Search Results (328883 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-31121 1 Open-emr 1 Openemr 2025-05-07 5.4 Medium
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 7.0.3.1, the Patient Image feature in OpenEMR is vulnerable to cross-site scripting attacks via the EXIF title in an image. This vulnerability is fixed in 7.0.3.1.
CVE-2024-28216 1 Naver 1 Ngrinder 2025-05-07 5.4 Medium
nGrinder before 3.5.9 allows an attacker to obtain the results of webhook requests due to lack of access control, which could be the cause of information disclosure and limited Server-Side Request Forgery.
CVE-2024-28215 1 Naver 1 Ngrinder 2025-05-07 7.5 High
nGrinder before 3.5.9 allows an attacker to create or update webhook configuration due to lack of access control, which could be the cause of information disclosure and limited Server-Side Request Forgery.
CVE-2024-28214 1 Naver 1 Ngrinder 2025-05-07 2.7 Low
nGrinder before 3.5.9 allows to set delay without limitation, which could be the cause of Denial of Service by remote attacker.
CVE-2024-28213 1 Naver 1 Ngrinder 2025-05-07 9.8 Critical
nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote attacker to execute arbitrary code via unsafe Java objects deserialization.
CVE-2024-28212 1 Naver 1 Ngrinder 2025-05-07 9.8 Critical
nGrinder before 3.5.9 uses old version of SnakeYAML, which could allow remote attacker to execute arbitrary code via unsafe deserialization.
CVE-2024-28211 1 Naver 1 Ngrinder 2025-05-07 9.8 Critical
nGrinder before 3.5.9 allows connection to malicious JMX/RMI server by default, which could be the cause of executing arbitrary code via RMI registry by remote attacker.
CVE-2024-51328 2 Projectworlds, Travel Management System Project 2 Travel Management System, Travel Management System 2025-05-07 6.1 Medium
Cross Site Scripting vulnerability in addcategory.php in projectworld's Travel Management System v1.0 allows remote attacker to inject arbitrary code via the t2 parameter.
CVE-2024-50996 1 Netgear 9 R6400 Firmware, R6400v2, R6400v2 Firmware and 6 more 2025-05-07 5.7 Medium
Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the bpa_server parameter at genie_bpa.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
CVE-2024-51003 1 Netgear 9 R6400 Firmware, R6400v2, R6400v2 Firmware and 6 more 2025-05-07 5.7 Medium
Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to multiple stack overflow vulnerabilities in the component ap_mode.cgi via the apmode_dns1_pri and apmode_dns1_sec parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request.
CVE-2025-2778 2025-05-07 N/A
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-20671 2 Google, Mediatek 11 Android, Mt2718, Mt6878 and 8 more 2025-05-07 6.4 Medium
In thermal, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09698599; Issue ID: MSV-3228.
CVE-2025-20668 2 Google, Mediatek 8 Android, Mt6878, Mt6897 and 5 more 2025-05-07 6.7 Medium
In scp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS09625562; Issue ID: MSV-3027.
CVE-2022-43231 1 Canteen Management System Project 1 Canteen Management System 2025-05-07 7.2 High
Canteen Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via /youthappam/manage_website.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
CVE-2022-43230 1 Simple Cold Storage Management System Project 1 Simple Cold Storage Managment System 2025-05-07 7.2 High
Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/?page=bookings/view_details.
CVE-2022-43229 1 Simple Cold Storage Management System Project 1 Simple Cold Storage Managment System 2025-05-07 7.2 High
Simple Cold Storage Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /bookings/update_status.php.
CVE-2022-43228 1 Barangay Management System Project 1 Barangay Management System 2025-05-07 7.2 High
Barangay Management System v1.0 was discovered to contain a SQL injection vulnerability via the hidden_id parameter at /clearance/clearance.php.
CVE-2022-43170 1 Rukovoditel 1 Rukovoditel 2025-05-07 5.4 Medium
A stored cross-site scripting (XSS) vulnerability in the Dashboard Configuration feature (index.php?module=dashboard_configure/index) of Rukovoditel v3.2.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter after clicking "Add info block".
CVE-2022-42189 1 Emlog 1 Emlog 2025-05-07 7.2 High
Emlog Pro 1.6.0 plugins upload suffers from a remote code execution (RCE) vulnerability.
CVE-2022-41575 1 Gradle 1 Enterprise 2025-05-07 7.5 High
A credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3.3 allows remote attackers to access a subset of application data (e.g., cleartext credentials). This is fixed in 2022.3.3.