Search Results (342404 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-8736 1 Lollms 1 Lollms Web Ui 2025-04-04 6.5 Medium
A Denial of Service (DoS) vulnerability exists in multiple file upload endpoints of parisneo/lollms-webui version V12 (Strawberry). The vulnerability can be exploited remotely via Cross-Site Request Forgery (CSRF). Despite CSRF protection preventing file uploads, the application still processes multipart boundaries, leading to resource exhaustion. By appending additional characters to the multipart boundary, an attacker can cause the server to parse each byte of the boundary, ultimately leading to service unavailability. This vulnerability is present in the `/upload_avatar`, `/upload_app`, and `/upload_logo` endpoints.
CVE-2024-12537 1 Openwebui 1 Open Webui 2025-04-04 7.5 High
In version 0.3.32 of open-webui/open-webui, the absence of authentication mechanisms allows any unauthenticated attacker to access the `api/v1/utils/code/format` endpoint. If a malicious actor sends a POST request with an excessively high volume of content, the server could become completely unresponsive. This could lead to severe performance issues, causing the server to become unresponsive or experience significant degradation, ultimately resulting in service interruptions for legitimate users.
CVE-2024-12450 1 Infiniflow 1 Ragflow 2025-04-04 9.8 Critical
In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `document_app.py` contains multiple vulnerabilities. The function does not filter URL parameters, allowing attackers to exploit Full Read SSRF by accessing internal network addresses and viewing their content through the generated PDF files. Additionally, the lack of restrictions on the file protocol enables Arbitrary File Read, allowing attackers to read server files. Furthermore, the use of an outdated Chromium headless version with --no-sandbox mode enabled makes the application susceptible to Remote Code Execution (RCE) via known Chromium v8 vulnerabilities. These issues are resolved in version 0.14.0.
CVE-2023-23749 1 Miniorange 1 Ldap Integration With Active Directory And Openldap 2025-04-04 7.5 High
The 'LDAP Integration with Active Directory and OpenLDAP - NTLM & Kerberos Login' extension is vulnerable to LDAP Injection since is not properly sanitizing the 'username' POST parameter. An attacker can manipulate this paramter to dump arbitrary contents form the LDAP Database.
CVE-2025-2972 2025-04-04 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-2970 2025-04-04 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-2969 2025-04-04 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-2968 2025-04-04 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-2967 2025-04-04 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-2966 2025-04-04 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-2965 2025-04-04 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-2964 2025-04-04 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-2963 2025-04-03 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2023-20908 1 Google 1 Android 2025-04-03 5.5 Medium
In several functions of SettingsState.java, there is a possible system crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-239415861
CVE-2023-20905 1 Google 1 Android 2025-04-03 7.8 High
In Mfc_Transceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-241387741
CVE-2023-20904 1 Google 1 Android 2025-04-03 7.8 High
In getTrampolineIntent of SettingsActivity.java, there is a possible launch of arbitrary activity due to an Intent mismatch in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-246300272
CVE-2022-48126 1 Totolink 2 A7100ru, A7100ru Firmware 2025-04-03 9.8 Critical
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the username parameter in the setting/setOpenVpnCertGenerationCfg function.
CVE-2022-20494 1 Google 1 Android 2025-04-03 5.5 Medium
In AutomaticZenRule of AutomaticZenRule.java, there is a possible persistent DoS due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-243794204
CVE-2020-22658 1 Ruckuswireless 28 R310, R310 Firmware, R500 and 25 more 2025-04-03 9.8 Critical
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone (vSZ) before 3.6.2.0.795, ZoneDirector 1100 9.10.2.0.130, ZoneDirector 1200 10.2.1.0.218, ZoneDirector 3000 10.2.1.0.218, ZoneDirector 5000 10.0.1.0.151, a vulnerability allows attackers to switch completely to unauthorized image to be Boot as primary verified image.
CVE-2025-1805 2025-04-03 5.3 Medium
Crypt::Salt for Perl version 0.01 uses insecure rand() function when generating salts for cryptographic purposes.