Search Results (96448 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2022-41721 2 Golang, Redhat 5 H2c, Acm, Migration Toolkit Applications and 2 more 2025-04-04 7.5 High
A request smuggling attack is possible when using MaxBytesHandler. When using MaxBytesHandler, the body of an HTTP request is not fully consumed. When the server attempts to read HTTP2 frames from the connection, it will instead be reading the body of the HTTP request, which could be attacker-manipulated to represent arbitrary HTTP2 requests.
CVE-2022-21191 1 Global-modules-path Project 1 Global-modules-path 2025-04-04 7.4 High
Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the getPath function.
CVE-2023-48060 1 Iteachyou 1 Dreamer Cms 2025-04-04 8.8 High
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/task/add
CVE-2023-45904 1 Iteachyou 1 Dreamer Cms 2025-04-04 8.8 High
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /variable/update.
CVE-2023-45903 1 Iteachyou 1 Dreamer Cms 2025-04-04 8.8 High
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/label/delete.
CVE-2023-45901 1 Iteachyou 1 Dreamer Cms 2025-04-04 8.8 High
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin\/category\/add.
CVE-2023-45906 1 Iteachyou 1 Dreamer Cms 2025-04-04 8.8 High
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/user/add.
CVE-2023-46887 1 Iteachyou 1 Dreamer Cms 2025-04-04 7.5 High
In Dreamer CMS before 4.0.1, the backend attachment management office has an Arbitrary File Download vulnerability.
CVE-2023-45902 1 Iteachyou 1 Dreamer Cms 2025-04-04 8.8 High
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/attachment/delete.
CVE-2023-45907 1 Iteachyou 1 Dreamer Cms 2025-04-04 8.8 High
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/variable/delete.
CVE-2023-45905 1 Iteachyou 1 Dreamer Cms 2025-04-04 8.8 High
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/variable/add.
CVE-2023-48058 2 Dreamer Cms Project, Iteachyou 2 Dreamer Cms, Dreamer Cms 2025-04-04 8.8 High
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/task/run
CVE-2023-43856 1 Iteachyou 1 Dreamer Cms 2025-04-04 7.5 High
Dreamer CMS v4.1.3 was discovered to contain an arbitrary file read vulnerability via the component /admin/TemplateController.java.
CVE-2023-48017 1 Iteachyou 1 Dreamer Cms 2025-04-04 8.8 High
Dreamer_cms 4.1.3 is vulnerable to Cross Site Request Forgery (CSRF) via Add permissions to CSRF in Permission Management.
CVE-2024-30870 1 Netentsec 2 Ns-asg, Ns-asg Firmware 2025-04-04 8.8 High
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/address_interpret.php.
CVE-2024-30871 1 Netentsec 3 Application Security Gateway, Ns-asg, Ns-asg Firmware 2025-04-04 8.8 High
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /WebPages/applyhardware.php.
CVE-2024-34219 1 Totolink 2 Cp450, Cp450 Firmware 2025-04-04 8.6 High
TOTOLINK CP450 V4.1.0cu.747_B20191224 was discovered to contain a vulnerability in the SetTelnetCfg function, which allows attackers to log in through telnet.
CVE-2024-34308 1 Totolink 2 Lr350, Lr350 Firmware 2025-04-04 8.8 High
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a stack overflow via the password parameter in the function urldecode.
CVE-2024-34921 1 Totolink 2 X5000r, X5000r Firmware 2025-04-04 8.8 High
TOTOLINK X5000R v9.1.0cu.2350_B20230313 was discovered to contain a command injection via the disconnectVPN function.
CVE-2024-34942 1 Tenda 2 Fh1206, Fh1206 Firmware 2025-04-04 8.8 High
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the funcpara1 parameter at ip/goform/exeCommand.