Search Results (30800 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-51018 1 Totolink 2 Ex1800t, Ex1800t Firmware 2025-04-17 9.8 Critical
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘opmode’ parameter of the setWiFiApConfig interface of the cstecgi .cgi.
CVE-2024-2599 1 Amss\+\+ Project 1 Amss\+\+ 2025-04-17 9.9 Critical
File upload restriction evasion vulnerability in AMSS++ version 4.31. This vulnerability could allow an authenticated user to potentially obtain RCE through webshell, compromising the entire infrastructure.
CVE-2023-50651 1 Totolink 2 X6000r, X6000r Firmware 2025-04-17 9.8 Critical
TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the component /cgi-bin/cstecgi.cgi.
CVE-2023-49442 1 Jeecg 1 Jeecg 2025-04-17 9.8 Critical
Deserialization of Untrusted Data in jeecgFormDemoController in JEECG 4.0 and earlier allows attackers to run arbitrary code via crafted POST request.
CVE-2023-47458 1 Bladex 1 Springblade 2025-04-17 9.8 Critical
An issue in SpringBlade v.3.7.0 and before allows a remote attacker to escalate privileges via the lack of permissions control framework.
CVE-2023-32874 1 Mediatek 45 Lr13, Mt2735, Mt6779 and 42 more 2025-04-17 9.8 Critical
In Modem IMS Stack, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY01161803; Issue ID: MOLY01161803 (MSV-893).
CVE-2022-42529 1 Google 1 Android 2025-04-17 9.8 Critical
Product: AndroidVersions: Android kernelAndroid ID: A-235292841References: N/A
CVE-2020-13879 1 Irfanview 1 B3d 2025-04-17 9.8 Critical
IrfanView B3D PlugIns before version 4.56 has a B3d.dll!+214f heap-based out-of-bounds write.
CVE-2023-52044 1 Std42 1 Elfinder 2025-04-17 9.8 Critical
Studio-42 eLfinder 2.1.62 is vulnerable to Remote Code Execution (RCE) as there is no restriction for uploading files with the .php8 extension.
CVE-2024-48237 1 Wtcms Project 1 Wtcms 2025-04-17 9.8 Critical
WTCMS 1.0 is vulnerable to Incorrect Access Control in \Common\Controller\HomebaseController.class.php.
CVE-2023-33025 1 Qualcomm 48 Ar8035, Ar8035 Firmware, Fastconnect 6700 and 45 more 2025-04-17 9.8 Critical
Memory corruption in Data Modem when a non-standard SDP body, during a VOLTE call.
CVE-2023-52310 1 Paddlepaddle 1 Paddlepaddle 2025-04-17 9.6 Critical
PaddlePaddle before 2.6.0 has a command injection in get_online_pass_interval. This resulted in the ability to execute arbitrary commands on the operating system.
CVE-2024-46986 1 Tuzitio 1 Camaleon Cms 2025-04-17 10 Critical
Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. An arbitrary file write vulnerability accessible via the upload method of the MediaController allows authenticated users to write arbitrary files to any location on the web server Camaleon CMS is running on (depending on the permissions of the underlying filesystem). E.g. This can lead to a delayed remote code execution in case an attacker is able to write a Ruby file into the config/initializers/ subfolder of the Ruby on Rails application. This issue has been addressed in release version 2.8.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVE-2024-25517 1 Ruvar 1 Ruvaroa 2025-04-17 9.8 Critical
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the tbTable argument at /WebUtility/MF.aspx.
CVE-2024-25518 1 Ruvar 1 Ruvaroa 2025-04-17 9.4 Critical
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the template_id parameter at /WorkFlow/wf_get_fields_approve.aspx.
CVE-2024-25519 1 Ruvar 1 Ruvaroa 2025-04-17 9.8 Critical
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the idlist parameter at /WorkFlow/wf_work_print.aspx.
CVE-2024-25520 1 Ruvar 2 Ruvaroa, Ruvaroa 2025-04-17 9.8 Critical
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /SysManage/sys_blogtemplate_new.aspx.
CVE-2024-25521 1 Ruvar 2 Ruvaroa, Ruvaroa 2025-04-17 9.4 Critical
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the txt_keyword parameter at get_company.aspx.
CVE-2024-25522 1 Ruvar 1 Ruvaroa 2025-04-17 9.4 Critical
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the office_missive_id parameter at /WorkFlow/wf_work_form_save.aspx.
CVE-2024-25523 1 Ruvar 2 Ruvaroa, Ruvaroa 2025-04-17 9.8 Critical
RuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /filemanage/file_memo.aspx.