Search Results (30640 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-0039 1 Google 1 Android 2025-03-13 9.8 Critical
In attp_build_value_cmd of att_protocol.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2024-52723 1 Totolink 2 X6000r, X6000r Firmware 2025-03-13 9.8 Critical
In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter filtering. An attacker can achieve arbitrary command execution by constructing the payload.
CVE-2024-46958 2 Linux, Nextcloud 2 Linux Kernel, Desktop 2025-03-13 9.1 Critical
In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or world readable. This is fixed in 3.13.4.
CVE-2024-37768 1 B1ackc4t 1 14finger 2025-03-13 9.1 Critical
14Finger v1.1 was discovered to contain an arbitrary user deletion vulnerability via the component /api/admin/user?id.
CVE-2024-31611 1 Seacms 1 Seacms 2025-03-13 9.1 Critical
SeaCMS 12.9 has a file deletion vulnerability via admin_template.php.
CVE-2024-30589 1 Tenda 2 Fh1202, Fh1202 Firmware 2025-03-13 9.8 Critical
Tenda FH1202 v1.2.0.14(408) firmware has a stack overflow vulnerability in the entrys parameter of the fromAddressNat function.
CVE-2024-30587 1 Tenda 2 Fh1202, Fh1202 Firmware 2025-03-13 9.8 Critical
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the urls parameter of the saveParentControlInfo function.
CVE-2024-30596 1 Tenda 2 Fh1202, Fh1202 Firmware 2025-03-13 9.8 Critical
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the formSetDeviceName function.
CVE-2024-30595 1 Tenda 2 Fh1202, Fh1202 Firmware 2025-03-13 9.8 Critical
Tenda FH1202 v1.2.0.14(408) has a stack overflow vulnerability in the deviceId parameter of the addWifiMacFilter function.
CVE-2024-52677 1 Hkcms 1 Hkcms 2025-03-13 9.8 Critical
HkCms <= v2.3.2.240702 is vulnerable to file upload in the getFileName method in /app/common/library/Upload.php.
CVE-2024-47485 1 Hikvision 2 Hikcentral Master, Hikcentral Master Lite 2025-03-13 9.8 Critical
There is a CSV injection vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could build malicious data to generate executable commands in the CSV file.
CVE-2024-42967 1 Totolink 2 Lr350, Lr350 Firmware 2025-03-13 9.8 Critical
Incorrect access control in TOTOLINK LR350 V9.3.5u.6369_B20220309 allows attackers to obtain the apmib configuration file, which contains the username and the password, via a crafted request to /cgi-bin/ExportSettings.sh.
CVE-2024-42008 1 Roundcube 1 Webmail 2025-03-13 9.3 Critical
A Cross-Site Scripting vulnerability in rcmail_action_mail_get->run() in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a malicious e-mail attachment served with a dangerous Content-Type header.
CVE-2024-46918 2 Misp, Misp-project 2 Misp, Misp 2025-03-13 9.8 Critical
app/Controller/UserLoginProfilesController.php in MISP before 2.4.198 does not prevent an org admin from viewing sensitive login fields of another org admin in the same org.
CVE-2024-30415 1 Huawei 2 Emui, Harmonyos 2025-03-13 9.1 Critical
Vulnerability of improper permission control in the window management module. Impact: Successful exploitation of this vulnerability will affect availability.
CVE-2023-52381 1 Huawei 2 Emui, Harmonyos 2025-03-13 9.8 Critical
Script injection vulnerability in the email module.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
CVE-2024-20997 1 Oracle 1 Hospitality Simphony 2025-03-13 9.9 Critical
Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Enterprise Server). Supported versions that are affected are 19.1.0-19.5.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality Simphony. While the vulnerability is in Oracle Hospitality Simphony, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Simphony. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
CVE-2024-52765 1 H3c 2 Gr-1800ax, Gr-1800ax Firmware 2025-03-13 9.8 Critical
H3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code execution (RCE) via the aspForm parameter.
CVE-2024-42947 1 Tenda 2 Fh1201, Fh1201 Firmware 2025-03-13 9.8 Critical
An issue in the handler function in /goform/telnet of Tenda FH1201 v1.2.0.14 (408) allows attackers to execute arbitrary commands via a crafted HTTP request.
CVE-2024-24117 1 Ruijie 2 Rg-nbs2009g-p, Rg-nbs2009g-p Firmware 2025-03-13 9.8 Critical
Insecure Permissions vulnerability in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release (9736) allows a remote attacker to gain privileges via the login check state component.