Search Results (359813 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-4200 1 Progress 1 Telerik Reporting 2025-01-16 7.7 High
In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.2.514), a code execution attack is possible by a local threat actor through an insecure deserialization vulnerability.
CVE-2024-2291 1 Progress 1 Moveit Transfer 2025-01-16 4.3 Medium
In Progress MOVEit Transfer versions released before 2022.0.11 (14.0.11), 2022.1.12 (14.1.12), 2023.0.9 (15.0.9), 2023.1.4 (15.1.4), a logging bypass vulnerability has been discovered.  An authenticated user could manipulate a request to bypass the logging mechanism within the web application which results in user activity not being logged properly.
CVE-2024-23052 2 5kcrm, Wukongopensource 2 Wukongcrm, Wukongcrm 2025-01-16 9.8 Critical
An issue in WuKongOpenSource WukongCRM v.72crm_9.0.1_20191202 allows a remote attacker to execute arbitrary code via the parseObject() function in the fastjson component.
CVE-2024-22939 1 Sunkaifei 1 Flycms 2025-01-16 8.8 High
Cross Site Request Forgery vulnerability in FlyCms v.1.0 allows a remote attacker to execute arbitrary code via the system/article/category_edit component.
CVE-2024-23302 1 Couchbase 1 Couchbase Server 2025-01-16 7.5 High
Couchbase Server before 7.2.4 has a private key leak in goxdcr.log.
CVE-2024-24155 1 Axiosys 1 Bento4 2025-01-16 6.5 Medium
Bento4 v1.5.1-628 contains a Memory leak on AP4_Movie::AP4_Movie, parsing tracks and added into m_Tracks list, but mp42aac cannot correctly delete when we got an no audio track found error. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted mp4 file.
CVE-2024-25831 1 F-logic 1 Datacube3 2025-01-16 5.4 Medium
F-logic DataCube3 Version 1.0 is affected by a reflected cross-site scripting (XSS) vulnerability due to improper input sanitization. An authenticated, remote attacker can execute arbitrary JavaScript code in the web management interface.
CVE-2024-25833 1 F-logic 1 Datacube3 2025-01-16 9.8 Critical
F-logic DataCube3 v1.0 is vulnerable to unauthenticated SQL injection, which could allow an unauthenticated malicious actor to execute arbitrary SQL queries in database.
CVE-2024-1977 1 Josephlopreste 1 Restaurant Solutions - Checklist 2025-01-16 4.4 Medium
The Restaurant Solutions – Checklist plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Checklist points in version 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
CVE-2024-4202 1 Progress 1 Telerik Reporting 2025-01-16 7.7 High
In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.514), a code execution attack is possible through an insecure instantiation vulnerability.
CVE-2023-4319 2025-01-16 N/A
This CVE ID is a reservation duplicate of CVE-2023-4677. Notes: All CVE users should reference CVE-2023-4677 instead of this CVE ID.
CVE-2023-31225 1 Huawei 1 Emui 2025-01-16 3.3 Low
The Gallery app has the risk of hijacking attacks. Successful exploitation of this vulnerability may cause download failures and affect product availability.
CVE-2023-30145 1 Tuzitio 1 Camaleon Cms 2025-01-16 9.8 Critical
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter.
CVE-2021-46886 1 Huawei 1 Emui 2025-01-16 7.5 High
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.
CVE-2021-46885 1 Huawei 1 Emui 2025-01-16 7.5 High
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.
CVE-2021-46884 1 Huawei 1 Emui 2025-01-16 7.5 High
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.
CVE-2021-46883 1 Huawei 1 Emui 2025-01-16 7.5 High
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.
CVE-2021-46882 1 Huawei 1 Emui 2025-01-16 7.5 High
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.
CVE-2021-46881 1 Huawei 1 Emui 2025-01-16 7.5 High
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.
CVE-2024-1800 1 Progress 1 Telerik Report Server 2025-01-16 9.9 Critical
In Progress® Telerik® Report Server versions prior to 2024 Q1 (10.0.24.130), a remote code execution attack is possible through an insecure deserialization vulnerability.