Search Results (14038 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-22133 1 Wegia 1 Wegia 2025-04-09 10 Critical
WeGIA is a web manager for charitable institutions. Prior to 3.2.8, a critical vulnerability was identified in the /WeGIA/html/socio/sistema/controller/controla_xlsx.php endpoint. The endpoint accepts file uploads without proper validation, allowing the upload of malicious files, such as .phar, which can then be executed by the server. This vulnerability is fixed in 3.2.8.
CVE-2022-4847 1 Usememos 1 Memos 2025-04-09 6.5 Medium
Incorrectly Specified Destination in a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4848 1 Usememos 1 Memos 2025-04-09 5.7 Medium
Improper Verification of Source of a Communication Channel in GitHub repository usememos/memos prior to 0.9.1.
CVE-2024-2537 1 Logitech 1 Logi Tune 2025-04-09 4.4 Medium
Improper Control of Dynamically-Managed Code Resources vulnerability in Logitech Logi Tune on MacOS allows Local Code Inclusion.
CVE-2023-0048 1 Daloradius 1 Daloradius 2025-04-09 8.8 High
Code Injection in GitHub repository lirantal/daloradius prior to master-branch.
CVE-2024-2497 1 Raspap 1 Raspap 2025-04-09 4.7 Medium
A vulnerability was found in RaspAP raspap-webgui 3.0.9 and classified as critical. This issue affects some unknown processing of the file includes/provider.php of the component HTTP POST Request Handler. The manipulation of the argument country leads to code injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-256919. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-3397 1 Yzmcms 1 Yzmcms 2025-04-09 4.3 Medium
A vulnerability classified as problematic has been found in YzmCMS 7.1. Affected is an unknown function of the file message.tpl. The manipulation of the argument gourl leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2022-3841 1 Redhat 2 Acm, Advanced Cluster Management For Kubernetes 2025-04-09 7.8 High
RHACM: unauthenticated SSRF in console API endpoint. A Server-Side Request Forgery (SSRF) vulnerability was found in the console API endpoint from Red Hat Advanced Cluster Management for Kubernetes (RHACM). An attacker could take advantage of this as the console API endpoint is missing an authentication check, allowing unauthenticated users making requests.
CVE-2024-35339 1 Tenda 2 Fh1206, Fh1206 Firmware 2025-04-09 9.8 Critical
Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/WriteFacMac.
CVE-2025-25789 1 Foxcms 1 Foxcms 2025-04-09 9.8 Critical
FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php.
CVE-2025-25760 1 Sucms Project 1 Sucms 2025-04-09 7.5 High
A Server-Side Request Forgery (SSRF) in the component admin_webgather.php of SUCMS v1.0 allows attackers to access internal data and services via a crafted GET request.
CVE-2023-0022 1 Sap 1 Businessobjects Business Intelligence Platform 2025-04-09 9.9 Critical
SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by the application over the network. On successful exploitation, an attacker can perform operations that may completely compromise the application causing a high impact on the confidentiality, integrity, and availability of the application.
CVE-2024-44677 1 Eladmin 1 Eladmin 2025-04-08 9.8 Critical
eladmin v2.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the DatabaseController.java component.
CVE-2025-26818 1 Netwrix 1 Password Secure 2025-04-08 9.8 Critical
Netwrix Password Secure through 9.2 allows command injection.
CVE-2025-32370 1 Kentico 1 Xperience 2025-04-08 7.2 High
Kentico Xperience before 13.0.178 has a specific set of allowed ContentUploader file extensions for unauthenticated uploads; however, because .zip is processed through TryZipProviderSafe, there is additional functionality to create files with other extensions. NOTE: this is a separate issue not necessarily related to SVG or XSS.
CVE-2025-32013 1 Lnbits 1 Lnbits 2025-04-08 7.5 High
LNbits is a Lightning wallet and accounts system. A Server-Side Request Forgery (SSRF) vulnerability has been discovered in LNbits' LNURL authentication handling functionality. When processing LNURL authentication requests, the application accepts a callback URL parameter and makes an HTTP request to that URL using the httpx library with redirect following enabled. The application doesn't properly validate the callback URL, allowing attackers to specify internal network addresses and access internal resources.
CVE-2025-3326 1 Iteaj 1 Iboot 2025-04-08 3.5 Low
A vulnerability has been found in iteaj iboot 物联网网关 1.1.3 and classified as problematic. This vulnerability affects unknown code of the file /common/upload of the component File Upload. The manipulation of the argument File leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-3327 1 Iteaj 1 Iboot 2025-04-08 3.5 Low
A vulnerability was found in iteaj iboot 物联网网关 1.1.3 and classified as problematic. This issue affects some unknown processing of the file /common/upload/batch of the component File Upload. The manipulation of the argument File leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-3297 1 Oretnom23 1 Online Eyewear Shop 2025-04-08 3.5 Low
A vulnerability, which was classified as problematic, was found in SourceCodester Online Eyewear Shop 1.0. Affected is an unknown function of the file /classes/Master.php?f=save_product. The manipulation of the argument brand leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
CVE-2024-29090 1 Meowapps 1 Ai Engine 2025-04-08 6.8 Medium
Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.1.4.