Search Results (357170 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-4092 1 Gitlab 1 Gitlab 2025-04-01 5.7 Medium
An issue has been discovered in GitLab EE affecting all versions starting from 15.6 before 15.6.1. It was possible to create a malicious README page due to improper neutralisation of user supplied input.
CVE-2022-27508 1 Citrix 2 Application Delivery Controller, Gateway 2025-04-01 7.5 High
Unauthenticated denial of service
CVE-2018-1472 2025-04-01 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it was erroneously associated with an open source vulnerability by another vendor.
CVE-2024-29302 2 Mayurik, Sourcecodester 2 Php Task Management System, Php Task Management System 2025-04-01 7.5 High
SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection via update-employee.php.
CVE-2024-29303 1 Mayurik 1 Php Task Management System 2025-04-01 9.8 Critical
The delete admin users function of SourceCodester PHP Task Management System 1.0 is vulnerable to SQL Injection
CVE-2024-30946 1 Dedecms 1 Dedecms 2025-04-01 5.5 Medium
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/co_do.php.
CVE-2024-30965 1 Dedecms 1 Dedecms 2025-04-01 8.8 High
DedeCMS v5.7 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /src/dede/member_scores.php.
CVE-2024-29661 1 Dedecms 1 Dedecms 2025-04-01 9.8 Critical
A File Upload vulnerability in DedeCMS v5.7 allows a local attacker to execute arbitrary code via a crafted payload.
CVE-2024-29660 1 Dedecms 1 Dedecms 2025-04-01 5.3 Medium
Cross Site Scripting vulnerability in DedeCMS v.5.7 allows a local attacker to execute arbitrary code via a crafted payload to the stepselect_main.php component.
CVE-2024-33749 1 Dedecms 1 Dedecms 2025-04-01 9.1 Critical
DedeCMS V5.7.114 is vulnerable to deletion of any file via mail_file_manage.php.
CVE-2024-34245 1 Dedecms 1 Dedecms 2025-04-01 6.5 Medium
An arbitrary file read vulnerability in DedeCMS v5.7.114 allows authenticated attackers to read arbitrary files by specifying any path in makehtml_js_action.php.
CVE-2024-34959 1 Dedecms 1 Dedecms 2025-04-01 5.5 Medium
DedeCMS V5.7.113 is vulnerable to Cross Site Scripting (XSS) via sys_data_replace.php.
CVE-2024-35375 1 Dedecms 1 Dedecms 2025-04-01 9.8 Critical
There is an arbitrary file upload vulnerability on the media add .php page in the backend of the website in version 5.7.114 of DedeCMS
CVE-2024-35510 1 Dedecms 1 Dedecms 2025-04-01 9.8 Critical
An arbitrary file upload vulnerability in /dede/file_manage_control.php of DedeCMS v5.7.114 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-57241 1 Dedecms 1 Dedecms 2025-04-01 6.5 Medium
Dedecms 5.71sp1 and earlier is vulnerable to URL redirect. In the web application, a logic error does not judge the input GET request resulting in URL redirection.
CVE-2024-4768 3 Debian, Mozilla, Redhat 8 Debian Linux, Firefox, Thunderbird and 5 more 2025-04-01 6.1 Medium
A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.
CVE-2024-4776 1 Mozilla 1 Firefox 2025-04-01 8.2 High
A file dialog shown while in full-screen mode could have resulted in the window remaining disabled. This vulnerability affects Firefox < 126.
CVE-2022-26329 1 Netiq 1 Identity Manager 2025-04-01 1.8 Low
File existence disclosure vulnerability in NetIQ Identity Manager plugin prior to version 4.8.5 allows attacker to determine whether a file exists on the filesystem. This issue affects: Micro Focus NetIQ Identity Manager NetIQ Identity Manager versions prior to 4.8.5 on ALL.
CVE-2024-4775 1 Mozilla 1 Firefox 2025-04-01 5.9 Medium
An iterator stop condition was missing when handling WASM code in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This issue only affects the application when the profiler is running. This vulnerability affects Firefox < 126.
CVE-2024-4771 1 Mozilla 1 Firefox 2025-04-01 8.6 High
A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 126.