Search Results (328456 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-30890 1 Ed01-cms Project 1 Ed01-cms 2025-04-30 4.7 Medium
Cross Site Scripting vulnerability in ED01-CMS v.1.0 allows an attacker to obtain sensitive information via the categories.php component.
CVE-2024-31574 1 Twcms 1 Twcms 2025-04-30 5 Medium
Cross Site Scripting vulnerability in TWCMS v.2.6 allows a local attacker to execute arbitrary code via a crafted script
CVE-2024-39331 2 Gnu, Redhat 6 Emacs, Enterprise Linux, Rhel Aus and 3 more 2025-04-30 9.8 Critical
In Emacs before 29.4, org-link-expand-abbrev in lisp/ol.el expands a %(...) link abbrev even when it specifies an unsafe function, such as shell-command-to-string. This affects Org Mode before 9.7.5.
CVE-2024-45527 2 Redcap, Vanderbilt 2 Redcap, Redcap 2025-04-30 6.1 Medium
REDCap 14.7.0 allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSRF via index.php?logout=1, and can also be used to insert a link to an external phishing website.
CVE-2025-30093 1 Wisc 1 Htcondor 2025-04-30 8.1 High
HTCondor 23.0.x before 23.0.22, 23.10.x before 23.10.22, 24.0.x before 24.0.6, and 24.6.x before 24.6.1 allows authenticated attackers to bypass authorization restrictions.
CVE-2024-55072 1 Mealie 1 Mealie 2025-04-30 5.4 Medium
A Broken Object Level Authorization vulnerability in the component /api/users/{user-id} of hay-kot mealie v2.2.0 allows users to edit their own profile in order to give themselves more permissions or to change their household.
CVE-2024-57519 1 Open5gs 1 Open5gs 2025-04-30 7.5 High
An issue in Open5GS v.2.7.2 allows a remote attacker to cause a denial of service via the ogs_dbi_auth_info function in lib/dbi/subscription.c file.
CVE-2024-48954 1 Logpoint 2 Logpoint, Siem 2025-04-30 6.4 Medium
An issue was discovered in Logpoint before 7.5.0. Unvalidated input during the EventHub Collector setup by an authenticated user leads to Remote Code execution.
CVE-2024-20021 2 Google, Mediatek 46 Android, Mt6768, Mt6781 and 43 more 2025-04-30 6.7 Medium
In atf spm, there is a possible way to remap physical memory to virtual memory due to a logic error. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08584568; Issue ID: MSV-1249.
CVE-2024-42991 1 Mingsoft 1 Mcms 2025-04-30 8.1 High
MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.
CVE-2024-20056 4 Google, Mediatek, Openwrt and 1 more 30 Android, Mt6739, Mt6761 and 27 more 2025-04-30 6.7 Medium
In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08528185; Issue ID: ALPS08528185.
CVE-2024-49200 1 Insyde 1 Kernel 2025-04-30 6.4 Medium
An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 though 5.7. A potential DXE memory corruption vulnerability has been identified. The root cause is use of a pointer originating from the value of an NVRAM variable as the target of a write operation. This can be leveraged by an attacker to perform arbitrary writes, potentially leading to arbitrary code execution. The issue has been fixed in kernel 5.2, Version 05.29.44; kernel 5.3, Version 05.38.44; kernel 5.4, Version 05.46.44; kernel 5.5, Version 05.54.44; kernel 5.6, Version 05.61.44; and kernel 5.7, Version 05.70.44.
CVE-2024-20057 2 Google, Mediatek 38 Android, Mt6761, Mt6765 and 35 more 2025-04-30 7.2 High
In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08587881; Issue ID: ALPS08587881.
CVE-2025-29017 1 Codeastro 1 Internet Banking System 2025-04-30 8.8 High
A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the profile_pic parameter within pages_view_client.php.
CVE-2024-20058 2 Google, Mediatek 26 Android, Mt6765, Mt6768 and 23 more 2025-04-30 4.4 Medium
In keyInstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580204; Issue ID: ALPS08580204.
CVE-2025-22926 1 Os4ed 1 Opensis 2025-04-30 9.8 Critical
An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename.
CVE-2024-20059 2 Google, Mediatek 26 Android, Mt6580, Mt6739 and 23 more 2025-04-30 6.7 Medium
In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue ID: ALPS08541749.
CVE-2024-38985 1 Janrywang 1 Depath 2025-04-30 9.8 Critical
janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() method at setIn (lib/index.js:90). This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
CVE-2024-20060 2 Google, Mediatek 26 Android, Mt6580, Mt6739 and 23 more 2025-04-30 5.9 Medium
In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue ID: ALPS08541754.
CVE-2024-37765 1 Machform 1 Machform 2025-04-30 8.8 High
Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.