Export limit exceeded: 15638 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (15638 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-50808 1 Seacms 1 Seacms 2025-03-28 8.8 High
SeaCms 13.1 is vulnerable to code injection in the notification module of the member message notification module in the backend user module, due to unsafe handling of the "notify" variable in admin_notify.php.
CVE-2024-42598 1 Seacms 1 Seacms 2025-03-28 6.7 Medium
SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the vulnerability to execute arbitrary commands and gain system privileges.
CVE-2024-30565 1 Seacms 1 Seacms 2025-03-28 8.8 High
An issue was discovered in SeaCMS version 12.9, allows remote attackers to execute arbitrary code via admin notify.php.
CVE-2022-48116 1 Ayacms Project 1 Ayacms 2025-03-28 7.2 High
AyaCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/tpl_edit.inc.php.
CVE-2024-27622 1 Cmsmadesimple 1 Cms Made Simple 2025-03-28 7.2 High
A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21. This vulnerability arises from inadequate sanitization of user-supplied input in the 'Code' section of the module. As a result, authenticated users with administrative privileges can inject and execute arbitrary PHP code.
CVE-2024-31666 1 Flusity 1 Flusity 2025-03-28 9.8 Critical
An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via a crafted script to the edit_addon_post.php component.
CVE-2023-24623 1 Paranoidhttp Project 1 Paranoidhttp 2025-03-28 7.5 High
Paranoidhttp before 0.3.0 allows SSRF because [::] is equivalent to the 127.0.0.1 address, but does not match the filter for private addresses.
CVE-2023-24622 1 Includesecurity 1 Safeurl-python 2025-03-28 5.3 Medium
isInList in the safeurl-python package before 1.2 for Python has an insufficiently restrictive regular expression for external domains, leading to SSRF.
CVE-2022-4335 1 Gitlab 1 Gitlab 2025-03-28 4.3 Medium
A blind SSRF vulnerability was identified in all versions of GitLab EE prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 which allows an attacker to connect to a local host.
CVE-2022-48175 1 Rukovoditel 1 Rukovoditel 2025-03-28 9.8 Critical
Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=dashboard/ajax_request.
CVE-2024-3787 1 Whitebearsolutions 1 Wbsairback 2025-03-27 6.6 Medium
Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through S3 disks (/admin/DeviceS3). Exploitation of this vulnerability could allow a remote user to execute arbitrary code.
CVE-2022-4201 1 Gitlab 1 Gitlab 2025-03-27 3.5 Low
A blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 allows an attacker to connect to local addresses when configuring a malicious GitLab Runner.
CVE-2022-25967 1 Eta.js 1 Eta 2025-03-27 8.1 High
Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for users who are rendering templates with user-defined data.
CVE-2024-25249 1 He3app 1 He3 App 2025-03-27 9.8 Critical
An issue in He3 App for macOS version 2.0.17, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.
CVE-2023-24495 1 Tenable 1 Tenable.sc 2025-03-27 6.5 Medium
A Server Side Request Forgery (SSRF) vulnerability exists in Tenable.sc due to improper validation of session & user-accessible input data. A privileged, authenticated remote attacker could interact with external and internal services covertly.
CVE-2025-0185 1 Dify 1 Dify 2025-03-27 8.8 High
A vulnerability in the Dify Tools' Vanna module of the langgenius/dify repository allows for a Pandas Query Injection in the latest version. The vulnerability occurs in the function `vn.get_training_plan_generic(df_information_schema)`, which does not properly sanitize user inputs before executing queries using the Pandas library. This can potentially lead to Remote Code Execution (RCE) if exploited.
CVE-2023-24060 1 Havenweb 1 Haven 2025-03-27 5 Medium
Haven 5d15944 allows Server-Side Request Forgery (SSRF) via the feed[url]= Feeds functionality. Authenticated users with the ability to create new RSS Feeds or add RSS Feeds can supply an arbitrary hostname (or even the hostname of the Haven server itself). NOTE: this product has significant usage but does not have numbered releases; ordinary end users may typically use the master branch.
CVE-2024-53604 1 Phpgurukul 1 Covid19 Testing Management System 2025-03-27 9.8 Critical
A SQL Injection vulnerability was found in /covid-tms/check_availability.php in PHPGurukul COVID 19 Testing Management System v1.0, which allows remote attackers to execute arbitrary code via the mobnumber POST request parameter.
CVE-2022-40258 1 Ami 2 Megarac Spx-12, Megarac Spx-13 2025-03-27 5.3 Medium
AMI Megarac Weak password hashes for Redfish & API
CVE-2024-31004 1 Axiosys 1 Bento4 2025-03-27 8.8 High
An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_StsdAtom::AP4_StsdAtom,mp4fragment.