Search Results (30673 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-1608 1 Oppo 1 Usercenter Credit Software Development Kit 2025-04-02 9.1 Critical
In OPPO Usercenter Credit SDK, there's a possible escalation of privilege due to loose permission check, This could lead to application internal information leak w/o user interaction.
CVE-2024-24722 1 12dsynergy 4 12d Synergy File Replication Server, 12d Synergy Server, 12dsynergy and 1 more 2025-04-02 9.1 Critical
An unquoted service path vulnerability in the 12d Synergy Server and File Replication Server components may allow an attacker to gain elevated privileges via the 12d Synergy Server and/or 12d Synergy File Replication Server executable service path. This is fixed in 4.3.10.192, 5.1.5.221, and 5.1.6.235.
CVE-2023-23560 1 Lexmark 256 B2236, B2236 Firmware, B2338 and 253 more 2025-04-02 9.8 Critical
In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.
CVE-2022-4693 1 Pickplugins 1 User Verification 2025-04-02 9.8 Critical
The User Verification WordPress plugin before 1.0.94 was affected by an Auth Bypass security vulnerability. To bypass authentication, we only need to know the user’s username. Depending on whose username we know, which can be easily queried because it is usually public data, we may even be given an administrative role on the website.
CVE-2022-4383 1 Codeboxr 1 Cbx Petition For Wordpress 2025-04-02 9.8 Critical
The CBX Petition for WordPress plugin through 1.0.3 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
CVE-2021-43445 1 Onlyoffice 1 Server 2025-04-02 9.8 Critical
ONLYOFFICE all versions as of 2021-11-08 is affected by Incorrect Access Control. An attacker can authenticate with the web socket service of the ONLYOFFICE document editor which is protected by JWT auth by using a default JWT signing key.
CVE-2023-0435 1 Pyload 1 Pyload 2025-04-02 9.8 Critical
Excessive Attack Surface in GitHub repository pyload/pyload prior to 0.5.0b3.dev41.
CVE-2023-24430 1 Jenkins 1 Semantic Versioning 2025-04-02 9.8 Critical
Jenkins Semantic Versioning Plugin 1.14 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2023-24429 1 Jenkins 1 Semantic Versioning 2025-04-02 9.8 Critical
Jenkins Semantic Versioning Plugin 1.14 and earlier does not restrict execution of an controller/agent message to agents, and implements no limitations about the file path that can be parsed, allowing attackers able to control agent processes to have Jenkins parse a crafted file that uses external entities for extraction of secrets from the Jenkins controller or server-side request forgery.
CVE-2023-24427 1 Jenkins 1 Bitbucket Oauth 2025-04-02 9.8 Critical
Jenkins Bitbucket OAuth Plugin 0.12 and earlier does not invalidate the previous session on login.
CVE-2022-40037 1 Javaweb Blog Project 1 Javaweb Blog 2025-04-02 9.8 Critical
An issue discovered in Rawchen blog-ssm v1.0 allows remote attacker to escalate privileges and execute arbitrary commands via the component /upFile.
CVE-2022-3572 1 Gitlab 1 Gitlab 2025-04-02 9.3 Critical
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions from 13.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the Jira Connect integration which could lead to a reflected XSS that allowed attackers to perform arbitrary actions on behalf of victims.
CVE-2023-24456 1 Jenkins 1 Keycloak Authentication 2025-04-02 9.8 Critical
Jenkins Keycloak Authentication Plugin 2.3.0 and earlier does not invalidate the previous session on login.
CVE-2023-24444 1 Jenkins 1 Openid 2025-04-02 9.8 Critical
Jenkins OpenID Plugin 2.4 and earlier does not invalidate the previous session on login.
CVE-2023-24443 1 Jenkins 1 Testcomplete Support 2025-04-02 9.8 Critical
Jenkins TestComplete support Plugin 2.8.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2023-24441 1 Jenkins 1 Mstest 2025-04-02 9.8 Critical
Jenkins MSTest Plugin 1.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2022-31706 1 Vmware 1 Vrealize Log Insight 2025-04-02 9.8 Critical
The vRealize Log Insight contains a Directory Traversal Vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.
CVE-2022-31704 1 Vmware 1 Vrealize Log Insight 2025-04-02 9.8 Critical
The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely inject code into sensitive files of an impacted appliance which can result in remote code execution.
CVE-2023-24022 1 Baicells 5 Nova227, Nova233, Nova243 and 2 more 2025-04-02 10 Critical
Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB devices with firmware through RTS/RTD 3.7.11.3 have hardcoded credentials that are easily discovered and can be used by remote attackers to authenticate via ssh. (The credentials are stored in the firmware, encrypted by the crypt function.)
CVE-2024-57169 1 Soplanning 1 Soplanning 2025-04-02 9.8 Critical
A file upload bypass vulnerability exists in SOPlanning 1.53.00, specifically in /process/upload.php. This vulnerability allows remote attackers to bypass upload restrictions and potentially achieve remote code execution by uploading malicious files.