Search Results (30648 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-33949 1 Wms Project 1 Wms 2025-03-18 9.8 Critical
An issue in FeMiner WMS v1.1 allows attackers to execute arbitrary code via the filename parameter and the exec function.
CVE-2021-33948 1 Hotels Server Project 1 Hotels Server 2025-03-18 9.8 Critical
SQL injection vulnerability in FantasticLBP Hotels Server v1.0 allows attacker to execute arbitrary code via the username parameter.
CVE-2021-33391 2 Htacg, Linux 2 Tidy, Linux Kernel 2025-03-18 9.8 Critical
An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in gdoc.c.
CVE-2021-33226 1 Saltstack 1 Salt 2025-03-18 9.8 Critical
Buffer Overflow vulnerability in Saltstack v.3003 and before allows attacker to execute arbitrary code via the func variable in salt/salt/modules/status.py file. NOTE: this is disputed by third parties because an attacker cannot influence the eval input
CVE-2022-35583 1 Wkhtmltopdf 1 Wkhtmltopdf 2025-03-18 9.8 Critical
wkhtmlTOpdf 0.12.6 is vulnerable to SSRF which allows an attacker to get initial access into the target's system by injecting iframe tag with initial asset IP address on it's source. This allows the attacker to takeover the whole infrastructure by accessing their internal assets.
CVE-2025-29029 1 Tenda 2 Ac6, Ac6 Firmware 2025-03-18 9.8 Critical
Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formSetSpeedWan function.
CVE-2024-57035 1 Wegia 1 Wegia 2025-03-18 9.8 Critical
WeGIA v3.2.0 is vulnerable to SQL Injection viathe nextPage parameter in /controle/control.php.
CVE-2023-49109 1 Apache 1 Dolphinscheduler 2025-03-18 9.8 Critical
Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue.
CVE-2023-24221 1 Luckyframe 1 Luckyframeweb 2025-03-18 9.8 Critical
LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/DeptMapper.xml.
CVE-2023-24220 1 Luckyframe 1 Luckyframeweb 2025-03-18 9.8 Critical
LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/RoleMapper.xml.
CVE-2023-24219 1 Luckyframe 1 Luckyframeweb 2025-03-18 9.8 Critical
LuckyframeWEB v3.5 was discovered to contain a SQL injection vulnerability via the dataScope parameter at /system/UserMapper.xml.
CVE-2023-23279 1 Canteen Management System Project 1 Canteen Management System 2025-03-18 9.8 Critical
Canteen Management System 1.0 is vulnerable to SQL Injection via /php_action/getOrderReport.php.
CVE-2022-40021 1 Qvidium 2 Amino A140, Amino A140 Firmware 2025-03-18 9.8 Critical
QVidium Technologies Amino A140 (prior to firmware version 1.0.0-283) was discovered to contain a command injection vulnerability.
CVE-2021-35261 1 Bearadmin Project 1 Bearadmin 2025-03-18 9.8 Critical
File Upload Vulnerability in Yupoxion BearAdmin before commit 10176153528b0a914eb4d726e200fd506b73b075 allows attacker to execute arbitrary remote code via the Upfile function of the extend/tools/Ueditor endpoint.
CVE-2021-34182 1 Ttyd Project 1 Ttyd 2025-03-18 9.8 Critical
An issue in ttyd v.1.6.3 allows attacker to execute arbitrary code via default configuration permissions.
CVE-2025-25746 1 Dlink 2 Dir-853, Dir-853 Firmware 2025-03-18 9.8 Critical
D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password parameter in the SetWanSettings module.
CVE-2024-57602 1 Easyappointments 1 Easyappointments 2025-03-18 9.8 Critical
An issue in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to escalate privileges via the index.php file.
CVE-2022-48337 3 Debian, Gnu, Redhat 4 Debian Linux, Emacs, Enterprise Linux and 1 more 2025-03-18 9.8 Critical
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the etags program. For example, a victim may use the "etags -u *" command (suggested in the etags documentation) in a situation where the current working directory has contents that depend on untrusted input.
CVE-2022-48329 1 Misp-project 1 Misp 2025-03-18 9.8 Critical
MISP before 2.4.166 unsafely allows users to use the order parameter, related to app/Model/Attribute.php, app/Model/GalaxyCluster.php, app/Model/Workflow.php, and app/Plugin/Assets/models/behaviors/LogableBehavior.php.
CVE-2022-40347 1 Intern Record System Project 1 Intern Record System 2025-03-18 9.8 Critical
SQL Injection vulnerability in Intern Record System version 1.0 in /intern/controller.php in 'phone', 'email', 'deptType' and 'name' parameters, allows attackers to execute arbitrary code and gain sensitive information.