Search Results (30648 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-24331 2 D-link, Dlink 3 Dir-816 A2 Firmware, Dir-816, Dir-816 Firmware 2025-03-25 9.8 Critical
Command Injection vulnerability in D-Link Dir 816 with firmware version DIR-816_A2_v1.10CNB04 allows attackers to run arbitrary commands via the urlAdd parameter.
CVE-2025-22974 1 Seacms 1 Seacms 2025-03-25 9.8 Critical
SQL Injection vulnerability in SeaCMS v.13.2 and before allows a remote attacker to execute arbitrary code via the DoTranExecSql parameter in the phome.php component.
CVE-2024-27227 1 Google 2 Android, Pixel 2025-03-25 9.8 Critical
A malicious DNS response can trigger a number of OOB reads, writes, and other memory issues
CVE-2022-3229 2 Microsoft, Unifiedremote 2 Windows, Unified Remote 2025-03-25 9.8 Critical
Because the web management interface for Unified Intents' Unified Remote solution does not itself require authentication, a remote, unauthenticated attacker can change or disable authentication requirements for the Unified Remote protocol, and leverage this now-unauthenticated access to run code of the attacker's choosing.
CVE-2024-32167 1 Oretnom23 1 Online Medicine Ordering System 2025-03-25 9.1 Critical
Sourcecodester Online Medicine Ordering System 1.0 is vulnerable to Arbitrary file deletion vulnerability as the backend settings have the function of deleting pictures to delete any files.
CVE-2022-43757 1 Suse 1 Rancher 2025-03-25 9.9 Critical
A Cleartext Storage of Sensitive Information vulnerability in SUSE Rancher allows users on managed clusters to gain access to credentials. The impact depends on the credentials exposed This issue affects: SUSE Rancher Rancher versions prior to 2.5.17; Rancher versions prior to 2.6.10; Rancher versions prior to 2.7.1.
CVE-2024-24300 1 4ipnet 2 Eap-767, Eap-767 Firmware 2025-03-25 9.8 Critical
4ipnet EAP-767 v3.42.00 is vulnerable to Incorrect Access Control. The device uses the same set of credentials, regardless of how many times a user logs in, the content of the cookie remains unchanged.
CVE-2023-0740 1 Answer 1 Answer 2025-03-25 9.0 Critical
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.
CVE-2024-30620 1 Tenda 2 Ax1803, Ax1803 Firmware 2025-03-25 9.8 Critical
Tenda AX1803 v1.0.0.1 contains a stack overflow via the serviceName parameter in the function fromAdvSetMacMtuWan.
CVE-2022-45527 1 Institutional Management Website Project 1 Institutional Management Website 2025-03-25 9.8 Critical
File upload vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows unauthorized attackers to directly upload malicious files to the courseimg directory.
CVE-2022-45526 1 Institutional Management Website Project 1 Institutional Management Website 2025-03-25 9.8 Critical
SQL Injection vulnerability in Future-Depth Institutional Management Website (IMS) 1.0, allows attackers to execute arbitrary commands via the ad parameter to /admin_area/login_transfer.php.
CVE-2023-0741 1 Answer 1 Answer 2025-03-25 9.0 Critical
Cross-site Scripting (XSS) - DOM in GitHub repository answerdev/answer prior to 1.0.4.
CVE-2023-0742 1 Answer 1 Answer 2025-03-25 9.0 Critical
Cross-site Scripting (XSS) - Stored in GitHub repository answerdev/answer prior to 1.0.4.
CVE-2023-0743 1 Answer 1 Answer 2025-03-25 9.0 Critical
Cross-site Scripting (XSS) - Generic in GitHub repository answerdev/answer prior to 1.0.4.
CVE-2023-0744 1 Answer 1 Answer 2025-03-25 9.8 Critical
Improper Access Control in GitHub repository answerdev/answer prior to 1.0.4.
CVE-2024-30635 1 Tenda 2 F1202, F1202 Firmware 2025-03-25 9.8 Critical
Tenda F1202 v1.2.0.20(408) has a stack overflow vulnerability located in the funcpara1 parameter in the formSetCfm function.
CVE-2024-3552 1 Salephpscripts 1 Web Directory Free 2025-03-25 9.8 Critical
The Web Directory Free WordPress plugin before 1.7.0 does not sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection with different techniques like UNION, Time-Based and Error-Based.
CVE-2023-52538 1 Huawei 2 Emui, Harmonyos 2025-03-25 9.1 Critical
Vulnerability of package name verification being bypassed in the HwIms module. Impact: Successful exploitation of this vulnerability will affect availability.
CVE-2022-45982 1 Thinkphp 1 Thinkphp 2025-03-25 9.8 Critical
thinkphp 6.0.0~6.0.13 and 6.1.0~6.1.1 contains a deserialization vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload.
CVE-2022-43550 2 Jitsi, Microsoft 2 Jitsi, Windows 2025-03-25 9.8 Critical
A command injection vulnerability exists in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 when launching browsers on Windows which could allow an attacker to insert an arbitrary URL which opens up the opportunity to remote execution.