Search Results (377230 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-3145 1 Okta 1 Oidc Middleware 2025-04-08 4.7 Medium
An open redirect vulnerability exists in Okta OIDC Middleware prior to version 5.0.0 allowing an attacker to redirect a user to an arbitrary URL.
CVE-2022-39186 1 Exfo 2 Bv-10, Bv-10 Firmware 2025-04-08 6.2 Medium
EXFO - BV-10 Performance Endpoint Unit misconfiguration. System configuration file has misconfigured permissions
CVE-2022-39185 1 Exfo 2 Bv-10, Bv-10 Firmware 2025-04-08 9.8 Critical
EXFO - BV-10 Performance Endpoint Unit Undocumented privileged user. Unit has an undocumented hard-coded privileged user.
CVE-2022-39184 1 Exfo 2 Bv-10, Bv-10 Firmware 2025-04-08 9.8 Critical
EXFO - BV-10 Performance Endpoint Unit authentication bypass User can manually manipulate access enabling authentication bypass.
CVE-2022-39182 1 Mingham-smith 1 Tardis 2000 2025-04-08 4.9 Medium
H C Mingham-Smith Ltd - Tardis 2000 Privilege escalation.Version 1.6 is vulnerable to privilege escalation which may allow a malicious actor to gain system privileges.
CVE-2023-24937 1 Microsoft 11 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 8 more 2025-04-08 6.5 Medium
Windows CryptoAPI Denial of Service Vulnerability
CVE-2024-26481 1 Getkirby 1 Kirby 2025-04-08 4.7 Medium
Kirby CMS v4.1.0 was discovered to contain a reflected self-XSS vulnerability via the URL parameter.
CVE-2023-24938 1 Microsoft 11 Windows 10 1809, Windows 10 21h2, Windows 10 21h2 and 8 more 2025-04-08 6.5 Medium
Windows CryptoAPI Denial of Service Vulnerability
CVE-2023-29346 1 Microsoft 19 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 16 more 2025-04-08 7.8 High
NTFS Elevation of Privilege Vulnerability
CVE-2022-46371 1 Alotceriot 2 Ar7088h-a, Ar7088h-a Firmware 2025-04-08 5.3 Medium
Alotcer - AR7088H-A firmware version 16.10.3 Information disclosure. Unspecified error message contains the default administrator user name.
CVE-2023-29351 1 Microsoft 19 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 16 more 2025-04-08 8.1 High
Windows Group Policy Elevation of Privilege Vulnerability
CVE-2023-29358 1 Microsoft 19 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 16 more 2025-04-08 7.8 High
Windows GDI Elevation of Privilege Vulnerability
CVE-2023-29359 1 Microsoft 19 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 16 more 2025-04-08 7.8 High
GDI Elevation of Privilege Vulnerability
CVE-2022-39183 1 Moodle 1 Saml Authentication 2025-04-08 6.5 Medium
Moodle Plugin - SAML Auth may allow Open Redirect through unspecified vectors.
CVE-2023-29361 1 Microsoft 9 Windows 10 21h2, Windows 10 21h2, Windows 10 22h2 and 6 more 2025-04-08 7 High
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
CVE-2023-29363 1 Microsoft 19 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 16 more 2025-04-08 9.8 Critical
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
CVE-2025-2993 1 Tenda 2 Fh1202, Fh1202 Firmware 2025-04-08 5.3 Medium
A vulnerability, which was classified as critical, has been found in Tenda FH1202 1.2.0.14(408). Affected by this issue is some unknown functionality of the file /default.cfg. The manipulation of the argument these leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2022-34335 2 Ibm, Linux 2 Sterling Partner Engagement Manager, Linux Kernel 2025-04-08 6.5 Medium
IBM Sterling Partner Engagement Manager 6.1.2, 6.2.0, and 6.2.1 could allow an authenticated user to exhaust server resources which could lead to a denial of service. IBM X-Force ID: 229705.
CVE-2025-3167 1 Tenda 2 Ac23, Ac23 Firmware 2025-04-08 6.5 Medium
A vulnerability, which was classified as problematic, has been found in Tenda AC23 16.03.07.52. This issue affects some unknown processing of the file /goform/VerAPIMant of the component API Interface. The manipulation of the argument getuid leads to denial of service. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2022-40615 2 Ibm, Linux 2 Sterling Partner Engagement Manager, Linux Kernel 2025-04-08 6.3 Medium
IBM Sterling Partner Engagement Manager 6.1, 6.2, and 6.2.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 236208.