Search Results (30741 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-57483 1 Tenda 2 I24, I24 Firmware 2025-04-09 9.8 Critical
Tenda i24 V2.0.0.5 is vulnerable to Buffer Overflow in the addWifiMacFilter function.
CVE-2021-3966 1 Zephyrproject 1 Zephyr 2025-04-09 9.6 Critical
usb device bluetooth class includes a buffer overflow related to implementation of net_buf_add_mem.
CVE-2025-22133 1 Wegia 1 Wegia 2025-04-09 10 Critical
WeGIA is a web manager for charitable institutions. Prior to 3.2.8, a critical vulnerability was identified in the /WeGIA/html/socio/sistema/controller/controla_xlsx.php endpoint. The endpoint accepts file uploads without proper validation, allowing the upload of malicious files, such as .phar, which can then be executed by the server. This vulnerability is fixed in 3.2.8.
CVE-2025-22140 1 Wegia 1 Wegia 2025-04-09 8.8 High
WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /html/funcionario/dependente_listar_um.php endpoint, specifically in the id_dependente parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database. This vulnerability is fixed in 3.2.8.
CVE-2025-22141 1 Wegia 1 Wegia 2025-04-09 8.8 High
WeGIA is a web manager for charitable institutions. A SQL Injection vulnerability was identified in the /dao/verificar_recursos_cargo.php endpoint, specifically in the cargo parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database. This vulnerability is fixed in 3.2.8.
CVE-2017-20166 1 Ecto Project 1 Ecto 2025-04-09 9.8 Critical
Ecto 2.2.0 lacks a certain protection mechanism associated with the interaction between is_nil and raise.
CVE-2025-28402 1 Ruoyi 1 Ruoyi 2025-04-09 9.8 Critical
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobId parameter
CVE-2025-28405 1 Ruoyi 1 Ruoyi 2025-04-09 9.8 Critical
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the changeStatus method
CVE-2025-28406 1 Ruoyi 1 Ruoyi 2025-04-09 9.8 Critical
An issue in RUoYi v.4.8.0 allows a remote attacker to escalate privileges via the jobLogId parameter
CVE-2022-38490 1 Easyvista 1 Service Manager 2025-04-09 9.6 Critical
An issue was discovered in EasyVista 2020.2.125.3 and 2022.1.109.0.03. Some parameters allow SQL injection. Version 2022.1.110.1.02 corrects this issue.
CVE-2022-4866 1 Usememos 1 Memos 2025-04-09 9.0 Critical
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-4865 1 Usememos 1 Memos 2025-04-09 9.0 Critical
Cross-site Scripting (XSS) - Stored in GitHub repository usememos/memos prior to 0.9.1.
CVE-2022-47866 1 Lead Management System Project 1 Lead Management System 2025-04-09 9.8 Critical
Lead management system v1.0 is vulnerable to SQL Injection via the id parameter in removeBrand.php.
CVE-2022-47865 1 Lead Management System Project 1 Lead Management System 2025-04-09 9.8 Critical
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeOrder.php.
CVE-2022-47864 1 Lead Management System Project 1 Lead Management System 2025-04-09 9.8 Critical
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeCategories.php.
CVE-2022-47862 1 Lead Management System Project 1 Lead Management System 2025-04-09 9.8 Critical
Lead Management System v1.0 is vulnerable to SQL Injection via the customer_id parameter in ajax_represent.php.
CVE-2022-47861 1 Lead Management System Project 1 Lead Management System 2025-04-09 9.8 Critical
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeLead.php.
CVE-2022-47860 1 Lead Management System Project 1 Lead Management System 2025-04-09 9.8 Critical
Lead Management System v1.0 is vulnerable to SQL Injection via the id parameter in removeProduct.php.
CVE-2022-47859 1 Lead Management System Project 1 Lead Management System 2025-04-09 9.8 Critical
Lead Management System v1.0 is vulnerable to SQL Injection via the user_id parameter in changePassword.php.
CVE-2022-47790 1 Dynamic Transaction Queuing System Project 1 Dynamic Transaction Queuing System 2025-04-09 9.8 Critical
Sourcecodester Dynamic Transaction Queuing System v1.0 is vulnerable to SQL Injection via /queuing/index.php?page=display&id=.