Search Results (357649 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-42423 1 Pdf-xchange 1 Pdf-xchange Editor 2025-03-31 7.8 High
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of TIF files. Crafted data in a TIF file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18716.
CVE-2024-48278 1 Phpgurukul 2 User Registration \& Login And User Management System, User Registration And Login And User Management System 2025-03-31 5.5 Medium
Phpgurukul User Registration & Login and User Management System 3.2 is vulnerable to Cross Site Request Forgery (CSRF) via /edit-profile.php.
CVE-2024-48279 1 Phpgurukul 2 User Registration \& Login And User Management System, User Registration And Login And User Management System 2025-03-31 7.6 High
A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary HTML code via the searchkey parameter in a POST HTTP request.
CVE-2024-48280 1 Phpgurukul 2 User Registration \& Login And User Management System, User Registration And Login And User Management System 2025-03-31 7.6 High
A SQL Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL command via the fromdate parameter in a POST HTTP request.
CVE-2022-47951 3 Debian, Openstack, Redhat 5 Debian Linux, Cinder, Glance and 2 more 2025-03-31 5.7 Medium
An issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.0.0; and Nova before 24.1.2, 25.x before 25.0.2, and 26.0.0. By supplying a specially created VMDK flat image that references a specific backing file path, an authenticated user may convince systems to return a copy of that file's contents from the server, resulting in unauthorized access to potentially sensitive data.
CVE-2022-46967 1 Revenue Collection System Project 1 Revenue Collection System 2025-03-31 9.8 Critical
An access control issue in Revenue Collection System v1.0 allows unauthenticated attackers to view the contents of /admin/DBbackup/ directory.
CVE-2024-48282 1 Phpgurukul 2 User Registration \& Login And User Management System, User Registration And Login And User Management System 2025-03-31 7.6 High
A SQL Injection vulnerability was found in /password-recovery.php of PHPGurukul User Registration & Login and User Management System 3.2, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the femail parameter in a POST HTTP request.
CVE-2024-3855 1 Mozilla 1 Firefox 2025-03-31 6.5 Medium
In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability affects Firefox < 125.
CVE-2024-3856 1 Mozilla 1 Firefox 2025-03-31 8.8 High
A use-after-free could occur during WASM execution if garbage collection ran during the creation of an array. This vulnerability affects Firefox < 125.
CVE-2023-0455 1 Bumsys Project 1 Bumsys 2025-03-31 8.8 High
Unrestricted Upload of File with Dangerous Type in GitHub repository unilogies/bumsys prior to v1.0.3-beta.
CVE-2024-3858 1 Mozilla 1 Firefox 2025-03-31 7.5 High
It was possible to mutate a JavaScript object so that the JIT could crash while tracing it. This vulnerability affects Firefox < 125.
CVE-2023-0470 1 Modoboa 1 Modoboa 2025-03-31 5.4 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository modoboa/modoboa prior to 2.0.4.
CVE-2023-0488 2 Pyload, Pyload-ng Project 2 Pyload, Pyload-ng 2025-03-31 5.4 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository pyload/pyload prior to 0.5.0b3.dev42.
CVE-2024-3860 1 Mozilla 1 Firefox 2025-03-31 6.2 Medium
An out-of-memory condition during object initialization could result in an empty shape list. If the JIT subsequently traced the object it would crash. This vulnerability affects Firefox < 125.
CVE-2023-0493 1 Btcpayserver 1 Btcpay Server 2025-03-31 5.3 Medium
Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5.
CVE-2024-3862 1 Mozilla 1 Firefox 2025-03-31 5.3 Medium
The MarkStack assignment operator, part of the JavaScript engine, could access uninitialized memory if it were used in a self-assignment. This vulnerability affects Firefox < 125.
CVE-2023-0509 2 Pyload, Pyload-ng Project 2 Pyload, Pyload-ng 2025-03-31 7.4 High
Improper Certificate Validation in GitHub repository pyload/pyload prior to 0.5.0b3.dev44.
CVE-2023-0512 1 Vim 1 Vim 2025-03-31 7.8 High
Divide By Zero in GitHub repository vim/vim prior to 9.0.1247.
CVE-2024-3853 1 Mozilla 1 Firefox 2025-03-31 7.5 High
A use-after-free could result if a JavaScript realm was in the process of being initialized when a garbage collection started. This vulnerability affects Firefox < 125.
CVE-2024-28557 1 Mayurik 1 Php Task Management System 2025-03-31 9.8 Critical
SQL Injection vulnerability in Sourcecodester php task management system v1.0, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via crafted payload to update-admin.php.