Export limit exceeded: 376151 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 376151 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 376151 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (15638 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-28091 | 1 Maccms | 1 Maccms | 2025-04-07 | 9.1 Critical |
| maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article. | ||||
| CVE-2025-28092 | 1 Shopxo | 1 Shopxo | 2025-04-07 | 6.3 Medium |
| ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) via image upload function. | ||||
| CVE-2025-28093 | 1 Shopxo | 1 Shopxo | 2025-04-07 | 6.3 Medium |
| ShopXO v6.4.0 is vulnerable to Server-Side Request Forgery (SSRF) in Email Settings. | ||||
| CVE-2025-28094 | 1 Shopxo | 1 Shopxo | 2025-04-07 | 6.5 Medium |
| shopxo v6.4.0 has a ssrf/xss vulnerability in multiple places. | ||||
| CVE-2025-28096 | 1 Onenav | 1 Onenav | 2025-04-07 | 5.4 Medium |
| OneNav 1.1.0 is vulnerable to Server-Side Request Forgery (SSRF) in custom headers. | ||||
| CVE-2024-11702 | 1 Mozilla | 2 Firefox, Thunderbird | 2025-04-05 | 7.5 High |
| Copying sensitive information from Private Browsing tabs on Android, such as passwords, may have inadvertently stored data in the cloud-based clipboard history if enabled. This vulnerability affects Firefox < 133 and Thunderbird < 133. | ||||
| CVE-2022-46648 | 3 Debian, Redhat, Ruby-git Project | 3 Debian Linux, Satellite, Ruby-git | 2025-04-04 | 8 High |
| ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-47318. | ||||
| CVE-2023-22316 | 1 Pixela | 2 Pix-rt100, Pix-rt100 Firmware | 2025-04-04 | 6.5 Medium |
| Hidden functionality vulnerability in PIX-RT100 versions RT100_TEQ_2.1.1_EQ101 and RT100_TEQ_2.1.2_EQ101 allows a network-adjacent attacker to access the product via undocumented Telnet or SSH services. | ||||
| CVE-2022-45926 | 1 Opentext | 1 Opentext Extended Ecm | 2025-04-04 | 8.8 High |
| An issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). The endpoint notify.localizeEmailTemplate allows a low-privilege user to evaluate webreports. | ||||
| CVE-2024-38791 | 1 Meowapps | 1 Ai Engine | 2025-04-04 | 4.9 Medium |
| Server-Side Request Forgery (SSRF) vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot allows Server Side Request Forgery.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.4.7. | ||||
| CVE-2022-45928 | 1 Opentext | 1 Opentext Extended Ecm | 2025-04-04 | 8.8 High |
| A remote OScript execution issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). Multiple endpoints allow the user to pass the parameter htmlFile, which is included in the HTML output rendering pipeline of a request. Because the Content Server evaluates and executes Oscript code in HTML files, it is possible for an attacker to execute Oscript code. The Oscript scripting language allows the attacker (for example) to manipulate files on the filesystem, create new network connections, or execute OS commands. | ||||
| CVE-2025-1548 | 1 Iteachyou | 1 Dreamer Cms | 2025-04-04 | 3.5 Low |
| A vulnerability was found in iteachyou Dreamer CMS 4.1.3. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/archives/edit. The manipulation of the argument editorValue/answer/content leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | ||||
| CVE-2024-30568 | 1 Netgear | 2 R6850, R6850 Firmware | 2025-04-04 | 9.8 Critical |
| Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter. | ||||
| CVE-2022-47318 | 4 Debian, Fedoraproject, Redhat and 1 more | 4 Debian Linux, Fedora, Satellite and 1 more | 2025-04-04 | 8.8 High |
| ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-46648. | ||||
| CVE-2021-37774 | 1 Tp-link | 2 Tl-wdr7660, Tl-wdr7660 Firmware | 2025-04-04 | 8 High |
| An issue was discovered in function httpProcDataSrv in TL-WDR7660 2.0.30 that allows attackers to execute arbitrary code. | ||||
| CVE-2024-30858 | 2 Netentsec, Ns Asg | 3 Ns-asg, Ns-asg Firmware, Ns Asg | 2025-04-04 | 9.8 Critical |
| netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_fire_wall.php. | ||||
| CVE-2024-30868 | 1 Netentsec | 2 Ns-asg, Ns-asg Firmware | 2025-04-04 | 9.8 Critical |
| netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/add_getlogin.php. | ||||
| CVE-2024-46103 | 1 Sem-cms | 1 Semcms | 2025-04-04 | 9.8 Critical |
| SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php. | ||||
| CVE-2024-32350 | 1 Totolink | 2 X5000r, X5000r Firmware | 2025-04-04 | 8.8 High |
| TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecPsk" parameter in the "cstecgi.cgi" binary. | ||||
| CVE-2024-32352 | 1 Totolink | 2 X5000r, X5000r Firmware | 2025-04-04 | 8.8 High |
| TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecL2tpEnable" parameter in the "cstecgi.cgi" binary. | ||||