Search Results (87637 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-56087 1 Logpoint 1 Siem 2025-04-17 5.9 Medium
An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template Dashboard. These are executed, leading to Server-Side Template Injection.
CVE-2024-56086 1 Logpoint 1 Siem 2025-04-17 7.1 High
An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are executed when the backup process is initiated, leading to Remote Code Execution.
CVE-2024-56085 1 Logpoint 1 Siem 2025-04-17 5.9 Medium
An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template Dashboard. These are executed, leading to Server-Side Template Injection.
CVE-2024-52676 2 Emiloimagtolis, Online Discussion Forum Project 2 Online Discussion Forum, Online Discussion Forum 2025-04-17 5.4 Medium
Itsourcecode Online Discussion Forum Project v.1.0.0 is vulnerable to Cross Site Scripting (XSS) via /bcc_forum/members/home.php.
CVE-2022-46538 1 Tenda 2 F1203, F1203 Firmware 2025-04-16 9.8 Critical
Tenda F1203 V2.0.1.6 was discovered to contain a command injection vulnerability via the mac parameter at /goform/WriteFacMac.
CVE-2022-46326 1 Huawei 2 Emui, Harmonyos 2025-04-16 9.8 Critical
Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.
CVE-2022-46325 1 Huawei 2 Emui, Harmonyos 2025-04-16 9.8 Critical
Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions.
CVE-2022-46324 1 Huawei 2 Emui, Harmonyos 2025-04-16 9.8 Critical
Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.
CVE-2022-46323 1 Huawei 2 Emui, Harmonyos 2025-04-16 9.8 Critical
Some smartphones have the out-of-bounds write vulnerability.Successful exploitation of this vulnerability may cause system service exceptions.
CVE-2022-46322 1 Huawei 2 Emui, Harmonyos 2025-04-16 7.5 High
Some smartphones have the out-of-bounds write vulnerability. Successful exploitation of this vulnerability may cause system service exceptions.
CVE-2022-46319 1 Huawei 2 Emui, Harmonyos 2025-04-16 9.8 Critical
Fingerprint calibration has a vulnerability of lacking boundary judgment. Successful exploitation of this vulnerability may cause out-of-bounds write.
CVE-2022-25929 1 Smoothiecharts 1 Smoothie Charts 2025-04-16 5.4 Medium
The package smoothie from 1.31.0 and before 1.36.1 are vulnerable to Cross-site Scripting (XSS) due to improper user input sanitization in strokeStyle and tooltipLabel properties. Exploiting this vulnerability is possible when the user can control these properties.
CVE-2023-45552 1 Veridiumid 1 Veridiumad 2025-04-16 6.5 Medium
In VeridiumID before 3.5.0, a stored cross-site scripting (XSS) vulnerability has been discovered in the admin portal that allows an authenticated attacker to take over all accounts by sending malicious input via the self-service portal.
CVE-2024-3024 1 Broadcom 1 Tcpreplay 2025-04-16 5.3 Medium
A vulnerability was found in appneta tcpreplay up to 4.4.4. It has been classified as problematic. This affects the function get_layer4_v6 of the file /tcpreplay/src/common/get.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The identifier VDB-258333 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2024-34224 2 Oretnom23, Sourcecodester 2 Computer Laboratory Management System, Computer Laboratory Management System 2025-04-16 7.3 High
Cross Site Scripting vulnerability in /php-lms/classes/Users.php?f=save in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the firstname, middlename, lastname parameters.
CVE-2024-29865 1 Logpoint 1 Siem 2025-04-16 5.4 Medium
Logpoint before 7.1.0 allows Self-XSS on the LDAP authentication page via the username to the LDAP login form.
CVE-2023-49983 1 Oretnom23 1 School Fees Management System 2025-04-16 6.8 Medium
A cross-site scripting (XSS) vulnerability in the component /management/class of School Fees Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.
CVE-2023-49986 2 Oretnom23, Sourcecodester 2 School Fees Management System, School Fees Management System 2025-04-16 4.7 Medium
A cross-site scripting (XSS) vulnerability in the component /admin/parent of School Fees Management System 1.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter.
CVE-2024-25551 1 Oretnom23 1 Simple Student Attendance System 2025-04-16 6.1 Medium
Cross Site Scripting (XSS) vulnerability in sourcecodester Simple Student Attendance System v1.0 allows attackers to execute arbitrary code via crafted GET request to web application URL.
CVE-2024-25434 1 Pkp.sfu 1 Open Journal Systems 2025-04-16 5.4 Medium
A cross-site scripting (XSS) vulnerability in Pkp Ojs v3.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Publicname parameter.