Search

Search Results (401322 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-20248 1 Cisco 1 Telepresence Management Suite 2025-04-04 5.4 Medium
A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient input validation by the web-based management interface. An attacker could exploit this vulnerability by inserting malicious data in a specific data field in the interface. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
CVE-2024-9900 1 Mudler 1 Localai 2025-04-04 6.1 Medium
mudler/localai version v2.21.1 contains a Cross-Site Scripting (XSS) vulnerability in its search functionality. The vulnerability arises due to improper sanitization of user input, allowing the injection and execution of arbitrary JavaScript code. This can lead to the execution of malicious scripts in the context of the victim's browser, potentially compromising user sessions, stealing session cookies, redirecting users to malicious websites, or manipulating the DOM.
CVE-2024-8998 1 Lunary 1 Lunary 2025-04-04 7.5 High
A Regular Expression Denial of Service (ReDoS) vulnerability exists in lunary-ai/lunary version git f07a845. The server uses the regex /{.*?}/ to match user-controlled strings. In the default JavaScript regex engine, this regex can take polynomial time to match certain crafted user inputs. As a result, an attacker can cause the server to hang for an arbitrary amount of time by submitting a specially crafted payload. This issue is fixed in version 1.4.26.
CVE-2024-8736 1 Lollms 1 Lollms Web Ui 2025-04-04 6.5 Medium
A Denial of Service (DoS) vulnerability exists in multiple file upload endpoints of parisneo/lollms-webui version V12 (Strawberry). The vulnerability can be exploited remotely via Cross-Site Request Forgery (CSRF). Despite CSRF protection preventing file uploads, the application still processes multipart boundaries, leading to resource exhaustion. By appending additional characters to the multipart boundary, an attacker can cause the server to parse each byte of the boundary, ultimately leading to service unavailability. This vulnerability is present in the `/upload_avatar`, `/upload_app`, and `/upload_logo` endpoints.
CVE-2024-12450 1 Infiniflow 1 Ragflow 2025-04-04 9.8 Critical
In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `document_app.py` contains multiple vulnerabilities. The function does not filter URL parameters, allowing attackers to exploit Full Read SSRF by accessing internal network addresses and viewing their content through the generated PDF files. Additionally, the lack of restrictions on the file protocol enables Arbitrary File Read, allowing attackers to read server files. Furthermore, the use of an outdated Chromium headless version with --no-sandbox mode enabled makes the application susceptible to Remote Code Execution (RCE) via known Chromium v8 vulnerabilities. These issues are resolved in version 0.14.0.
CVE-2023-23749 1 Miniorange 1 Ldap Integration With Active Directory And Openldap 2025-04-04 7.5 High
The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly sanitizing the 'username' POST parameter. An attacker can manipulate this paramter to dump arbitrary contents form the LDAP Database.
CVE-2025-2972 2025-04-04 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-2970 2025-04-04 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-2969 2025-04-04 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-2968 2025-04-04 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-2967 2025-04-04 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-2966 2025-04-04 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-2965 2025-04-04 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-2964 2025-04-04 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-2963 2025-04-03 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-20908 1 Google 1 Android 2025-04-03 5.5 Medium
In several functions of SettingsState.java, there is a possible system crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-239415861
CVE-2023-20905 1 Google 1 Android 2025-04-03 7.8 High
In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-241387741
CVE-2023-20904 1 Google 1 Android 2025-04-03 7.8 High
In getTrampolineIntent of SettingsActivity.java, there is a possible launch of arbitrary activity due to an Intent mismatch in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-246300272
CVE-2022-48126 1 Totolink 2 A7100ru, A7100ru Firmware 2025-04-03 9.8 Critical
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the username parameter in the setting/setOpenVpnCertGenerationCfg function.
CVE-2022-20494 1 Google 1 Android 2025-04-03 5.5 Medium
In AutomaticZenRule of AutomaticZenRule.java, there is a possible persistent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-243794204