Export limit exceeded: 346585 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (78921 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-7654 1 Progress 1 Openedge 2024-09-05 8.3 High
An ActiveMQ Discovery service was reachable by default from an OpenEdge Management installation when an OEE/OEM auto-discovery feature was activated.  Unauthorized access to the discovery service's UDP port allowed content injection into parts of the OEM web interface making it possible for other types of attack that could spoof or deceive web interface users.   Unauthorized use of the OEE/OEM discovery service was remediated by deactivating the discovery service by default.
CVE-2024-34659 1 Samsung 1 Group Sharing 2024-09-05 7.5 High
Exposure of sensitive information in GroupSharing prior to version 13.6.13.3 allows remote attackers can force the victim to join the group.
CVE-2024-34657 1 Samsung 1 Notes 2024-09-05 8.6 High
Stack-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows remote attackers to execute arbitrary code.
CVE-2024-8330 2 6shr System Project, Gethertechnology 2 6shr System, 6shr 2024-09-05 8.8 High
6SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload web shell scripts and use them to execute arbitrary system commands on the server.
CVE-2024-8329 2 6shr System Project, Gethertechnology 2 6shr System, 6shr 2024-09-05 8.8 High
6SHR system from Gether Technology does not properly validate the specific page parameter, allowing remote attackers with regular privilege to inject SQL command to read, modify, and delete database contents.
CVE-2024-34660 1 Samsung 1 Notes 2024-09-05 7.3 High
Heap-based out-of-bounds write in Samsung Notes prior to version 4.4.21.62 allows local attackers to execute arbitrary code.
CVE-2024-8194 1 Google 1 Chrome 2024-09-05 7.5 High
Type Confusion in V8 in Google Chrome prior to 128.0.6613.113 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2024-8193 1 Google 1 Chrome 2024-09-05 8.8 High
Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.113 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2024-39825 1 Zoom 6 Rooms, Vdi Windows Meeting Client, Workplace and 3 more 2024-09-04 8.5 High
Buffer overflow in some Zoom Workplace Apps and Rooms Clients may allow an authenticated user to conduct an escalation of privilege via network access.
CVE-2024-44820 1 Zzcms 1 Zzcms 2024-09-04 7.5 High
A sensitive information disclosure vulnerability exists in ZZCMS v.2023 and before within the eginfo.php file located at /3/E_bak5.1/upload/. When accessed with the query parameter phome=ShowPHPInfo, the application executes the phpinfo() function, which exposes detailed information about the PHP environment, including server configuration, loaded modules, and environment variables.
CVE-2024-38868 1 Zohocorp 1 Manageengine Endpoint Central 2024-09-04 7.6 High
Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.This issue affects Endpoint Central: before 11.3.2406.08 and before 11.3.2400.15
CVE-2024-7927 1 Zzcms 1 Zzcms 2024-09-04 7.3 High
A vulnerability classified as critical was found in ZZCMS 2023. Affected by this vulnerability is an unknown functionality of the file /admin/class.php?dowhat=modifyclass. The manipulation of the argument skin[] leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-7926 1 Zzcms 1 Zzcms 2024-09-04 7.3 High
A vulnerability classified as critical has been found in ZZCMS 2023. Affected is an unknown function of the file /admin/about_edit.php?action=modify. The manipulation of the argument skin leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-39776 2 Avtec, Avtecinc 5 Outpost 0810, Outpost Uploader Utility, Outpost 0810 and 2 more 2024-09-04 7.5 High
Avtec Outpost stores sensitive information in an insecure location without proper access controls in place.
CVE-2024-42418 2 Avtec, Avtecinc 5 Outpost 0810, Outpost Uploader Utility, Outpost 0810 and 2 more 2024-09-04 7.5 High
Avtec Outpost uses a default cryptographic key that can be used to decrypt sensitive information.
CVE-2024-45048 2 Phpoffice, Phpspreadsheet Project 2 Phpspreadsheet, Phpspreadsheet 2024-09-04 8.8 High
PHPSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Affected versions are subject to a bypassing of a filter which allows for an XXE-attack. This in turn allows attacker to obtain contents of local files, even if error reporting is muted. This vulnerability has been addressed in release version 2.2.1. All users are advised to upgrade. There are no known workarounds for this vulnerability.
CVE-2024-8327 2 Easy Test Online Learning And Testing Platform Project, Hwa Jiuh Digital Technology 2 Easy Test Online Learning And Testing Platform, Easy Test Online Learning And Testing Platform 2024-09-04 8.8 High
Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular privilege to inject arbitrary SQL commands to read, modify, and delete database contents.
CVE-2024-38386 2 Openatom, Openharmony 2 Openharmony, Openharmony 2024-09-04 8.4 High
in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.
CVE-2024-8343 2 Oretnom23, Sourcecodester 2 Sentiment Based Movie Rating System, Sentiment Based Movie Rating System 2024-09-04 7.3 High
A vulnerability, which was classified as critical, was found in SourceCodester Sentiment Based Movie Rating System 1.0. Affected is an unknown function of the file /classes/Users.php?f=save_client of the component User Registration Handler. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-39816 2 Openatom, Openharmony 2 Openharmony, Openharmony 2024-09-04 8.4 High
in OpenHarmony v4.1.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through out-of-bounds write.