Search Results (346933 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-4815 1 Hitachi 2 Vantara Pentaho, Vantara Pentaho Business Analytics Server 2025-01-16 8 High
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constraining the parser to approved classes and methods. 
CVE-2023-33355 1 Thecosy 1 Icecms 2025-01-16 7.5 High
IceCMS v1.0.0 has Insecure Permissions. There is unauthorized access to the API, resulting in the disclosure of sensitive information.
CVE-2023-33280 1 Storecommander 1 Quickaccounting 2025-01-16 9.8 Critical
In the Store Commander scquickaccounting module for PrestaShop through 3.7.3, multiple sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.
CVE-2023-33279 1 Scfixmyprestashop Project 1 Scfixmyprestashop 2025-01-16 9.8 Critical
In the Store Commander scfixmyprestashop module through 2023-05-09 for PrestaShop, sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.
CVE-2023-33278 1 Storecommander 1 Customers Export 2025-01-16 9.8 Critical
In the Store Commander scexportcustomers module for PrestaShop through 3.6.1, sensitive SQL calls can be executed with a trivial HTTP request and exploited to forge a blind SQL injection.
CVE-2023-33263 1 Wftpd Project 1 Wftpd 2025-01-16 7.5 High
In WFTPD 3.25, usernames and password hashes are stored in an openly viewable wftpd.ini configuration file within the WFTPD directory. NOTE: this is a product from 2006.
CVE-2023-31861 1 Zlmediakit 1 Zlmediakit 2025-01-16 7.5 High
ZLMediaKit 4.0 is vulnerable to Directory Traversal.
CVE-2023-20883 2 Redhat, Vmware 5 Camel Spring Boot, Jboss Enterprise Bpms Platform, Jboss Fuse and 2 more 2025-01-16 7.5 High
In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there is potential for a denial-of-service (DoS) attack if Spring MVC is used together with a reverse proxy cache.
CVE-2023-20882 1 Cloudfoundry 2 Cf-deployment, Routing Release 2025-01-16 5.9 Medium
In Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can lead to a denial of service of applications hosted on Cloud Foundry. Under the right circumstances, when client connections are closed prematurely, gorouter marks the currently selected backend as failed and removes it from the routing pool.
CVE-2022-2041 1 Brizy 1 Brizy 2025-01-16 5.4 Medium
The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element content, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks
CVE-2023-51396 1 Brizy 1 Brizy 2025-01-16 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brizy.Io Brizy – Page Builder allows Stored XSS.This issue affects Brizy – Page Builder: from n/a through 2.4.29.
CVE-2022-2040 1 Brizy 1 Brizy 2025-01-16 5.4 Medium
The Brizy WordPress plugin before 2.4.2 does not sanitise and escape some element URL, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks
CVE-2024-3650 1 Wpmet 1 Elements Kit Elementor Addons 2025-01-16 6.4 Medium
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Image Accordion widget in all versions 3.0.7 through 3.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2024-21541 2 Dom-iterator, Matthewmueller 2 Dom-iterator, Dom-iterator 2025-01-16 7.3 High
Versions of the package dom-iterator before 1.0.1 are vulnerable to Arbitrary Code Execution due to use of the Function constructor without complete input sanitization. Function generates a new function body and thus care must be given to ensure that the inputs to Function are not attacker-controlled. The risks involved are similar to that of allowing attacker-controlled input to reach eval.
CVE-2024-10401 2025-01-16 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2022-21384 2025-01-16 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is a duplicate of CVE-2021-39275.
CVE-2021-35685 2025-01-16 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is a duplicate of CVE-2022-21371
CVE-2021-35684 2025-01-16 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is a duplicate of CVE-2022-21306.
CVE-2024-37966 1 Microsoft 4 Sql Server, Sql Server 2017, Sql Server 2019 and 1 more 2025-01-15 7.1 High
Microsoft SQL Server Native Scoring Information Disclosure Vulnerability
CVE-2023-31226 1 Huawei 1 Emui 2025-01-15 7.5 High
The SDK for the MediaPlaybackController module has improper permission verification. Successful exploitation of this vulnerability may affect confidentiality.