Search

Search Results (399618 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2014-2050 1 Owncloud 2 Owncloud, Owncloud Server 2025-03-31 6.5 Medium
Cross-site request forgery (CSRF) vulnerability in ownCloud Server before 5.0.15 and 6.0.x before 6.0.2 allows remote attackers to hijack the authentication of users for requests that reset passwords via a crafted HTTP Host header.
CVE-2023-35789 2 Rabbitmq-c Project, Redhat 2 Rabbitmq-c, Enterprise Linux 2025-03-30 5.5 Medium
An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only be entered on the command line (e.g., for amqp-publish or amqp-consume) and are thus visible to local attackers by listing a process and its arguments.
CVE-2023-23750 1 Joomla 1 Joomla\! 2025-03-29 6.3 Medium
An issue was discovered in Joomla! 4.0.0 through 4.2.6. A missing token check causes a CSRF vulnerability in the handling of post-installation messages.
CVE-2024-21724 1 Joomla 1 Joomla\! 2025-03-29 6.1 Medium
Inadequate input validation for media selection fields lead to XSS vulnerabilities in various extensions.
CVE-2023-23751 1 Joomla 1 Joomla\! 2025-03-29 4.3 Medium
An issue was discovered in Joomla! 4.0.0 through 4.2.4. A missing ACL check allows non super-admin users to access com_actionlogs.
CVE-2025-31374 2025-03-29 N/A
Not used
CVE-2025-31373 2025-03-29 N/A
Not used
CVE-2025-31372 2025-03-29 N/A
Not used
CVE-2025-31371 2025-03-29 N/A
Not used
CVE-2025-31370 2025-03-29 N/A
Not used
CVE-2025-31369 2025-03-29 N/A
Not used
CVE-2025-31368 2025-03-29 N/A
Not used
CVE-2025-31367 2025-03-29 N/A
Not used
CVE-2024-30417 1 Huawei 2 Emui, Harmonyos 2025-03-29 7.5 High
Path traversal vulnerability in the Bluetooth-based sharing module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2024-2631 2 Fedoraproject, Google 2 Fedora, Chrome 2025-03-29 4.3 Medium
Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
CVE-2024-28155 1 Jenkins 1 Appspider 2025-03-29 4.3 Medium
Jenkins AppSpider Plugin 1.0.16 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to obtain information about available scan config names, engine group names, and client names.
CVE-2024-27379 2 Samsung, Samsung Mobile 11 Exynos 1280, Exynos 1280 Firmware, Exynos 1330 and 8 more 2025-03-29 6.7 Medium
An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_nan_subscribe_get_nl_params(), there is no input validation check on hal_req->num_intf_addr_present coming from userspace, which can lead to a heap overwrite.
CVE-2024-25865 1 Anzhiyu-c 1 Hexo-theme-anzhiyu 2025-03-29 6.1 Medium
Cross Site Scripting (XSS) vulnerability in hexo-theme-anzhiyu v1.6.12, allows remote attackers to execute arbitrary code via the algolia search function.
CVE-2024-25435 1 Md1health 1 Md1patient 2025-03-29 6.1 Medium
A cross-site scripting (XSS) vulnerability in Md1health Md1patient v2.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Msg parameter.
CVE-2024-25422 1 Sem-cms 1 Semcms 2025-03-29 9.8 Critical
SQL Injection vulnerability in SEMCMS v.4.8 allows a remote attacker to execute arbitrary code and obtain sensitive information via the SEMCMS_Menu.php component.