Search Results (30903 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-34257 1 Totolink 2 Ex1800t, Ex1800t Firmware 2025-05-28 9.8 Critical
TOTOLINK EX1800T V9.1.0cu.2112_B20220316 has a vulnerability in the apcliEncrypType parameter that allows unauthorized execution of arbitrary commands, allowing an attacker to obtain device administrator privileges.
CVE-2024-52274 1 Tenda 2 Ac6, Ac6 Firmware 2025-05-28 9.8 Critical
Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (setDoubleL2tpConfig->guest_ip_check(overflow arg: mask) modules) allows Overflow Buffers.This issue affects Tenda AC6V2: through 15.03.06.50
CVE-2024-52273 1 Tenda 2 Ac6, Ac6 Firmware 2025-05-28 9.8 Critical
Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (setDoublePppoeConfig->guest_ip_check(overflow arg: mask) modules) allows Overflow Buffers.This issue affects Tenda AC6V2: through 15.03.06.50
CVE-2024-52272 1 Tenda 2 Ac6, Ac6 Firmware 2025-05-28 9.8 Critical
Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (fromAdvSetLanip(overflow arg:lanMask) modules) allows Overflow Buffers.This issue affects Tenda AC6V2: through 15.03.06.50
CVE-2024-52275 1 Tenda 2 Ac6, Ac6 Firmware 2025-05-28 9.8 Critical
Stack-based Buffer Overflow vulnerability in Shenzhen Tenda Technology Co Tenda AC6V2 (fromWizardHandle modules) allows Overflow Buffers.This issue affects Tenda AC6V2: through 15.03.06.50.
CVE-2022-40030 1 Simple Task Managing System Project 1 Simple Task Managing System 2025-05-28 9.8 Critical
SourceCodester Simple Task Managing System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at changeStatus.php.
CVE-2023-4122 1 Imsurajghosh 1 Student Information System 2025-05-28 9.9 Critical
Student Information System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'photo' parameter of my-profile page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.
CVE-2025-45885 1 Phpgurukul 1 Vehicle Parking Management System 2025-05-28 9.8 Critical
PHPGURUKUL Vehicle Parking Management System v1.13 is vulnerable to SQL injection in the /vpms/users/login.php file. Attackers can inject malicious code from the parameter 'emailcont' and use it directly in SQL queries.
CVE-2024-5975 1 Contrive 1 Cz Loan Management 2025-05-28 9.1 Critical
The CZ Loan Management WordPress plugin through 1.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
CVE-2021-43310 1 Keylime 1 Keylime 2025-05-27 9.8 Critical
A vulnerability in Keylime before 6.3.0 allows an attacker to craft a request to the agent that resets the U and V keys as if the agent were being re-added to a verifier. This could lead to a remote code execution.
CVE-2022-32174 1 Gogs 1 Gogs 2025-05-27 9 Critical
In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.
CVE-2022-32176 1 Gin-vue-admin Project 1 Gin-vue-admin 2025-05-27 9 Critical
In "Gin-Vue-Admin", versions v2.5.1 through v2.5.3b are vulnerable to Unrestricted File Upload that leads to execution of javascript code, through the "Compress Upload" functionality to the Media Library. When an admin user views the uploaded file, a low privilege attacker will get access to the admin's cookie leading to account takeover.
CVE-2024-6330 2 Geo My Wp, Geomywp 2 Geo My Wp, Geo My Wordpress 2025-05-27 9.8 Critical
The GEO my WP WordPress plugin before 4.5.0.2 does not prevent unauthenticated attackers from including arbitrary files in PHP's execution context, which leads to Remote Code Execution.
CVE-2021-4226 1 Rsjoomla 1 Rsfirewall\! 2025-05-27 9.8 Critical
RSFirewall tries to identify the original IP address by looking at different HTTP headers. A bypass is possible due to the way it is implemented.
CVE-2024-6847 2 Smartsearchwp, Webdigit 2 Chatbot With Chatgpt Wordpress, Chatbot With Chatgpt 2025-05-27 9.8 Critical
The Chatbot with ChatGPT WordPress plugin before 2.4.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users when submitting messages to the chatbot.
CVE-2023-38951 1 Zkteco 1 Biotime 2025-05-27 9.8 Critical
ZKTeco BioTime 8.5.5 through 9.x before 9.0.1 (20240617.19506) allows authenticated attackers to create or overwrite arbitrary files on the server via crafted requests to /base/sftpsetting/ endpoints that abuse a path traversal issue in the Username field and a lack of input sanitization on the SSH Key field. Overwriting specific files may lead to arbitrary code execution as NT AUTHORITY\SYSTEM.
CVE-2022-28722 1 Hp 198 A7w93a, A7w93a Firmware, D3q15a and 195 more 2025-05-27 9.8 Critical
Certain HP Print Products are potentially vulnerable to Buffer Overflow.
CVE-2022-28721 1 Hp 600 1g5m0a, 1g5m0a Firmware, 1k7k6a and 597 more 2025-05-27 9.8 Critical
Certain HP Print Products are potentially vulnerable to Remote Code Execution.
CVE-2023-26770 1 Taskcafe Project 1 Taskcafe 2025-05-27 9.8 Critical
TaskCafe 0.3.2 lacks validation in the Cookie value. Any unauthenticated attacker who knows a registered UserID can change the password of that user.
CVE-2022-37026 2 Erlang, Redhat 2 Erlang\/otp, Openstack 2025-05-27 9.8 Critical
In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certification situations for SSL, TLS, and DTLS.