Search Results (348174 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-1025 1 Simplefilelist 1 Simple File List 2025-02-26 4.8 Medium
The Simple File List WordPress plugin before 6.0.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2022-4009 1 Octopus 1 Octopus Server 2025-02-26 8.8 High
In affected versions of Octopus Deploy it is possible for a user to introduce code via offline package creation
CVE-2021-31637 1 Uwamp Project 1 Uwamp 2025-02-26 7.8 High
An issue found in UwAmp v.1.1, 1.2, 1.3, 2.0, 2.1, 2.2, 2.2.1, 3.0.0, 3.0.1, 3.0.2 allows a remote attacker to execute arbitrary code via a crafted DLL.
CVE-2020-22647 1 Smartconrtactgames Project 1 Smartconrtactgames 2025-02-26 9.1 Critical
An issue found in DepositGame v.1.0 allows an attacker to gain sensitive information via the GetBonusWithdraw and withdraw functions.
CVE-2023-21452 1 Samsung 1 Android 2025-02-26 3.3 Low
Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected device.
CVE-2023-21453 1 Samsung 1 Android 2025-02-26 6 Medium
Improper input validation vulnerability in SoftSim TA prior to SMR Mar-2023 Release 1 allows local attackers access to protected data.
CVE-2023-21454 1 Samsung 1 Android 2025-02-26 2.4 Low
Improper authorization in Samsung Keyboard prior to SMR Mar-2023 Release 1 allows physical attacker to access users text history on the lockscreen.
CVE-2023-21455 1 Samsung 2 Exynos, Exynos Firmware 2025-02-26 5.9 Medium
Improper authorization implementation in Exynos baseband prior to SMR Mar-2023 Release 1 allows incorrect handling of unencrypted message.
CVE-2024-34791 1 Wpbean 1 Wpb Elementor Addons 2025-02-26 6.5 Medium
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in wpbean WPB Elementor Addons allows Stored XSS.This issue affects WPB Elementor Addons: from n/a through 1.0.9.
CVE-2024-22244 1 Linuxfoundation 1 Harbor 2025-02-26 4.3 Medium
Open Redirect in HarborĀ  <=v2.8.4, <=v2.9.2, and <=v2.10.0 may redirect a user to a malicious site.
CVE-2024-33557 1 8theme 1 Xstore Core 2025-02-26 8.5 High
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in 8theme XStore Core allows PHP Local File Inclusion.This issue affects XStore Core: from n/a through 5.3.8.
CVE-2024-32818 1 Pluginus 1 Wordpress Meta Data And Taxonomies Filter 2025-02-26 4.3 Medium
Missing Authorization vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF).This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.
CVE-2023-21456 1 Samsung 1 Android 2025-02-26 9 Critical
Path traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uid.
CVE-2023-21458 1 Samsung 1 Android 2025-02-26 6.2 Medium
Improper privilege management vulnerability in PhoneStatusBarPolicy in System UI prior to SMR Mar-2023 Release 1 allows attacker to turn off Do not disturb via unprotected intent.
CVE-2020-4927 1 Ibm 1 Spectrum Scale 2025-02-26 5.7 Medium
A vulnerability in the Spectrum Scale 5.0.5.0 through 5.1.6.1 core component could allow unauthorized access to user data or injection of arbitrary data in the communication protocol. IBM X-Force ID: 191695.
CVE-2022-46774 1 Ibm 2 Manage Application, Maximo Application Suite 2025-02-26 5.4 Medium
IBM Manage Application 8.8.0 and 8.9.0 in the IBM Maximo Application Suite is vulnerable to incorrect default permissions which could give access to a user to actions that they should not have access to. IBM X-Force ID: 242953.
CVE-2023-22876 1 Ibm 1 Sterling B2b Integrator 2025-02-26 4.3 Medium
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.7 and 6.1.0.0 through 6.1.2.1 could allow a privileged user to obtain sensitive information that could aid in further attacks against the system. IBM X-Force ID: 244364.
CVE-2020-4556 1 Ibm 1 Financial Transaction Manager 2025-02-26 4 Medium
IBM Financial Transaction Manager for High Value Payments for Multi-Platform 3.2.0 through 3.2.10 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 183329.
CVE-2023-25680 1 Ibm 3 Robotic Process Automation, Robotic Process Automation As A Service, Robotic Process Automation For Cloud Pak 2025-02-26 4.2 Medium
IBM Robotic Process Automation 21.0.1 through 21.0.5 is vulnerable to insufficiently protecting credentials. Queue Provider credentials are not obfuscated while editing queue provider details. IBM X-Force ID: 247032.
CVE-2023-27059 1 Churchcrm 1 Churchcrm 2025-02-26 7.8 High
A cross-site scripting (XSS) vulnerability in the Edit Group function of ChurchCRM v4.5.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Edit Group Name text field.