Search Results (381211 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-2994 1 Tenda 2 Fh1202, Fh1202 Firmware 2025-04-07 5.3 Medium
A vulnerability, which was classified as critical, was found in Tenda FH1202 1.2.0.14(408). This affects an unknown part of the file /goform/qossetting of the component Web Management Interface. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-3018 1 Oretnom23 1 Online Eyewear Shop 2025-04-07 6.3 Medium
A vulnerability, which was classified as critical, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /classes/Users.php?f=delete. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-32326 1 Totolink 2 Ex200, Ex200 Firmware 2025-04-07 6.8 Medium
TOTOLINK EX200 V4.0.3c.7646_B20201211 contains a Cross-site scripting (XSS) vulnerability through the key parameter in the setWiFiExtenderConfig function.
CVE-2024-26495 1 Friendica 1 Friendica 2025-04-07 6.1 Medium
Cross Site Scripting (XSS) vulnerability in Friendica versions after v.2023.12, allows a remote attacker to execute arbitrary code and obtain sensitive information via the BBCode tags in the post content and post comments function.
CVE-2025-25579 1 Totolink 2 A3002r, A3002r Firmware 2025-04-07 9.8 Critical
TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr.
CVE-2025-28087 1 Nayem-howlader 1 Online Exam System 2025-04-07 9.8 Critical
Sourcecodester Online Exam System 1.0 is vulnerable to SQL Injection via dash.php.
CVE-2025-28089 1 Maccms 1 Maccms 2025-04-07 9.1 Critical
maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.
CVE-2025-28090 1 Maccms 1 Maccms 2025-04-07 9.1 Critical
maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.
CVE-2025-28091 1 Maccms 1 Maccms 2025-04-07 9.1 Critical
maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.
CVE-2023-29839 1 Digitaldruid 1 Hoteldruid 2025-04-07 5.4 Medium
A Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows arbitrary execution of commands. The vulnerable fields are Surname, Name, and Nickname in the Document function.
CVE-2025-2989 1 Tenda 2 Fh1202, Fh1202 Firmware 2025-04-07 5.3 Medium
A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been declared as critical. This vulnerability affects unknown code of the file /goform/AdvSetWrl of the component Web Management Interface. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-2991 1 Tenda 2 Fh1202, Fh1202 Firmware 2025-04-07 5.3 Medium
A vulnerability classified as critical has been found in Tenda FH1202 1.2.0.14(408). Affected is an unknown function of the file /goform/AdvSetWrlmacfilter of the component Web Management Interface. The manipulation leads to improper access controls. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-2990 1 Tenda 2 Fh1202, Fh1202 Firmware 2025-04-07 5.3 Medium
A vulnerability was found in Tenda FH1202 1.2.0.14(408). It has been rated as critical. This issue affects some unknown processing of the file /goform/AdvSetWrlGstset of the component Web Management Interface. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-28092 1 Shopxo 1 Shopxo 2025-04-07 6.3 Medium
ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function.
CVE-2025-28093 1 Shopxo 1 Shopxo 2025-04-07 6.3 Medium
ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) in Email Settings.
CVE-2025-28094 1 Shopxo 1 Shopxo 2025-04-07 6.5 Medium
shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places.
CVE-2025-25749 1 Digitaldruid 1 Hoteldruid 2025-04-07 7.1 High
An issue in HotelDruid version 3.0.7 and earlier allows users to set weak passwords due to the lack of enforcement of password strength policies.
CVE-2025-28096 1 Onenav 1 Onenav 2025-04-07 5.4 Medium
OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers.
CVE-2025-28097 1 Onenav 1 Onenav 2025-04-07 5.5 Medium
OneNav 1.1.0 is vulnerable to Cross Site Scripting (XSS) in custom headers.
CVE-2025-3070 1 Google 1 Chrome 2025-04-07 6.5 Medium
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 135.0.7049.52 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)