Export limit exceeded: 100455 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (100455 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-50664 1 Gpac 1 Gpac 2025-02-11 7.8 High
gpac 2.4 contains a heap-buffer-overflow at isomedia/sample_descs.c:1799 in gf_isom_new_mpha_description in gpac/MP4Box.
CVE-2023-27728 1 F5 1 Njs 2025-02-11 7.5 High
Nginx NJS v0.7.10 was discovered to contain a segmentation violation via the function njs_dump_is_recursive at src/njs_vmcode.c.
CVE-2023-22614 1 Insyde 1 Insydeh2o 2025-02-11 8.8 High
An issue was discovered in ChipsetSvcSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. There is insufficient input validation in BIOS Guard updates. An attacker can induce memory corruption in SMM by supplying malformed inputs to the BIOS Guard SMI handler.
CVE-2023-22613 1 Insyde 1 Insydeh2o 2025-02-11 8.8 High
An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. It is possible to write to an attacker-controlled address. An attacker could invoke an SMI handler with a malformed pointer in RCX that overlaps SMRAM, resulting in SMM memory corruption.
CVE-2021-46879 1 Treasuredata 1 Fluent Bit 2025-02-11 7.8 High
An issue was discovered in Treasure Data Fluent Bit 1.7.1, a wrong variable is used to get the msgpack data resulting in a heap overflow in flb_msgpack_gelf_value_ext. An attacker can craft a malicious file and tick the victim to open the file with the software, triggering a heap overflow and execute arbitrary code on the target system.
CVE-2020-36073 1 Tailor Management System Project 1 Tailor Management System 2025-02-11 8.8 High
SQL injection vulnerability found in Tailor Management System v.1 allows a remote attacker to execute arbitrary code via the detail parameter of the document.php page.
CVE-2024-38761 2 Dylanjames, Zephyr-one 2 Zephyr Project Manager, Zephyr Project Manager 2025-02-11 7.5 High
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.99.
CVE-2023-28733 1 Acymailing 1 Acymailing 2025-02-11 7.2 High
AnyMailing Joomla Plugin is vulnerable to stored cross site scripting (XSS) in templates and emails of AcyMailing, exploitable without authentication when access is granted to the campaign's creation on front-office. This issue affects AnyMailing Joomla Plugin Enterprise in versions below 8.3.0.
CVE-2023-1737 1 Young Entrepreneur E-negosyo System Project 1 Young Entrepreneur E-negosyo System 2025-02-11 7.3 High
A vulnerability, which was classified as critical, was found in SourceCodester Young Entrepreneur E-Negosyo System 1.0. This affects an unknown part of the file login.php. The manipulation of the argument U_USERNAME leads to sql injection. It is possible to initiate the attack remotely. The identifier VDB-224625 was assigned to this vulnerability.
CVE-2022-47192 1 Generex 2 Cs141, Cs141 Firmware 2025-02-11 8.8 High
Generex UPS CS141 below 2.06 version, could allow a remote attacker to upload a backup file containing a modified "users.json" to the web server of the device, allowing him to replace the administrator password.
CVE-2025-21161 1 Adobe 1 Substance 3d Designer 2025-02-11 7.8 High
Substance3D - Designer versions 14.0.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVE-2023-26986 1 Chinamobileltd 1 Oa Mailbox Pc 2025-02-11 7.8 High
An issue in China Mobile OA Mailbox PC v2.9.23 allows remote attackers to execute arbitrary commands on a victim host via user interaction with a crafted EML file sent to their OA mailbox.
CVE-2023-26919 1 Javadelight 1 Nashorn Sandbox 2025-02-11 7.2 High
delight-nashorn-sandbox 0.2.4 and 0.2.5 is vulnerable to sandbox escape. When allowExitFunctions is set to false, the loadWithNewGlobal function can be used to invoke the exit and quit methods to exit the Java process.
CVE-2023-22612 1 Insyde 1 Insydeh2o 2025-02-11 8.8 High
An issue was discovered in IhisiSmm in Insyde InsydeH2O with kernel 5.0 through 5.5. A malicious host OS can invoke an Insyde SMI handler with malformed arguments, resulting in memory corruption in SMM.
CVE-2023-22429 1 Wolt 1 Wolt Delivery 2025-02-11 7.8 High
Android App 'Wolt Delivery: Food and more' version 4.27.2 and earlier uses hard-coded credentials (API key for an external service), which may allow a local attacker to obtain the hard-coded API key via reverse-engineering the application binary.
CVE-2023-22282 2 Elecom, Microsoft 2 Wab-mat, Windows 2025-02-11 7.3 High
WAB-MAT Ver.5.0.0.8 and earlier starts another program with an unquoted file path. Since a registered Windows service path contains spaces and are unquoted, if a malicious executable is placed on a certain path, the executable may be executed with the privilege of the Windows service.
CVE-2023-1381 1 Joomunited 1 Wp Meta Seo 2025-02-11 8.8 High
The WP Meta SEO WordPress plugin before 4.5.5 does not validate image file paths before attempting to manipulate the image files, leading to a PHAR deserialization vulnerability. Furthermore, the plugin contains a gadget chain which may be used in certain configurations to achieve remote code execution.
CVE-2022-42858 1 Apple 1 Macos 2025-02-11 7.8 High
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Ventura 13.1. An app may be able to execute arbitrary code with kernel privileges
CVE-2020-19803 1 Doyocms Project 1 Doyocms 2025-02-11 8.8 High
Cross Site Request Forgery vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary code via the background system settings.
CVE-2024-2448 2 Kemptechnologies, Progress 2 Loadmaster, Loadmaster 2025-02-11 8.4 High
An OS command injection vulnerability has been identified in LoadMaster.  An authenticated UI user with any permission settings may be able to inject commands into a UI component using a shell command resulting in OS command injection.