Search Results (328094 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-42585 1 Siamonhasan 1 Warehouse Inventory System 2025-05-01 8.8 High
A Cross-Site Request Forgery (CSRF) in the component delete_media.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
CVE-2024-42578 2 Oswapp, Siamonhasan 2 Warehouse Inventory System, Warehouse Inventory System 2025-05-01 8 High
A Cross-Site Request Forgery (CSRF) in the component edit_product.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
CVE-2024-42576 1 Siamonhasan 1 Warehouse Inventory System 2025-05-01 8.8 High
A Cross-Site Request Forgery (CSRF) in the component edit_categorie.php of Warehouse Inventory System v2.0 allows attackers to escalate privileges.
CVE-2025-28145 1 Edimax 2 Br-6478ac V3, Br-6478ac V3 Firmware 2025-05-01 6.5 Medium
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3 1.0.15 was discovered to contain a command injection vulnerability via partition in /boafrm/formDiskFormat.
CVE-2025-28143 1 Edimax 2 Br-6478ac V3, Br-6478ac V3 Firmware 2025-05-01 6.5 Medium
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the groupname at the /boafrm/formDiskCreateGroup.
CVE-2025-28142 1 Edimax 2 Br-6478ac V3, Br-6478ac V3 Firmware 2025-05-01 6.5 Medium
Edimax AC1200 Wave 2 Dual-Band Gigabit Router BR-6478AC V3_1.0.15 was discovered to contain a command injection vulnerability via the foldername in /boafrm/formDiskCreateShare.
CVE-2024-52884 1 Audiocodes 1 Mediant Session Border Controller 2025-05-01 7.5 High
An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841. Due to the use of weak password obfuscation/encryption, an attacker with access to configuration exports (INI) is able to decrypt the passwords.
CVE-2024-0855 1 Spiffyplugins 1 Spiffy Calendar 2025-05-01 5.3 Medium
The Spiffy Calendar WordPress plugin before 4.9.9 doesn't check the event_author parameter, and allows any user to alter it when creating an event, leading to deceiving users/admins that a page was created by a Contributor+.
CVE-2024-52883 1 Audiocodes 1 One Voice Operations Center 2025-05-01 7.5 High
An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a path traversal vulnerability, sensitive data can be read without any authentication.
CVE-2024-52882 1 Audiocodes 1 One Voice Operations Center 2025-05-01 6.1 Medium
An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to improper neutralization of input via the devices API, an attacker can inject malicious JavaScript code (XSS) to attack logged-in administrator sessions.
CVE-2024-52881 1 Audiocodes 1 One Voice Operations Center 2025-05-01 7.5 High
An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to the use of a hard-coded key, an attacker is able to decrypt sensitive data such as passwords extracted from the topology file.
CVE-2024-40410 1 Cybelesoft 1 Thinfinity Workspace 2025-05-01 4.8 Medium
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain a hardcoded cryptographic key used for encryption.
CVE-2024-40408 1 Cybelesoft 1 Thinfinity Workspace 2025-05-01 7.3 High
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the Create Profile section. This vulnerability allows attackers to create arbitrary user profiles with elevated privileges.
CVE-2024-40407 1 Cybelesoft 1 Thinfinity Workspace 2025-05-01 7.5 High
A full path disclosure in Cybele Software Thinfinity Workspace before v7.0.2.113 allows attackers to obtain the root path of the application via unspecified vectors.
CVE-2024-40405 1 Cybelesoft 1 Thinfinity Workspace 2025-05-01 8.1 High
Incorrect access control in Cybele Software Thinfinity Workspace before v7.0.3.109 allows attackers to gain access to a secondary broker via a crafted request.
CVE-2024-40404 1 Cybelesoft 1 Thinfinity Workspace 2025-05-01 9.8 Critical
Cybele Software Thinfinity Workspace before v7.0.2.113 was discovered to contain an access control issue in the API endpoint where Web Sockets connections are established.
CVE-2022-31253 1 Opensuse 1 Openldap2 2025-05-01 7.1 High
A Untrusted Search Path vulnerability in openldap2 of openSUSE Factory allows local attackers with control of the ldap user or group to change ownership of arbitrary directory entries to this user/group, leading to escalation to root. This issue affects: openSUSE Factory openldap2 versions prior to 2.6.3-404.1.
CVE-2021-34566 1 Wago 98 750-8100, 750-8100 Firmware, 750-8101 and 95 more 2025-05-01 9.1 Critical
In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to crash the iocheck process and write memory resulting in loss of integrity and DoS.
CVE-2024-1106 2 3uu, Datenverwurstungszentrale 2 Shariff Wrapper, Shariff Wrapper 2025-05-01 6.1 Medium
The Shariff Wrapper WordPress plugin before 4.6.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2021-34567 1 Wago 98 750-8100, 750-8100 Firmware, 750-8101 and 95 more 2025-05-01 8.2 High
In WAGO I/O-Check Service in multiple products an unauthenticated remote attacker can send a specially crafted packet containing OS commands to provoke a denial of service and an limited out-of-bounds read.