Search Results (30903 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-51964 1 Tenda 2 Ax1803, Ax1803 Firmware 2025-06-03 9.8 Critical
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function setIptvInfo.
CVE-2023-51956 1 Tenda 2 Ax1803, Ax1803 Firmware 2025-06-03 9.8 Critical
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.city.vlan parameter in the function formSetIptv
CVE-2023-51954 1 Tenda 2 Ax1803, Ax1803 Firmware 2025-06-03 9.8 Critical
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formSetIptv.
CVE-2023-51277 1 Tinowagner 1 Jupyter Notebook Viewer 2025-06-03 9.8 Critical
nbviewer-app (aka Jupyter Notebook Viewer) before 0.1.6 has the get-task-allow entitlement for release builds.
CVE-2023-50982 1 Studip 1 Stud.ip 2025-06-03 9 Critical
Stud.IP 5.x through 5.3.3 allows XSS with resultant upload of executable files, because upload_action and edit_action in Admin_SmileysController do not check the file extension. This leads to remote code execution with the privileges of the www-data user. The fixed versions are 5.3.4, 5.2.6, 5.1.7, and 5.0.9.
CVE-2023-50643 1 Evernote 1 Evernote 2025-06-03 9.8 Critical
An issue in Evernote Evernote for MacOS v.10.68.2 allows a remote attacker to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments components.
CVE-2023-50585 1 Tenda 2 A18, A18 Firmware 2025-06-03 9.8 Critical
Tenda A18 v15.13.07.09 was discovered to contain a stack overflow via the devName parameter in the formSetDeviceName function.
CVE-2023-50090 1 Ureport2 Project 1 Ureport2 2025-06-03 9.8 Critical
Arbitrary File Write vulnerability in the saveReportFile method of ureport2 2.2.9 and before allows attackers to write arbitrary files and run arbitrary commands via crafted POST request.
CVE-2023-50027 1 Buy-addons 1 Bazoom Magnifier 2025-06-03 9.8 Critical
SQL Injection vulnerability in Buy Addons baproductzoommagnifier module for PrestaShop versions 1.0.16 and before, allows remote attackers to escalate privileges and gain sensitive information via BaproductzoommagnifierZoomModuleFrontController::run() method.
CVE-2022-39009 1 Huawei 2 Emui, Harmonyos 2025-06-03 9.8 Critical
The WLAN module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause third-party apps to affect WLAN functions.
CVE-2024-55371 1 Wallosapp 1 Wallos 2025-06-03 9.8 Critical
Wallos <= 2.38.2 has a file upload vulnerability in the restore backup function, which allows authenticated users to restore backups by uploading a ZIP file. The contents of the ZIP file are extracted on the server. This functionality enables an authenticated attacker (being an administrator is not required) to upload malicious files to the server. Once a web shell is installed, the attacker gains the ability to execute arbitrary commands.
CVE-2024-55372 1 Wallosapp 1 Wallos 2025-06-03 9.8 Critical
Wallos <=2.38.2 has a file upload vulnerability in the restore database function, which allows unauthenticated users to restore database by uploading a ZIP file. The contents of the ZIP file are extracted on the server. This functionality enables an unauthenticated attacker to upload malicious files to the server. Once a web shell is installed, the attacker gains the ability to execute arbitrary commands.
CVE-2023-33030 1 Qualcomm 596 315 5g Iot Modem, 315 5g Iot Modem Firmware, 9205 Lte Modem and 593 more 2025-06-03 9.3 Critical
Memory corruption in HLOS while running playready use-case.
CVE-2023-6339 1 Google 2 Nest Wifi Pro, Nest Wifi Pro Firmware 2025-06-03 10 Critical
Google Nest WiFi Pro root code-execution & user-data compromise
CVE-2023-48418 1 Google 2 Pixel Watch, Pixel Watch Firmware 2025-06-03 10 Critical
In checkDebuggingDisallowed of DeviceVersionFragment.java, there is a     possible way to access adb before SUW completion due to an insecure default     value. This could lead to local escalation of privilege with no additional     execution privileges needed. User interaction is not needed for     exploitation
CVE-2023-50743 1 Kashipara 1 Online Notice Board System 2025-06-03 9.8 Critical
Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'dd' parameter of the registration.php resource does not validate the characters received and they are sent unfiltered to the database.
CVE-2023-50753 1 Kashipara 1 Online Notice Board System 2025-06-03 9.8 Critical
Online Notice Board System v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'dd' parameter of the user/update_profile.php resource does not validate the characters received and they are sent unfiltered to the database.
CVE-2023-50866 1 Kashipara 1 Travel Website 2025-06-03 9.8 Critical
Travel Website v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'username' parameter of the loginAction.php resource does not validate the characters received and they are sent unfiltered to the database.
CVE-2020-16165 1 Bladex 1 Springblade 2025-06-03 9.8 Critical
The DAO/DTO implementation in SpringBlade through 2.7.1 allows SQL Injection in an ORDER BY clause. This is related to the /api/blade-log/api/list ascs and desc parameters.
CVE-2024-0322 1 Gpac 1 Gpac 2025-06-03 9.1 Critical
Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3-DEV.