Search

Search Results (320187 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-27034 1 Qualcomm 227 315 5g Iot Modem, 315 5g Iot Modem Firmware, Ar8035 and 224 more 2025-11-28 9.8 Critical
Memory corruption while selecting the PLMN from SOR failed list.
CVE-2025-34236 1 Advantech 2 Webaccess/vpn, Webaccess\/vpn 2025-11-28 5.4 Medium
Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via NetworksController.addNetworkAction(). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
CVE-2025-34237 1 Advantech 2 Webaccess/vpn, Webaccess\/vpn 2025-11-28 5.4 Medium
Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via StandaloneVpnClientsController.addStandaloneVpnClientAction(). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
CVE-2025-52584 1 Ashlar 5 Argon, Cobalt, Cobalt Share and 2 more 2025-11-28 7.8 High
In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing XE files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
CVE-2025-46269 1 Ashlar 5 Argon, Cobalt, Cobalt Share and 2 more 2025-11-28 7.8 High
In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing VC6 files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
CVE-2025-53705 1 Ashlar 5 Argon, Cobalt, Cobalt Share and 2 more 2025-11-28 7.8 High
In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing CO files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
CVE-2025-41392 1 Ashlar 5 Argon, Cobalt, Cobalt Share and 2 more 2025-11-28 7.8 High
In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing AR files. This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
CVE-2025-34111 1 Tiki 1 Tikiwiki Cms\/groupware 2025-11-28 9.8 Critical
An unauthenticated arbitrary file upload vulnerability exists in Tiki Wiki CMS Groupware version 15.1 and earlier via the ELFinder component's default connector (connector.minimal.php), which allows remote attackers to upload and execute malicious PHP scripts in the context of the web server. The vulnerable component does not enforce file type validation, allowing attackers to craft a POST request to upload executable PHP payloads through the ELFinder interface exposed at /vendor_extra/elfinder/.
CVE-2025-21465 1 Qualcomm 699 315 5g Iot Modem, 315 5g Iot Modem Firmware, 9205 Lte Modem and 696 more 2025-11-28 6.5 Medium
Information disclosure while processing the hash segment in an MBN file.
CVE-2025-21464 1 Qualcomm 685 315 5g Iot Modem, 315 5g Iot Modem Firmware, 9205 Lte Modem and 682 more 2025-11-28 6.5 Medium
Information disclosure while reading data from an image using specified offset and size parameters.
CVE-2025-65085 1 Ashlar 5 Argon, Cobalt, Cobalt Share and 2 more 2025-11-28 9.8 Critical
A Heap-based Buffer Overflow vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.207 and prior that could allow an attacker to disclose information or execute arbitrary code.
CVE-2025-65084 1 Ashlar 5 Argon, Cobalt, Cobalt Share and 2 more 2025-11-28 9.8 Critical
An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.207 and prior that could allow an attacker to disclose information or execute arbitrary code.
CVE-2025-21463 1 Qualcomm 422 Ar8035, Ar8035 Firmware, Csr8811 and 419 more 2025-11-28 7.5 High
Transient DOS while processing the EHT operation IE in the received beacon frame.
CVE-2024-53026 1 Qualcomm 468 205 Mobile Platform, 205 Mobile Platform Firmware, 215 Mobile Platform and 465 more 2025-11-28 8.2 High
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
CVE-2025-34113 1 Tiki 1 Tikiwiki Cms\/groupware 2025-11-28 N/A
An authenticated command injection vulnerability exists in Tiki Wiki CMS versions ≤14.1, ≤12.4 LTS, ≤9.10 LTS, and ≤6.14 via the `viewmode` GET parameter in `tiki-calendar.php`. When the calendar module is enabled and an authenticated user has permission to access it, an attacker can inject and execute arbitrary PHP code. Successful exploitation leads to remote code execution in the context of the web server user.
CVE-2024-53021 1 Qualcomm 450 205 Mobile Platform, 205 Mobile Platform Firmware, 215 Mobile Platform and 447 more 2025-11-28 8.2 High
Information disclosure may occur while processing goodbye RTCP packet from network.
CVE-2025-60917 2 Austrian Archaeological Institute, Craws 2 Openatlas, Openatlas 2025-11-28 4.6 Medium
A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the color parameter.
CVE-2025-60916 2 Austrian Archaeological Institute, Craws 2 Openatlas, Openatlas 2025-11-28 5.4 Medium
A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload into the charge parameter.
CVE-2025-60915 2 Austrian Archaeological Institute, Craws 2 Openatlas, Openatlas 2025-11-28 8.1 High
An issue in the size query parameter (/views/file.py) of Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to execute a path traversal via a crafted request.
CVE-2025-60914 2 Austrian Archaeological Institute, Craws 2 Openatlas, Openatlas 2025-11-28 4.6 Medium
Incorrect access control in Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to access sensitive information via sending a crafted GET request to the /display_logo endpoint.