchange 1 Open-xchange Appsuite 2025-04-14 6.1 Medium
OX App Suite through 7.10.6 allows XSS via HTML in text/plain e-mail messages.
CVE-2022-37307 1 Open-xchange 1 Open-xchange Appsuite 2025-04-14 6.1 Medium
OX App Suite through 7.10.6 allows XSS via XHTML CDATA for a snippet, as demonstrated by the onerror attribute of an IMG element within an e-mail signature.
CVE-2022-36664 1 Adiscon 1 Password Manager For Iis 2025-04-14 6.1 Medium
Password Manager for IIS 2.0 has a cross-site scripting (XSS) vulnerability via the /isapi/PasswordManager.dll ResultURL parameter.
CVE-2022-31469 1 Open-xchange 1 Open-xchange Appsuite 2025-04-14 6.1 Medium
OX App Suite through 7.10.6 allows XSS via a deep link, as demonstrated by class="deep-link-app" for a /#!!&app=%2e./ URI.
CVE-2022-26969 1 Monospace 1 Directus 2025-04-14 9.8 Critical
In Directus before 9.7.0, the default settings of CORS_ORIGIN and CORS_ENABLED are true.
CVE-2024-54925 1 Lopalopa 1 E-learning Management System 2025-04-14 9.8 Critical
A SQL Injection was found in /remove_sent_message.php in kashipara E-learning Management System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the id parameter.
CVE-2024-54918 1 Lopalopa 1 E-learning Management System 2025-04-14 9.8 Critical
Kashipara E-learning Management System v1.0 is vulnerable to Remote Code Execution via File Upload in /teacher_avatar.php.
CVE-2025-27178 3 Adobe, Apple, Microsoft 3 Indesign, Macos, Windows 2025-04-14 7.8 High
InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2025-27179 3 Adobe, Apple, Microsoft 3 Indesign, Macos, Windows 2025-04-14 5.5 Medium
InDesign Desktop versions ID20.1, ID19.5.2 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2025-21170 1 Adobe 1 Substance 3d Modeler 2025-04-14 5.5 Medium
Substance3D - Modeler versions 1.15.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2023-41612 2 Govicture, Victure 3 Pc420, Pc420 Firmware, Pc420 Firmware 2025-04-14 8.8 High
Victure PC420 1.1.39 was discovered to use a weak encryption key for the file enabled_telnet.dat on the Micro SD card.
CVE-2023-41611 1 Govicture 2 Pc420, Pc420 Firmware 2025-04-14 6.5 Medium
Victure PC420 1.1.39 was discovered to use a weak and partially hardcoded key to encrypt data.
CVE-2023-41610 1 Govicture 2 Pc420, Pc420 Firmware 2025-04-14 8.8 High
Victure PC420 1.1.39 was discovered to contain a hardcoded root password which is stored in plaintext.