Search Results (338851 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-31841 1 Italtel 1 Embrace 2025-05-21 7.5 High
An issue was discovered in Italtel Embrace 1.6.4. The web server fails to sanitize input data, allowing remote unauthenticated attackers to read arbitrary files on the filesystem.
CVE-2024-31846 1 Italtel 1 Embrace 2025-05-21 7.5 High
An issue was discovered in Italtel Embrace 1.6.4. The web application does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVE-2024-31845 1 Italtel 1 Embrace 2025-05-21 5.3 Medium
An issue was discovered in Italtel Embrace 1.6.4. The product does not neutralize or incorrectly neutralizes output that is written to logs. The web application writes logs using a GET query string parameter. This parameter can be modified by an attacker, so that every action he performs is attributed to a different user. This can be exploited without authentication.
CVE-2024-31843 1 Italtel 1 Embrace 2025-05-21 4.1 Medium
An issue was discovered in Italtel Embrace 1.6.4. The Web application does not properly check the parameters sent as input before they are processed on the server side. This allows authenticated users to execute commands on the Operating System.
CVE-2024-27752 1 Cszcms 1 Csz Cms 2025-05-21 5.4 Medium
Cross Site Scripting vulnerability in CSZ CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the Default Keyword field in the settings function.
CVE-2022-40928 1 Online Leave Management System Project 1 Online Leave Management System 2025-05-21 7.2 High
Online Leave Management System v1.0 is vulnerable to SQL Injection via /leave_system/classes/Master.php?f=delete_application.
CVE-2022-40925 1 Phpgurukul 1 Zoo Management System 2025-05-21 7.2 High
Zoo Management System v1.0 has an arbitrary file upload vulnerability in the picture upload point of the "save_event" file of the "Events" module in the background management system.
CVE-2022-40116 1 Online Banking System Project 1 Online Banking System 2025-05-21 9.8 Critical
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the search parameter at /net-banking/beneficiary.php.
CVE-2022-40115 1 Online Banking System Project 1 Online Banking System 2025-05-21 9.8 Critical
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/delete_beneficiary.php.
CVE-2022-40114 1 Online Banking System Project 1 Online Banking System 2025-05-21 9.8 Critical
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/edit_customer.php.
CVE-2022-3200 2 Fedoraproject, Google 2 Fedora, Chrome 2025-05-21 8.8 High
Heap buffer overflow in Internals in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2022-3199 2 Fedoraproject, Google 2 Fedora, Chrome 2025-05-21 8.8 High
Use after free in Frames in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2022-3198 2 Fedoraproject, Google 2 Fedora, Chrome 2025-05-21 8.8 High
Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)
CVE-2022-38970 2 Hipcam, Iegeek 3 Realserver, Ig20, Ig20 Firmware 2025-05-21 6.5 Medium
ieGeek IG20 hipcam RealServer V1.0 is vulnerable to Incorrect Access Control. The algorithm used to generate device IDs (UIDs) for devices that utilize Shenzhen Yunni Technology iLnkP2P suffers from a predictability flaw that allows remote attackers to establish direct connections to arbitrary devices.
CVE-2022-36159 1 Contec 8 Fxa2000, Fxa2000 Firmware, Fxa3000 and 5 more 2025-05-21 8.8 High
Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the password strength is weak, it can be cracked in few minutes. Through this credential, a malicious actor can access the Wireless LAN Manager interface and open the telnet port then sniff the traffic or inject any malware.
CVE-2025-25907 1 Tianti Project 1 Tianti 2025-05-21 8.8 High
tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/save. This vulnerability allows attackers to execute arbitrary operations via a crafted GET or POST request.
CVE-2024-30885 1 Hadsky 1 Hadsky 2025-05-21 6.1 Medium
Reflected Cross-Site Scripting (XSS) vulnerability in HadSky v7.6.3, allows remote attackers to execute arbitrary code and obtain sensitive information via the chklogin.php component .
CVE-2024-30886 1 Hadsky 1 Hadsky 2025-05-21 5.4 Medium
A stored cross-site scripting (XSS) vulnerability in the remotelink function of HadSky v7.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the url parameter.
CVE-2024-33661 1 Portainer 1 Portainer 2025-05-21 9.1 Critical
Portainer before 2.20.0 allows redirects when the target is not index.yaml.
CVE-2024-33662 1 Portainer 1 Portainer 2025-05-21 7.5 High
Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.