Search Results (96461 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-4722 1 Ikus-soft 1 Rdiffweb 2025-04-09 7.2 High
Authentication Bypass by Primary Weakness in GitHub repository ikus060/rdiffweb prior to 2.5.5.
CVE-2022-4688 1 Usememos 1 Memos 2025-04-09 8.8 High
Improper Authorization in GitHub repository usememos/memos prior to 0.9.0.
CVE-2023-5457 1 Ailux 1 Imx6 2025-04-09 7.5 High
A CWE-1269 “Product Released in Non-Release Configuration” vulnerability in the Django web framework used by the web application (due to the “debug” configuration parameter set to “True”) allows a remote unauthenticated attacker to access critical information and have other unspecified impacts to the confidentiality, integrity, and availability of the application. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.
CVE-2022-4687 1 Usememos 1 Memos 2025-04-09 8.1 High
Incorrect Use of Privileged APIs in GitHub repository usememos/memos prior to 0.9.0.
CVE-2022-4684 1 Usememos 1 Memos 2025-04-09 8.8 High
Improper Access Control in GitHub repository usememos/memos prior to 0.9.0.
CVE-2025-3137 1 Phpgurukul 1 Online Security Guards Hiring System 2025-04-09 7.3 High
A vulnerability, which was classified as critical, was found in PHPGurukul Online Security Guards Hiring System 1.0. Affected is an unknown function of the file /admin/changeimage.php. The manipulation of the argument editid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-3138 1 Phpgurukul 1 Online Security Guards Hiring System 2025-04-09 7.3 High
A vulnerability has been found in PHPGurukul Online Security Guards Hiring System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/edit-guard-detail.php. The manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2022-4043 1 Wp Custom Admin Interface Project 1 Wp Custom Admin Interface 2025-04-09 7.2 High
The WP Custom Admin Interface WordPress plugin before 7.29 unserialize user input provided via the settings, which could allow high privilege users such as admin to perform PHP Object Injection when a suitable gadget is present.
CVE-2022-47976 1 Huawei 2 Emui, Harmonyos 2025-04-09 7.5 High
The DMSDP module of the distributed hardware has a vulnerability that may cause imposter control connections.Successful exploitation of this vulnerability may disconnect normal service connections.
CVE-2022-47975 1 Huawei 2 Emui, Harmonyos 2025-04-09 7.5 High
The DUBAI module has a double free vulnerability. Successful exploitation of this vulnerability may affect system availability.
CVE-2022-40520 1 Qualcomm 294 Apq8064au, Apq8064au Firmware, Apq8096au and 291 more 2025-04-09 8.4 High
Memory corruption due to stack-based buffer overflow in Core
CVE-2022-3417 1 Bravenewcode 1 Wptouch 2025-04-09 8.8 High
The WPtouch WordPress plugin before 4.3.45 unserialises the content of an imported settings file, which could lead to PHP object injections issues when an user import (intentionally or not) a malicious settings file and a suitable gadget chain is present on the blog.
CVE-2022-3416 1 Bravenewcode 1 Wptouch 2025-04-09 7.2 High
The WPtouch WordPress plugin before 4.3.45 does not properly validate images to be uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)
CVE-2022-33276 1 Qualcomm 268 Ar8035, Ar8035 Firmware, Ar9380 and 265 more 2025-04-09 8.4 High
Memory corruption due to buffer copy without checking size of input in modem while receiving WMI_REQUEST_STATS_CMDID command.
CVE-2022-33274 1 Qualcomm 22 Qam8295p, Qam8295p Firmware, Qca6574au and 19 more 2025-04-09 8.4 High
Memory corruption in android core due to improper validation of array index while returning feature ids after license authentication.
CVE-2022-33253 1 Qualcomm 322 Aqt1000, Aqt1000 Firmware, Ar8035 and 319 more 2025-04-09 7.5 High
Transient DOS due to buffer over-read in WLAN while parsing corrupted NAN frames.
CVE-2022-33252 1 Qualcomm 322 Aqt1000, Aqt1000 Firmware, Ar8035 and 319 more 2025-04-09 8.2 High
Information disclosure due to buffer over-read in WLAN while handling IBSS beacons frame.
CVE-2022-33218 1 Qualcomm 48 Apq8064au, Apq8064au Firmware, Apq8096au and 45 more 2025-04-09 8.2 High
Memory corruption in Automotive due to improper input validation.
CVE-2022-25746 1 Qualcomm 196 Aqt1000, Aqt1000 Firmware, Ar8035 and 193 more 2025-04-09 8.1 High
Memory corruption in kernel due to missing checks when updating the access rights of a memextent mapping.
CVE-2022-3679 1 Kadencewp 1 Starter Templates 2025-04-09 8.8 High
The Starter Templates by Kadence WP WordPress plugin before 1.2.17 unserialises the content of an imported file, which could lead to PHP object injection issues when an admin import (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.