Search Results (359645 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-25795 1 Wp-master 1 Feed Changer \& Remover 2025-01-13 5.9 Medium
Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in WP-master.Ir Feed Changer & Remover plugin <= 0.2 versions.
CVE-2023-25794 1 Nooz Project 1 Nooz 2025-01-13 5.9 Medium
Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Mighty Digital Nooz plugin <= 1.6.0 versions.
CVE-2024-24377 1 Idocv 1 Idocview 2025-01-13 9.8 Critical
An issue in idocv v.14.1.3_20231228 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script.
CVE-2023-51931 1 Alanclarke 1 Urlite 2025-01-13 7.5 High
An issue in alanclarke URLite v.3.1.0 allows an attacker to cause a denial of service (DoS) via a crafted payload to the parsing function.
CVE-2024-25415 1 Phoenixcart 1 Ce Phoenix Cart 2025-01-13 7.2 High
A remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to execute arbitrary PHP code via injecting a crafted payload into the file english.php.
CVE-2024-51728 2025-01-13 N/A
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2024. Notes: none.
CVE-2021-30184 2 Fedoraproject, Gnu 2 Fedora, Chess 2025-01-12 7.8 High
GNU Chess 6.2.7 allows attackers to execute arbitrary code via crafted PGN (Portable Game Notation) data. This is related to a buffer overflow in the use of a .tmp.epd temporary file in the cmd_pgnload and cmd_pgnreplay functions in frontend/cmd.cc.
CVE-2025-23128 2025-01-11 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-23127 2025-01-11 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-23126 2025-01-11 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-23125 2025-01-11 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-23124 2025-01-11 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-34205 1 Moov 1 Signedxml 2025-01-10 9.1 Critical
In Moov signedxml through 1.0.0, parsing the raw XML (as received) can result in different output than parsing the canonicalized XML. Thus, signature validation can be bypassed via a Signature Wrapping attack (aka XSW).
CVE-2023-33656 1 Emqx 1 Nanomq 2025-01-10 5.5 Medium
A memory leak vulnerability exists in NanoMQ 0.17.2. The vulnerability is located in the file message.c. An attacker could exploit this vulnerability to cause a denial of service attack by causing the program to consume all available memory resources.
CVE-2023-33245 1 Minecraft 1 Minecraft 2025-01-10 8.8 High
Minecraft through 1.19 and 1.20 pre-releases before 7 (Java) allow arbitrary file overwrite, and possibly code execution, via crafted world data that contains a symlink.
CVE-2023-2953 4 Apple, Netapp, Openldap and 1 more 18 Macos, Active Iq Unified Manager, Clustered Data Ontap and 15 more 2025-01-10 7.5 High
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
CVE-2022-44517 3 Adobe, Apple, Microsoft 6 Acrobat, Acrobat Dc, Acrobat Reader and 3 more 2025-01-10 5.5 Medium
Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2022-44516 3 Adobe, Apple, Microsoft 6 Acrobat, Acrobat Dc, Acrobat Reader and 3 more 2025-01-10 5.5 Medium
Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2022-34159 1 Huawei 2 Cv81-wdm, Cv81-wdm Firmware 2025-01-10 7.5 High
Huawei printers have an input verification vulnerability. Successful exploitation of this vulnerability may cause device service exceptions. (Vulnerability ID: HWPSIRT-2022-80078) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2022-34159.
CVE-2022-44515 3 Adobe, Apple, Microsoft 6 Acrobat, Acrobat Dc, Acrobat Reader and 3 more 2025-01-10 5.5 Medium
Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.