Search Results (97629 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-24334 1 Rt-thread 1 Rt-thread 2025-04-30 8.4 High
A heap buffer overflow occurs in dfs_v2 dfs_file in RT-Thread through 5.0.2.
CVE-2024-23722 2 Fluent, Treasuredata 2 Fluent Bit, Fluent Bit 2025-04-30 7.5 High
In Fluent Bit 2.1.8 through 2.2.1, a NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-urlencoded. It crashes and does not restart. This could result in logs not being delivered properly.
CVE-2024-32391 1 Maccms 1 Maccms 2025-04-30 7.3 High
Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload.
CVE-2024-29434 1 Alldata 1 Alldata 2025-04-30 8.3 High
An issue in the system image upload interface of Alldata v0.4.6 allows attackers to execute a directory traversal when uploading a file.
CVE-2025-30093 1 Wisc 1 Htcondor 2025-04-30 8.1 High
HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, and 24.6.x before 24.6.1 allows authenticated attackers to bypass authorization restrictions.
CVE-2024-57519 1 Open5gs 1 Open5gs 2025-04-30 7.5 High
An issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in lib/dbi/subscription.c file.
CVE-2024-42991 1 Mingsoft 1 Mcms 2025-04-30 8.1 High
MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.
CVE-2024-20057 2 Google, Mediatek 38 Android, Mt6761, Mt6765 and 35 more 2025-04-30 7.2 High
In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08587881; Issue ID: ALPS08587881.
CVE-2025-29017 1 Codeastro 1 Internet Banking System 2025-04-30 8.8 High
A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the profile_pic parameter within pages_view_client.php.
CVE-2024-37765 1 Machform 1 Machform 2025-04-30 8.8 High
Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.
CVE-2024-48951 1 Logpoint 2 Logpoint, Siem 2025-04-30 7.5 High
An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoint's API Token leading to authentication bypass.
CVE-2024-48953 1 Logpoint 2 Logpoint, Siem 2025-04-30 7.5 High
An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed unauthenticated users to register their own authentication plugins in Logpoint, resulting in unauthorized access.
CVE-2021-25966 1 Orchardcore 1 Orchard Core 2025-04-30 8.8 High
In “Orchard core CMS” application, versions 1.0.0-beta1-3383 to 1.0.0 are vulnerable to an improper session termination after password change. When a password has been changed by the user or by an administrator, a user that was already logged in, will still have access to the application even after the password was changed.
CVE-2024-44739 2 Oretnom23, Sourcecodester 2 Simple Forum Website, Simple Forum Website 2025-04-30 8.8 High
Sourcecodester Simple Forum Website v1.0 has a SQL injection vulnerability in /php-sqlite-forum/?page=manage_user&id=.
CVE-2024-52945 1 Veritas 1 Netbackup 2025-04-30 7.8 High
An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup components running on a Windows Operating System. If a user executes specific NetBackup commands or an attacker uses social engineering techniques to impel the user to execute the commands, a malicious DLL could be loaded, resulting in execution of the attacker's code in the user's security context.
CVE-2024-52920 1 Bitcoin 1 Bitcoin Core 2025-04-30 7.5 High
Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (infinite loop) via a malformed GETDATA message.
CVE-2024-52916 1 Bitcoin 1 Bitcoin Core 2025-04-30 7.5 High
Bitcoin Core before 0.15.0 allows a denial of service (OOM kill of a daemon process) via a flood of minimum difficulty headers.
CVE-2024-52915 1 Bitcoin 1 Bitcoin Core 2025-04-30 7.5 High
Bitcoin Core before 0.20.0 allows remote attackers to cause a denial of service (memory consumption) via a crafted INV message.
CVE-2024-52914 1 Bitcoin 1 Bitcoin Core 2025-04-30 7.5 High
In Bitcoin Core before 0.18.0, a node could be stalled for hours when processing the orphans of a crafted unconfirmed transaction.
CVE-2022-43780 1 Hp 82 M2u75a, M2u75a Firmware, M2u76a and 79 more 2025-04-30 7.5 High
Certain HP ENVY, OfficeJet, and DeskJet printers may be vulnerable to a Denial of Service attack.