Search Results (100965 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-21077 1 Oracle 1 Trade Management 2025-03-28 7.5 High
Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: GL Accounts LOV). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trade Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Trade Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
CVE-2023-52715 1 Huawei 1 Harmonyos 2025-03-28 7.5 High
The SystemUI module has a vulnerability in permission management. Impact: Successful exploitation of this vulnerability may affect availability.
CVE-2025-25876 1 Angeljudesuarez 1 Simple Chatbox 2025-03-28 7.2 High
A vulnerability was found in ITSourcecode Simple ChatBox up to 1.0. This vulnerability affects unknown code of the file /delete.php. The attack can use SQL injection to obtain sensitive data.
CVE-2025-25387 1 Phpgurukul 1 Land Record System 2025-03-28 7.2 High
A SQL Injection vulnerability was found in /admin/manage-propertytype.php in PHPGurukul Land Record System v1.0, which allows remote attackers to execute arbitrary code via the propertytype POST request parameter.
CVE-2024-46429 1 Tenda 2 W18e, W18e Firmware 2025-03-28 8.8 High
A hardcoded credentials vulnerability in Tenda W18E V16.01.0.8(1625) allows unauthenticated remote attackers to access the web management portal using a default guest account with administrative privileges.
CVE-2022-44715 1 Netscout 1 Ngeniusone 2025-03-28 8.8 High
Improper File Permissions in NetScout nGeniusONE 6.3.2 build 904 allows authenticated remote users to gain permissions via a crafted payload.
CVE-2022-44026 1 Netscout 1 Ngeniusone 2025-03-28 7.1 High
An issue was discovered in NetScout nGeniusONE 6.3.2 before P10. It allows Reflected Cross-Site Scripting (XSS), issue 3 of 6.
CVE-2020-36658 2 Debian, Lemonldap-ng 2 Debian Linux, Apache\ 2025-03-28 8.1 High
In Apache::Session::LDAP before 0.5, validity of the X.509 certificate is not checked by default when connecting to remote LDAP backends, because the default configuration of the Net::LDAPS module for Perl is used. NOTE: this can, for example, be fixed in conjunction with the CVE-2020-16093 fix.
CVE-2022-46499 2 Codeastro, Phpgurukul 2 Hospital Management System, Hospital Management System 2025-03-28 8.8 High
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_admin_view_single_patient.php.
CVE-2022-46497 2 Codeastro, Phpgurukul 2 Hospital Management System, Hospital Management System 2025-03-28 8.1 High
Hospital Management System 1.0 was discovered to contain a SQL injection vulnerability via the pat_number parameter at his_doc_view_single_patien.php.
CVE-2025-23058 1 Arubanetworks 1 Clearpass Policy Manager 2025-03-28 8.8 High
A vulnerability in the ClearPass Policy Manager web-based management interface allows a low-privileged (read-only) authenticated remote attacker to gain unauthorized access to data and the ability to execute functions that should be restricted to administrators only with read/write privileges. Successful exploitation could enable a low-privileged user to execute administrative functions leading to an escalation of privileges.
CVE-2024-29499 1 Anchorcms 1 Anchor Cms 2025-03-28 7.4 High
Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via /anchor/admin/users/delete/2.
CVE-2024-42599 1 Seacms 1 Seacms 2025-03-28 8.8 High
SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_files.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the vulnerability to execute arbitrary commands and gain system privileges.
CVE-2024-44916 1 Seacms 1 Seacms 2025-03-28 7.2 High
Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php file and could result in arbitrary command execution.
CVE-2024-44720 1 Seacms 1 Seacms 2025-03-28 7.5 High
SeaCMS v13.1 was discovered to an arbitrary file read vulnerability via the component admin_safe.php.
CVE-2024-50808 1 Seacms 1 Seacms 2025-03-28 8.8 High
SeaCms 13.1 is vulnerable to code injection in the notification module of the member message notification module in the backend user module, due to unsafe handling of the "notify" variable in admin_notify.php.
CVE-2025-25515 1 Seacms 1 Seacms 2025-03-28 8.8 High
Seacms <=13.3 is vulnerable to SQL Injection in admin_collect.php that allows an authenticated attacker to exploit the database.
CVE-2024-30565 1 Seacms 1 Seacms 2025-03-28 8.8 High
An issue was discovered in SeaCMS version 12.9, allows remote attackers to execute arbitrary code via admin notify.php.
CVE-2021-36874 1 Stylemixthemes 1 Ulisting 2025-03-28 7.1 High
Authenticated Insecure Direct Object References (IDOR) vulnerability in WordPress uListing plugin (versions <= 2.0.5).
CVE-2021-36880 1 Stylemixthemes 1 Ulisting 2025-03-28 8.6 High
Unauthenticated SQL Injection (SQLi) vulnerability in WordPress uListing plugin (versions <= 2.0.3), vulnerable parameter: custom.