Search Results (381063 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-25860 1 Simple-git Project 1 Simple-git 2025-04-01 8.1 High
Versions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemote() methods, due to improper input sanitization. This vulnerability exists due to an incomplete fix of [CVE-2022-25912](https://security.snyk.io/vuln/SNYK-JS-SIMPLEGIT-3112221).
CVE-2022-25350 1 Helecloud 1 Puppet-facter 2025-04-01 7.4 High
All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization.
CVE-2024-28353 1 Trendnet 2 Tew-827dru, Tew-827dru Firmware 2025-04-01 8.8 High
There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.config.smb_admin_name in the apply.cgi interface, thereby gaining root shell privileges.
CVE-2024-28354 1 Trendnet 2 Tew-827dru, Tew-827dru Firmware 2025-04-01 10.0 Critical
There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.@smb[%d].username in the apply.cgi interface, thereby gaining root shell privileges.
CVE-2025-29483 1 Libming 1 Libming 2025-04-01 6.5 Medium
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_ENABLEDEBUGGER2 function.
CVE-2025-29484 1 Libming 1 Libming 2025-04-01 7.5 High
An out-of-memory error in the parseABC_NS_SET_INFO function of libming v0.4.8 allows attackers to cause a Denial of Service (DoS) due to allocator exhaustion.
CVE-2025-29485 1 Libming 1 Libming 2025-04-01 6.5 Medium
libming v0.4.8 was discovered to contain a segmentation fault via the decompileRETURN function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.
CVE-2025-29486 1 Libming 1 Libming 2025-04-01 6.5 Medium
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_PLACEOBJECT3 function.
CVE-2024-26337 1 Swftools 1 Swftools 2025-04-01 4.3 Medium
swftools v0.9.2 was discovered to contain a segmentation violation via the function s_font at swftools/src/swfc.c.
CVE-2024-26339 2 Swftools, Swftools Project 2 Swftools, Swftools 2025-04-01 9.1 Critical
swftools v0.9.2 was discovered to contain a strcpy parameter overlap via /home/swftools/src/swfc+0x48318a.
CVE-2025-29488 1 Libming 1 Libming 2025-04-01 6.5 Medium
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_INITACTION function.
CVE-2025-29489 1 Libming 1 Libming 2025-04-01 6.5 Medium
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHLINESTYLES function.
CVE-2025-29490 1 Libming 1 Libming 2025-04-01 6.5 Medium
libming v0.4.8 was discovered to contain a segmentation fault via the decompileCALLMETHOD function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.
CVE-2025-29491 1 Libming 1 Libming 2025-04-01 6.5 Medium
An allocation-size-too-big error in the parseSWF_DEFINEBINARYDATA function of libming v0.48 allows attackers to cause a Denial of Service (DoS) via supplying a crafted SWF file.
CVE-2025-29492 1 Libming 1 Libming 2025-04-01 6.5 Medium
libming v0.4.8 was discovered to contain a segmentation fault via the decompileSETVARIABLE function.
CVE-2025-29493 1 Libming 1 Libming 2025-04-01 6.5 Medium
libming v0.4.8 was discovered to contain a segmentation fault via the decompileGETPROPERTY function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.
CVE-2025-29496 1 Libming 1 Libming 2025-04-01 6.5 Medium
libming v0.4.8 was discovered to contain a segmentation fault via the decompileDUPLICATECLIP function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.
CVE-2025-29494 1 Libming 1 Libming 2025-04-01 6.5 Medium
libming v0.4.8 was discovered to contain a segmentation fault via the decompileGETMEMBER function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted SWF file.
CVE-2025-29497 1 Libming 1 Libming 2025-04-01 6.5 Medium
libming v0.4.8 was discovered to contain a memory leak via the parseSWF_MORPHFILLSTYLES function.
CVE-2024-1487 1 Contest-gallery 1 Contest Gallery 2025-04-01 5.4 Medium
The Photos and Files Contest Gallery WordPress plugin before 21.3.1 does not sanitize and escape some parameters, which could allow users with a role as low as author to perform Cross-Site Scripting attacks.