Search Results (101067 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-33218 1 Qualcomm 48 Apq8064au, Apq8064au Firmware, Apq8096au and 45 more 2025-04-09 8.2 High
Memory corruption in Automotive due to improper input validation.
CVE-2022-25746 1 Qualcomm 196 Aqt1000, Aqt1000 Firmware, Ar8035 and 193 more 2025-04-09 8.1 High
Memory corruption in kernel due to missing checks when updating the access rights of a memextent mapping.
CVE-2022-3679 1 Kadencewp 1 Starter Templates 2025-04-09 8.8 High
The Starter Templates by Kadence WP WordPress plugin before 1.2.17 unserialises the content of an imported file, which could lead to PHP object injection issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
CVE-2025-28407 1 Ruoyi 1 Ruoyi 2025-04-09 8.8 High
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the edit method of the /edit/{dictId} endpoint does not properly validate whether the requesting user has permission to modify the specified dictId
CVE-2025-28409 1 Ruoyi 1 Ruoyi 2025-04-09 8.8 High
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the add method of the /add/{parentId} endpoint does not properly validate whether the requesting user has permission to add a menu item under the specified parentId
CVE-2024-36612 1 Zulip 2 Zulip, Zulip Server 2025-04-09 7.5 High
Zulip from 8.0 to 8.3 contains a memory leak vulnerability in the handling of popovers.
CVE-2022-4665 1 Ampache 1 Ampache 2025-04-09 8.8 High
Unrestricted Upload of File with Dangerous Type in GitHub repository ampache/ampache prior to 5.5.6.
CVE-2024-51116 1 Tenda 2 Ac6, Ac6 Firmware 2025-04-09 8.8 High
Tenda AC6 v2.0 V15.03.06.50 was discovered to contain a buffer overflow in the function 'formSetPPTPServer'.
CVE-2024-44859 1 Tenda 2 Fh1201, Fh1201 Firmware 2025-04-09 8 High
Tenda FH1201 v1.2.0.14 has a stack buffer overflow vulnerability in `formWrlExtraGet`.
CVE-2024-54907 1 Totolink 2 A3002r, A3002r Firmware 2025-04-09 8.8 High
TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Remote Code Execution in /bin/boa via formWsc.
CVE-2024-53472 1 Wegia 1 Wegia 2025-04-09 8.8 High
WeGIA v3.2.0 was discovered to contain a Cross-Site Request Forgery (CSRF).
CVE-2024-53473 1 Wegia 1 Wegia 2025-04-09 7.5 High
WeGIA 3.2.0 before 3998672 does not verify permission to change a password.
CVE-2025-22140 1 Wegia 1 Wegia 2025-04-09 8.8 High
WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /html/funcionario/dependente_listar_um.php endpoint, specifically in the id_dependente parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database. This vulnerability is fixed in 3.2.8.
CVE-2025-22141 1 Wegia 1 Wegia 2025-04-09 8.8 High
WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /dao/verificar_recursos_cargo.php endpoint, specifically in the cargo parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database. This vulnerability is fixed in 3.2.8.
CVE-2024-57030 1 Wegia 1 Wegia 2025-04-09 8.1 High
Wegia < 3.2.0 is vulnerable to Cross Site Scripting (XSS) in /geral/documentos_funcionario.php via the id parameter.
CVE-2024-35552 1 Idccms 1 Idccms 2025-04-09 8.8 High
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=del&dataType=logo&dataTypeCN.
CVE-2024-35553 1 Idccms 1 Idccms 2025-04-09 8.3 High
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=add&nohrefStr=close.
CVE-2024-35556 1 Idccms 1 Idccms 2025-04-09 8.8 High
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/vpsSys_deal.php?mudi=infoSet.
CVE-2024-35558 2 Idccms, Idccms Project 2 Idccms, Idccms 2025-04-09 8.8 High
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=rev&nohrefStr=close.
CVE-2024-35559 2 Idccms, Idccms Project 2 Idccms, Idccms 2025-04-09 8.8 High
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoMove_deal.php?mudi=rev&nohrefStr=close.