Search Results (95844 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-28663 1 Formidablepro2pdf 1 Formidable Pro2pdf 2025-02-25 8.8 High
The Formidable PRO2PDF WordPress Plugin, version < 3.11, is affected by an authenticated SQL injection vulnerability in the ‘fieldmap’ parameter in the fpropdf_export_file action.
CVE-2023-28659 1 Plugin 1 Waiting 2025-02-25 8.8 High
The Waiting: One-click Countdowns WordPress Plugin, version <= 0.6.2, is affected by an authenticated SQL injection vulnerability in the pbc_down[meta][id] parameter of the pbc_save_downs action.
CVE-2023-27079 1 Tenda 2 G103, G103 Firmware 2025-02-25 7.5 High
Command Injection vulnerability found in Tenda G103 v.1.0.05 allows an attacker to obtain sensitive information via a crafted package
CVE-2023-27077 1 360 2 D901, D901 Firmware 2025-02-25 7.5 High
Stack Overflow vulnerability found in 360 D901 allows a remote attacker to cause a Distributed Denial of Service (DDOS) via a crafted HTTP package.
CVE-2023-1580 1 Devolutions 1 Devolutions Gateway 2025-02-25 7.5 High
Uncontrolled resource consumption in the logging feature in Devolutions Gateway 2023.1.1 and earlier allows an attacker to cause a denial of service by filling up the disk and render the system unusable.
CVE-2020-19786 1 Cszcms 1 Csz Cms 2025-02-25 8.8 High
File upload vulnerability in CSKaza CSZ CMS v.1.2.2 fixed in v1.2.4 allows attacker to execute aritrary commands and code via crafted PHP file.
CVE-2025-1538 1 Dlink 2 Dap-1320, Dap-1320 Firmware 2025-02-25 8.8 High
A vulnerability classified as critical was found in D-Link DAP-1320 1.00. Affected by this vulnerability is the function set_ws_action of the file /dws/api/. The manipulation leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2025-0916 1 Yaycommerce 1 Yaysmtp 2025-02-25 7.2 High
The YaySMTP and Email Logs: Amazon SES, SendGrid, Outlook, Mailgun, Brevo, Google and Any SMTP Service plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 2.4.9 to 2.6.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Note: The vulnerability has been initially patched in version 2.4.8 and was reintroduced in version 2.4.9 with the removal of the wp_kses_post() built-in WordPress sanitization function.
CVE-2024-45421 1 Zoom 7 Meeting Software Development Kit, Rooms, Rooms Controller and 4 more 2025-02-25 8.5 High
Buffer overflow in some Zoom Apps may allow an authenticated user to conduct an escalation of privilege via network access.
CVE-2023-28759 1 Veritas 1 Netbackup 2025-02-25 7.8 High
An issue was discovered in Veritas NetBackup before 10.0 on Windows. A vulnerability in the way the client validates the path to a DLL prior to loading may allow a lower-level user to elevate privileges and compromise the system.
CVE-2023-28758 1 Veritas 1 Netbackup 2025-02-25 7.1 High
An issue was discovered in Veritas NetBackup before 8.3.0.2. BPCD allows an unprivileged user to specify a log file path when executing a NetBackup command. This can be used to overwrite existing NetBackup log files.
CVE-2023-28676 1 Jenkins 1 Convert To Pipeline 2025-02-25 8.8 High
A cross-site request forgery (CSRF) vulnerability in Jenkins Convert To Pipeline Plugin 1.0 and earlier allows attackers to create a Pipeline based on a Freestyle project, potentially leading to remote code execution (RCE).
CVE-2023-27871 2 Ibm, Linux 2 Aspera Faspex, Linux Kernel 2025-02-25 7.5 High
IBM Aspera Faspex 4.4.2 could allow a remote attacker to obtain sensitive credential information for an external user, using a specially crafted SQL query. IBM X-Force ID: 249613.
CVE-2023-26114 1 Coder 1 Code-server 2025-02-25 8.2 High
Versions of the package code-server before 4.10.1 are vulnerable to Missing Origin Validation in WebSockets handshakes. Exploiting this vulnerability can allow an adversary in specific scenarios to access data from and connect to the code-server instance.
CVE-2023-1578 1 Pimcore 1 Pimcore 2025-02-25 8.8 High
SQL Injection in GitHub repository pimcore/pimcore prior to 10.5.19.
CVE-2025-0842 1 Needyamin 1 Library Card System 2025-02-25 7.3 High
A vulnerability was found in needyamin Library Card System 1.0 and classified as critical. This issue affects some unknown processing of the file admin.php of the component Login. The manipulation of the argument email/password leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-36259 1 Odoo 1 Odoo 2025-02-25 7.5 High
Improper access control in mail module of Odoo Community 17.0 and Odoo Enterprise 17.0 allows remote authenticated attackers to extract sensitive information via an oracle-based (yes/no response) crafted attack.
CVE-2025-23046 1 Glpi-project 1 Glpi 2025-02-25 7.5 High
GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to version 10.0.18, if a "Mail servers" authentication provider is configured to use an Oauth connection provided by the OauthIMAP plugin, anyone can connect to GLPI using a user name on which an Oauth authorization has already been established. Version 10.0.18 contains a patch. As a workaround, one may disable any "Mail servers" authentication provider configured to use an Oauth connection provided by the OauthIMAP plugin.
CVE-2023-1605 1 Radare 1 Radare2 2025-02-25 7.5 High
Denial of Service in GitHub repository radareorg/radare2 prior to 5.8.6.
CVE-2024-12368 1 Odoo 1 Odoo 2025-02-25 8.1 High
Improper access control in the auth_oauth module of Odoo Community 15.0 and Odoo Enterprise 15.0 allows an internal user to export the OAuth tokens of other users.