Search Results (86011 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-31184 1 Rozcom 1 Rozcom Client 2025-01-13 6.2 Medium
ROZCOM client CWE-798: Use of Hard-coded Credentials
CVE-2020-9253 1 Huawei 2 Lion-al00c, Lion-al00c Firmware 2025-01-13 6.3 Medium
There is a stack overflow vulnerability in some Huawei smart phone. An attacker can craft specific packet to exploit this vulnerability. Due to insufficient verification, this could be exploited to tamper with the information to affect the availability. (Vulnerability ID: HWPSIRT-2019-11030) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9253.
CVE-2020-9086 1 Huawei 2 B612, B612 Firmware 2025-01-13 4.3 Medium
There is a buffer error vulnerability in some Huawei product. An unauthenticated attacker may send special UPNP message to the affected products. Due to insufficient input validation of some value, successful exploit may cause some service abnormal. (Vulnerability ID: HWPSIRT-2017-08234) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9086.
CVE-2023-34152 3 Fedoraproject, Imagemagick, Redhat 4 Extra Packages For Enterprise Linux, Fedora, Imagemagick and 1 more 2025-01-13 9.8 Critical
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.
CVE-2023-52954 1 Huawei 2 Emui, Harmonyos 2025-01-13 4.4 Medium
Vulnerability of improper permission control in the Gallery module Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2020-9211 1 Huawei 2 Mate 30, Mate 30 Firmware 2025-01-13 6.4 Medium
There is an out-of-bound read and write vulnerability in Huawei smartphone. A module dose not verify the input sufficiently. Attackers can exploit this vulnerability by modifying some configuration to cause out-of-bound read and write, causing denial of service. (Vulnerability ID: HWPSIRT-2020-05103) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2020-9211.
CVE-2023-29101 1 Muffingroup 1 Betheme 2025-01-13 7.1 High
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Muffingroup Betheme theme <= 26.7.5 versions.
CVE-2022-40697 1 3commarketing 1 3com-asesor-de-cookies 2025-01-13 4.8 Medium
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in 3com – Asesor de Cookies para normativa española plugin <= 3.4.3 versions.
CVE-2023-22721 1 Oi Yandex.maps Project 1 Oi Yandex.maps 2025-01-13 6.5 Medium
Auth. Stored Cross-Site Scripting (XSS) in Oi Yandex.Maps for WordPress <= 3.2.7 versions.
CVE-2023-23687 1 Youtube Shortcode Project 1 Youtube Shortcode 2025-01-13 6.5 Medium
Auth. Stored Cross-Site Scripting (XSS) vulnerability in Youtube shortcode <= 1.8.5 versions.
CVE-2022-29416 1 Afterpay 1 Afterpay Gateway For Woocommerce 2025-01-13 4.7 Medium
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Afterpay Gateway for WooCommerce <= 3.5.0 versions.
CVE-2022-37402 1 Afsanalytics 1 Afs Analytics 2025-01-13 4.8 Medium
Stored Cross-site Scripting (XSS) vulnerability in AFS Analytics plugin <= 4.18 versions.
CVE-2022-38971 1 Themekraft 1 Post Form Registration Form Profile Form For User Profiles And Content Forms 2025-01-13 4.7 Medium
Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions plugin <= 2.7.5 versions.
CVE-2022-40699 1 Yasr - Yet Another Stars Rating Project 1 Yasr - Yet Another Stars Rating 2025-01-13 5.4 Medium
Cross-Site Scripting (XSS) vulnerability in Dario Curvino Yasr – Yet Another Stars Rating plugin <= 3.1.2 versions.
CVE-2022-41554 1 Slideshow Se Project 1 Slideshow Se 2025-01-13 4.8 Medium
Stored Cross-Site Scripting (XSS) vulnerability in John West Slideshow SE plugin <= 2.5.5 versions.
CVE-2022-43461 1 Slideshow Se Project 1 Slideshow Se 2025-01-13 4.8 Medium
Stored Cross-Site Scripting (XSS) vulnerability in John West Slideshow SE plugin <= 2.5.5 versions.
CVE-2022-45817 1 Gc Testimonials Project 1 Gc Testimonials 2025-01-13 5.4 Medium
Cross-Site Scripting (XSS) vulnerability in Erin Garscadden GC Testimonials plugin <= 1.3.2 versions.
CVE-2023-25795 1 Wp-master 1 Feed Changer \& Remover 2025-01-13 5.9 Medium
Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in WP-master.Ir Feed Changer & Remover plugin <= 0.2 versions.
CVE-2023-25794 1 Nooz Project 1 Nooz 2025-01-13 5.9 Medium
Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Mighty Digital Nooz plugin <= 1.6.0 versions.
CVE-2024-24377 1 Idocv 1 Idocview 2025-01-13 9.8 Critical
An issue in idocv v.14.1.3_20231228 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script.