Search Results (312043 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-37871 2 Emiloi, Itsourcecode 2 Online Discussion Forum, Online Discussion Forum 2025-05-14 8.2 High
SQL injection vulnerability in login.php in Itsourcecode Online Discussion Forum Project in PHP with Source Code 1.0 allows remote attackers to execute arbitrary SQL commands via the email parameter.
CVE-2024-10815 1 Reneade 1 Postlists 2025-05-14 4.2 Medium
The PostLists WordPress plugin through 2.0.2 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
CVE-2022-41602 1 Huawei 2 Emui, Harmonyos 2025-05-14 3.4 Low
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
CVE-2024-37872 2 Angeljudesuarez, Itsourcecode 2 Billing System, Billing System 2025-05-14 8.1 High
SQL injection vulnerability in process.php in Itsourcecode Billing System in PHP 1.0 allows remote attackers to execute arbitrary SQL commands via the username parameter.
CVE-2024-12096 1 Ulfben 1 Exhibit To Wp Gallery 2025-05-14 6.1 Medium
The Exhibit to WP Gallery WordPress plugin through 0.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
CVE-2022-42488 1 Openharmony 1 Openharmony 2025-05-14 8.4 High
OpenHarmony-v3.1.2 and prior versions have a Missing permission validation vulnerability in param service of startup subsystem. An malicious application installed on the device could elevate its privileges to the root user, disable security features, or cause DoS by disabling particular services.
CVE-2022-41686 2 Openatom, Openharmony 2 Openharmony, Openharmony 2025-05-14 5.1 Medium
OpenHarmony-v3.1.2 and prior versions, 3.0.6 and prior versions have an Out-of-bound memory read and write vulnerability in /dev/mmz_userdev device driver. The impact depends on the privileges of the attacker. The unprivileged process run on the device could read out-of-bound memory leading sensitive to information disclosure. The processes with system user UID run on the device would be able to write out-of-bound memory which could lead to unspecified memory corruption.
CVE-2024-6235 1 Citrix 1 Netscaler Console 2025-05-14 8.8 High
Sensitive information disclosure in NetScaler Console
CVE-2022-42969 1 Pytest 1 Py 2025-05-14 5.3 Medium
The py library through 1.11.0 for Python allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data, because the InfoSvnCommand argument is mishandled. Note: This has been disputed by multiple third parties as not being reproduceable and they argue this is not a valid vulnerability.
CVE-2022-42968 1 Gitea 1 Gitea 2025-05-14 9.8 Critical
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.
CVE-2022-42961 1 Wolfssl 1 Wolfssl 2025-05-14 5.3 Medium
An issue was discovered in wolfSSL before 5.5.0. A fault injection attack on RAM via Rowhammer leads to ECDSA key disclosure. Users performing signing operations with private ECC keys, such as in server-side TLS connections, might leak faulty ECC signatures. These signatures can be processed via an advanced technique for ECDSA key recovery. (In 5.5.0 and later, WOLFSSL_CHECK_SIG_FAULTS can be used to address the vulnerability.)
CVE-2022-42234 1 Ucms Project 1 Ucms 2025-05-14 8.8 High
There is a file inclusion vulnerability in the template management module in UCMS 1.6
CVE-2022-42071 1 Oretnom23 1 Online Birth Certificate Management System 2025-05-14 6.1 Medium
Online Birth Certificate Management System version 1.0 suffers from a Cross Site Scripting (XSS) Vulnerability.
CVE-2022-41601 1 Huawei 2 Emui, Harmonyos 2025-05-14 3.4 Low
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
CVE-2022-41600 1 Huawei 2 Emui, Harmonyos 2025-05-14 3.4 Low
The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service.
CVE-2022-41585 1 Huawei 2 Emui, Harmonyos 2025-05-14 7.8 High
The kernel module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause memory overwriting.
CVE-2022-41584 1 Huawei 2 Emui, Harmonyos 2025-05-14 7.8 High
The kernel module has an out-of-bounds read vulnerability.Successful exploitation of this vulnerability may cause memory overwriting.
CVE-2022-41583 1 Huawei 2 Emui, Harmonyos 2025-05-14 7.5 High
The storage maintenance and debugging module has an array out-of-bounds read vulnerability.Successful exploitation of this vulnerability will cause incorrect statistics of this module.
CVE-2022-41582 1 Huawei 2 Emui, Harmonyos 2025-05-14 7.5 High
The security module has configuration defects.Successful exploitation of this vulnerability may affect system availability.
CVE-2022-41581 1 Huawei 2 Emui, Harmonyos 2025-05-14 9.1 Critical
The HW_KEYMASTER module has a vulnerability of not verifying the data read.Successful exploitation of this vulnerability may cause malicious construction of data, which results in out-of-bounds access.