Search

Search Results (320151 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-53026 1 Qualcomm 468 205 Mobile Platform, 205 Mobile Platform Firmware, 215 Mobile Platform and 465 more 2025-11-28 8.2 High
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
CVE-2025-34113 1 Tiki 1 Tikiwiki Cms\/groupware 2025-11-28 N/A
An authenticated command injection vulnerability exists in Tiki Wiki CMS versions ≤14.1, ≤12.4 LTS, ≤9.10 LTS, and ≤6.14 via the `viewmode` GET parameter in `tiki-calendar.php`. When the calendar module is enabled and an authenticated user has permission to access it, an attacker can inject and execute arbitrary PHP code. Successful exploitation leads to remote code execution in the context of the web server user.
CVE-2024-53021 1 Qualcomm 450 205 Mobile Platform, 205 Mobile Platform Firmware, 215 Mobile Platform and 447 more 2025-11-28 8.2 High
Information disclosure may occur while processing goodbye RTCP packet from network.
CVE-2025-60917 2 Austrian Archaeological Institute, Craws 2 Openatlas, Openatlas 2025-11-28 4.6 Medium
A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the color parameter.
CVE-2025-60916 2 Austrian Archaeological Institute, Craws 2 Openatlas, Openatlas 2025-11-28 5.4 Medium
A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the charge parameter.
CVE-2025-60915 2 Austrian Archaeological Institute, Craws 2 Openatlas, Openatlas 2025-11-28 8.1 High
An issue in the size query parameter (/views/file.py) of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute a path traversal via a crafted request.
CVE-2025-60914 2 Austrian Archaeological Institute, Craws 2 Openatlas, Openatlas 2025-11-28 4.6 Medium
Incorrect access control in Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to access sensitive information via sending a crafted GET request to the /display_logo endpoint.
CVE-2025-56423 2 Austrian Archaeological Institute, Craws 2 Openatlas, Openatlas 2025-11-28 5.3 Medium
An issue in Austrian Academy of Sciences (AW) Austrian Archaeological Institute OpenAtlas v.8.12.0 allows a remote attacker to obtain sensitive information via the login error messages
CVE-2025-21487 1 Qualcomm 455 205 Mobile Platform, 205 Mobile Platform Firmware, 215 Mobile Platform and 452 more 2025-11-28 8.2 High
Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length.
CVE-2024-21910 1 Tiny 1 Tinymce 2025-11-28 6.1 Medium
TinyMCE versions before 5.10.0 are affected by a cross-site scripting vulnerability. A remote and unauthenticated attacker could introduce crafted image or link URLs that would result in the execution of arbitrary JavaScript in an editing user's browser.
CVE-2024-21908 1 Tiny 1 Tinymce 2025-11-28 6.1 Medium
TinyMCE versions before 5.9.0 are affected by a stored cross-site scripting vulnerability. An unauthenticated and remote attacker could insert crafted HTML into the editor resulting in arbitrary JavaScript execution in another user's browser.
CVE-2023-30805 1 Sangfor 1 Next-gen Application Firewall 2025-11-28 9.8 Critical
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an operating system command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary commands by sending a crafted HTTP POST request to the /LogInOut.php endpoint. This is due to mishandling of shell meta-characters in the "un" parameter.
CVE-2023-30804 1 Sangfor 1 Next-gen Application Firewall 2025-11-28 4.9 Medium
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authenticated file disclosure vulnerability. A remote and authenticated attacker can read arbitrary system files using the svpn_html/loadfile.php endpoint. This issue is exploitable by a remote and unauthenticated attacker when paired with CVE-2023-30803.
CVE-2023-30803 1 Sangfor 1 Next-gen Application Firewall 2025-11-28 9.8 Critical
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can bypass authentication and access administrative functionality by sending HTTP requests using a crafted Y-forwarded-for header.
CVE-2023-30802 1 Sangfor 1 Next-gen Application Firewall 2025-11-28 5.3 Medium
The Sangfor Next-Gen Application Firewall version NGAF8.0.17 is vulnerable to a source code disclosure vulnerability. A remote and unauthenticated attacker can obtain PHP source code by sending an HTTP request with an invalid Content-Length field.
CVE-2025-47318 1 Qualcomm 407 Apq8017, Apq8017 Firmware, Apq8064au and 404 more 2025-11-28 7.5 High
Transient DOS while parsing the EPTM test control message to get the test pattern.
CVE-2025-34186 1 Ilevia 3 Eve X1 Server, Eve X1 Server Firmware, Eve X5 Server 2025-11-28 9.8 Critical
Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized input is passed to a system() call for authentication, allowing attackers to inject special characters and manipulate command parsing. Due to the binary's interpretation of non-zero exit codes as successful authentication, remote attackers can bypass authentication and gain full access to the system.
CVE-2025-34187 1 Ilevia 3 Eve X1 Server, Eve X1 Server Firmware, Eve X5 Server 2025-11-28 8.8 High
Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a misconfiguration in the sudoers file that allows passwordless execution of certain Bash scripts. If these scripts are writable by web-facing users or accessible via command injection, attackers can replace them with malicious payloads. Execution with sudo grants full root access, resulting in remote privilege escalation and potential system compromise.
CVE-2025-34184 1 Ilevia 2 Eve X1 Server, Eve X1 Server Firmware 2025-11-28 9.8 Critical
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax/php/login.php script. Remote attackers can execute arbitrary system commands by injecting payloads into the 'passwd' HTTP POST parameter, leading to full system compromise or denial of service.
CVE-2025-34183 1 Ilevia 2 Eve X1 Server, Eve X1 Server Firmware 2025-11-28 7.5 High
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains a vulnerability in its server-side logging mechanism that allows unauthenticated remote attackers to retrieve plaintext credentials from exposed .log files. This flaw enables full authentication bypass and system compromise through credential reuse.