Search Results (30648 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-57579 1 Tenda 2 Ac18, Ac18 Firmware 2025-03-19 9.8 Critical
Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the limitSpeedUp parameter in the formSetClientState function.
CVE-2024-43042 1 Pluck-cms 1 Pluck 2025-03-19 9.8 Critical
Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.
CVE-2024-38466 1 Guoxinled 1 Synthesis Image System 2025-03-19 9.8 Critical
Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.
CVE-2023-23459 2 Microsoft, Priority-software 2 Windows, Priority 2025-03-19 9.1 Critical
Priority Windows may allow Command Execution via SQL Injection using an unspecified method.
CVE-2025-29386 1 Tenda 2 Ac9, Ac9 Firmware 2025-03-19 9.8 Critical
In Tenda AC9 v1.0 V15.03.05.14_multi, the mac parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
CVE-2025-29385 1 Tenda 2 Ac9, Ac9 Firmware 2025-03-19 9.8 Critical
In Tenda AC9 v1.0 V15.03.05.14_multi, the cloneType parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
CVE-2025-29384 1 Tenda 2 Ac9, Ac9 Firmware 2025-03-19 9.8 Critical
In Tenda AC9 v1.0 V15.03.05.14_multi, the wanMTU parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, which can lead to remote arbitrary code execution.
CVE-2025-29031 1 Tenda 2 Ac6, Ac6 Firmware 2025-03-19 9.8 Critical
Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the fromAddressNat function.
CVE-2025-29030 1 Tenda 2 Ac6, Ac6 Firmware 2025-03-19 9.8 Critical
Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formWifiWpsOOB function.
CVE-2024-48428 1 Olivegroup 1 Olivevle 2025-03-19 9.8 Critical
An issue in Olive VLE allows an attacker to obtain sensitive information via the reset password function.
CVE-2023-23461 1 Libpeconv Project 1 Libpeconv 2025-03-19 9.8 Critical
Libpeconv – access violation, before commit b076013 (30/11/2022).
CVE-2023-23460 1 Priority-software 1 Priority 2025-03-19 9.1 Critical
Priority Web version 19.1.0.68, parameter manipulation on an unspecified end-point may allow authentication bypass.
CVE-2020-19825 1 Kimai 1 Kimai 2025-03-19 9.6 Critical
Cross Site Scripting (XSS) vulnerability in kevinpapst kimai2 1.30.0 in /src/Twig/Runtime/MarkdownExtension.php, allows attackers to gain escalated privileges.
CVE-2022-46892 1 Amperecomputing 4 Ampere Altra, Ampere Altra Firmware, Ampere Altra Max and 1 more 2025-03-19 9.8 Critical
In Ampere AltraMax and Ampere Altra before 2.10c, improper access controls allows the OS to reinitialize a disabled root complex.
CVE-2024-30163 1 Invisioncommunity 1 Invisioncommunity 2025-03-19 9.8 Critical
Invision Community before 4.7.16 allow SQL injection via the applications/nexus/modules/front/store/store.php IPS\nexus\modules\front\store\_store::_categoryView() method, where user input passed through the filter request parameter is not properly sanitized before being used to execute SQL queries. This can be exploited by unauthenticated attackers to carry out Blind SQL Injection attacks.
CVE-2023-25765 1 Jenkins 1 Email Extension 2025-03-19 9.9 Critical
In Jenkins Email Extension Plugin 2.93 and earlier, templates defined inside a folder were not subject to Script Security protection, allowing attackers able to define email templates in folders to bypass the sandbox protection and execute arbitrary code in the context of the Jenkins controller JVM.
CVE-2023-23462 1 Libpeconv Project 1 Libpeconv 2025-03-19 9.8 Critical
Libpeconv – integer overflow, before commit 75b1565 (30/11/2022).
CVE-2023-22855 1 Kardex 1 Kardex Control Center 2025-03-19 9.8 Critical
Kardex Mlog MCC 5.7.12+0-a203c2a213-master allows remote code execution. It spawns a web interface listening on port 8088. A user-controllable path is handed to a path-concatenation method (Path.Combine from .NET) without proper sanitisation. This yields the possibility of including local files, as well as remote files on SMB shares. If one provides a file with the extension .t4, it is rendered with the .NET templating engine mono/t4, which can execute code.
CVE-2024-43984 1 Podlove 1 Podlove Podcast Publisher 2025-03-19 9.6 Critical
Cross-Site Request Forgery (CSRF) vulnerability in Podlove Podlove Podcast Publisher allows Code Injection.This issue affects Podlove Podcast Publisher: from n/a through 4.1.13.
CVE-2023-23465 1 Mediacp 1 Media Control Panel 2025-03-19 9.1 Critical
Media CP Media Control Panel latest version. CSRF possible through unspecified endpoint.