Search Results (328883 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-4226 1 Octopus 1 Octopus Server 2025-06-27 3.5 Low
It was identified that in certain versions of Octopus Server, that a user created with no permissions could view all users, user roles and permissions. This functionality was removed in versions of Octopus Server after the fixed versions listed.
CVE-2024-24818 1 Espocrm 1 Espocrm 2025-06-27 5.9 Medium
EspoCRM is an Open Source Customer Relationship Management software. An attacker can inject arbitrary IP or domain in "Password Change" page and redirect victim to malicious page that could lead to credential stealing or another attack. This vulnerability is fixed in 8.1.2.
CVE-2024-28640 1 Totolink 4 A7000r, A7000r Firmware, X5000r and 1 more 2025-06-27 7.5 High
Buffer Overflow vulnerability in TOTOLink X5000R V9.1.0u.6118-B20201102 and A7000R V9.1.0u.6115-B20201022 allows a remote attacker to cause a denial of service (D0S) via the command field.
CVE-2024-2241 1 Devolutions 1 Workspace 2025-06-27 6.3 Medium
Improper access control in the user interface in Devolutions Workspace 2024.1.0 and earlier allows an authenticated user to perform unintended actions via specific permissions
CVE-2022-36263 2 Logitech, Microsoft 2 Streamlabs Desktop, Windows 2025-06-27 7.3 High
StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe. An attacker can execute arbitrary code via a crafted .exe file.
CVE-2024-1316 1 Liquidweb 1 Event Tickets 2025-06-27 6.5 Medium
The Event Tickets and Registration WordPress plugin before 5.8.1, Events Tickets Plus WordPress plugin before 5.9.1 does not prevent users with at least the contributor role from leaking the existence of certain events they shouldn't have access to. (e.g. draft, private, pending review, pw-protected, and trashed events).
CVE-2025-32642 2 Appsbd, Wordpress 2 Vite Coupon Plugin, Wordpress 2025-06-27 10 Critical
Cross-Site Request Forgery (CSRF) vulnerability in appsbd Vite Coupon allows Remote Code Inclusion. This issue affects Vite Coupon: from n/a through 1.0.7.
CVE-2025-32660 2 Joomsky, Wordpress 2 Js Job Manager, Wordpress 2025-06-27 10 Critical
Unrestricted Upload of File with Dangerous Type vulnerability in JoomSky JS Job Manager allows Upload a Web Shell to a Web Server. This issue affects JS Job Manager: from n/a through 2.0.2.
CVE-2025-36535 1 Automationdirect 1 Mb Gateway 2025-06-27 10 Critical
The embedded web server lacks authentication and access controls, allowing unrestricted remote access. This could lead to configuration changes, operational disruption, or arbitrary code execution depending on the environment and exposed functionality.
CVE-2025-39380 2 Hospital Management System, Wordpress 2 Hospital Management System, Wordpress 2025-06-27 10 Critical
Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management System allows Upload a Web Shell to a Web Server.This issue affects Hospital Management System: from n/a through 47.0(20-11-2023).
CVE-2025-39401 2 Mojoomla, Wordpress 2 Wpams Plugin, Wordpress 2025-06-27 10 Critical
Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla WPAMS allows Upload a Web Shell to a Web Server.This issue affects WPAMS: from n/a through 44.0 (17-08-2023).
CVE-2025-39402 2 Mojoomla, Wordpress 2 Wpams Plugin, Worpress 2025-06-27 9.9 Critical
Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla WPAMS allows Upload a Web Shell to a Web Server.This issue affects WPAMS: from n/a through 44.0 (17-08-2023).
CVE-2025-46616 1 Quantum 1 Stornext 2025-06-27 9.9 Critical
Quantum StorNext Web GUI API before 7.2.4 allows potential Arbitrary Remote Code Execution (RCE) via upload of a file. This affects StorNext RYO before 7.2.4, StorNext Xcellis Workflow Director before 7.2.4, and ActiveScale Cold Storage.
CVE-2025-47641 1 Woocommerce 1 Woocommerce 2025-06-27 10 Critical
Unrestricted Upload of File with Dangerous Type vulnerability in printcart Printcart Web to Print Product Designer for WooCommerce allows Upload a Web Shell to a Web Server. This issue affects Printcart Web to Print Product Designer for WooCommerce: from n/a through 2.3.8.
CVE-2025-47663 3 Hospital Management System, Hospital Management System Project, Wordpress 3 Hospital Management System, Hospital Management System, Wordpress 2025-06-27 9.9 Critical
Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management System allows Upload a Web Shell to a Web Server. This issue affects Hospital Management System: from 47.0(20 through 11.
CVE-2025-40585 1 Siemens 2 Energy Services, G5dfr 2025-06-27 9.9 Critical
A vulnerability has been identified in Energy Services (All versions with G5DFR). Affected solutions using G5DFR contain default credentials. This could allow an attacker to gain control of G5DFR component and tamper with outputs from the device.
CVE-2025-48123 2 Woocommerce, Wordpress 2 Woocommerce, Wordpress 2025-06-27 10 Critical
Improper Control of Generation of Code ('Code Injection') vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light allows Code Injection. This issue affects Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light: from n/a through 2.4.37.
CVE-2025-32291 2 Fantasticplugins, Wordpress 2 Sumo Affiliates Pro, Wordpress 2025-06-27 10 Critical
Unrestricted Upload of File with Dangerous Type vulnerability in FantasticPlugins SUMO Affiliates Pro allows Using Malicious Files. This issue affects SUMO Affiliates Pro: from n/a through 10.7.0.
CVE-2025-48140 2 Metalpriceapi, Wordpress 2 Metalpriceapi, Wordpress 2025-06-27 9.9 Critical
Improper Control of Generation of Code ('Code Injection') vulnerability in metalpriceapi MetalpriceAPI allows Code Injection. This issue affects MetalpriceAPI: from n/a through 1.1.4.
CVE-2025-29902 2 Rts, Telex 2 Vlink Virtual Matrix Software, Remote Dispatch Console Server 2025-06-27 10 Critical
Remote code execution that allows unauthorized users to execute arbitrary code on the server machine.