Search Results (357345 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-10566 1 10web 1 Slider 2025-04-01 6.1 Medium
The Slider by 10Web WordPress plugin before 1.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2024-13122 1 Advancedformintegration 1 Advanced Form Integration 2025-04-01 3.5 Low
The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2024-13123 1 Advancedformintegration 1 Advanced Form Integration 2025-04-01 3.5 Low
The AFI WordPress plugin before 1.100.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2025-2740 1 Phpgurukul 1 Old Age Home Management System 2025-04-01 7.3 High
A vulnerability classified as critical has been found in PHPGurukul Old Age Home Management System 1.0. Affected is an unknown function of the file /admin/eligibility.php. The manipulation of the argument pagetitle leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-27833 1 Artifex 1 Ghostscript 2025-04-01 7.8 High
An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs for a long TTF font name to pdf/pdf_fmap.c.
CVE-2025-27834 1 Artifex 1 Ghostscript 2025-04-01 7.8 High
An issue was discovered in Artifex Ghostscript before 10.05.0. A buffer overflow occurs via an oversized Type 4 function in a PDF document to pdf/pdf_func.c.
CVE-2025-27837 1 Artifex 1 Ghostscript 2025-04-01 9.8 Critical
An issue was discovered in Artifex Ghostscript before 10.05.0. Access to arbitrary files can occur through a truncated path with invalid UTF-8 characters, for base/gp_mswin.c and base/winrtsup.cpp.
CVE-2025-26001 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2025-04-01 7.5 High
Telesquare TLR-2005KSH 1.1.4 is vulnerable to Information Disclosure via the parameter getUserNamePassword.
CVE-2025-26002 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2025-04-01 9.8 Critical
Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setSyncTimeHost.
CVE-2025-26003 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2025-04-01 9.8 Critical
Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized command execution vulnerability when requesting the admin.cgi parameter with setAutorest.
CVE-2025-26004 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2025-04-01 9.8 Critical
Telesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack buffer overflow vulnerability when requesting admin.cgi parameter with setDdns.
CVE-2024-55963 1 Appsmith 1 Appsmith 2025-04-01 6.5 Medium
An issue was discovered in Appsmith before 1.51. A user on Appsmith that doesn't have admin permissions can trigger the restart API on Appsmith, causing a server restart. This is still within the Appsmith container, and the impact is limited to Appsmith's own server only, but there is a denial of service because it can be continually restarted. This is due to incorrect access control checks, which should check for super user permissions on the incoming request.
CVE-2024-55964 1 Appsmith 1 Appsmith 2025-04-01 9.8 Critical
An issue was discovered in Appsmith before 1.52. An incorrectly configured PostgreSQL instance in the Appsmith image leads to remote command execution inside the Appsmith Docker container. The attacker must be able to access Appsmith, login to it, create a datasource, create a query against that datasource, and execute that query.
CVE-2025-26005 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2025-04-01 9.8 Critical
Telesquare TLR-2005KSH 1.1.4 is vulnerable to unauthorized stack overflow vulnerability when requesting admin.cgi parameter with setNtp.
CVE-2025-26006 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2025-04-01 9.8 Critical
Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability when requesting the admin.cgi parameter with setAutorest.
CVE-2025-26007 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2025-04-01 9.8 Critical
Telesquare TLR-2005KSH 1.1.4 has an unauthorized stack overflow vulnerability in the login interface when requesting systemtil.cgi.
CVE-2025-26008 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2025-04-01 9.8 Critical
In Telesquare TLR-2005KSH 1.1.4, an unauthorized stack overflow vulnerability exists when requesting admin.cgi parameter with setSyncTimeHost.
CVE-2025-26009 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2025-04-01 7.5 High
Telesquare TLR-2005KSH 1.1.4 has an Information Disclosure vulnerability when requesting systemutilit.cgi.
CVE-2025-26010 1 Telesquare 2 Tlr-2005ksh, Tlr-2005ksh Firmware 2025-04-01 9.8 Critical
Telesquare TLR-2005KSH 1.1.4 allows unauthorized password modification when requesting the admin.cgi parameter with setUserNamePassword.
CVE-2024-29944 3 Debian, Mozilla, Redhat 8 Debian Linux, Firefox, Firefox Esr and 5 more 2025-04-01 8.4 High
An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. Note: This vulnerability affects Desktop Firefox only, it does not affect mobile versions of Firefox. This vulnerability affects Firefox < 124.0.1 and Firefox ESR < 115.9.1.