Search Results (329550 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2025-0627 1 Taxopress 1 Taxopress 2025-04-30 3.5 Low
The WordPress Tag, Category, and Taxonomy Manager WordPress plugin before 3.30.0 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2022-24938 1 Silabs 1 Emberznet 2025-04-30 6.5 Medium
A malformed packet causes a stack overflow in the Ember ZNet stack. This causes an assert which leads to a reset, immediately clearing the error.
CVE-2022-24937 1 Silabs 1 Emberznet 2025-04-30 6.5 Medium
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Silicon Labs Ember ZNet allows Overflow Buffers.
CVE-2025-4020 1 Phpgurukul 1 Old Age Home Management System 2025-04-30 7.3 High
A vulnerability was found in PHPGurukul Old Age Home Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /contact.php. The manipulation of the argument fname leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
CVE-2025-3269 2025-04-30 N/A
Red Hat Product Security has come to the conclusion that this CVE is not needed.
CVE-2025-2156 2025-04-30 N/A
Red Hat Product Security has come to the conclusion that this CVE is not needed.
CVE-2025-1782 2025-04-30 N/A
Red Hat Product Security has come to the conclusion that this CVE is not needed.
CVE-2023-21358 1 Google 1 Android 2025-04-30 7.8 High
In UWB Google, there is a possible way for a malicious app to masquerade as system app com.android.uwb.resources due to improperly used crypto. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVE-2022-45391 1 Jenkins 1 Ns-nd Integration Performance Publisher 2025-04-30 7.5 High
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier globally and unconditionally disables SSL/TLS certificate and hostname validation for the entire Jenkins controller JVM.
CVE-2022-45390 1 Jenkins 1 Loader.io 2025-04-30 4.3 Medium
A missing permission check in Jenkins loader.io Plugin 1.0.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
CVE-2022-45389 1 Jenkins 1 Xp-dev 2025-04-30 5.3 Medium
A missing permission check in Jenkins XP-Dev Plugin 1.0 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to an attacker-specified repository.
CVE-2022-45388 1 Jenkins 1 Config Rotator 2025-04-30 7.5 High
Jenkins Config Rotator Plugin 2.0.1 and earlier does not restrict a file name query parameter in an HTTP endpoint, allowing unauthenticated attackers to read arbitrary files with '.xml' extension on the Jenkins controller file system.
CVE-2022-45387 1 Jenkins 1 Bart 2025-04-30 5.4 Medium
Jenkins BART Plugin 1.0.3 and earlier does not escape the parsed content of build logs before rendering it on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability.
CVE-2022-45386 1 Jenkins 1 Violations 2025-04-30 5.5 Medium
Jenkins Violations Plugin 0.7.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2022-45385 1 Jenkins 1 Cloudbees Docker Hub\/registry Notification 2025-04-30 7.5 High
A missing permission check in Jenkins CloudBees Docker Hub/Registry Notification Plugin 2.6.2 and earlier allows unauthenticated attackers to trigger builds of jobs corresponding to the attacker-specified repository.
CVE-2022-45384 1 Jenkins 1 Reverse Proxy Auth 2025-04-30 6.5 Medium
Jenkins Reverse Proxy Auth Plugin 1.7.3 and earlier stores the LDAP manager password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.
CVE-2022-43119 1 Csphere 1 Clansphere 2025-04-30 6.1 Medium
A cross-site scripting (XSS) vulnerability in Clansphere CMS v2011.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username parameter.
CVE-2022-43071 1 Xpdfreader 1 Xpdf 2025-04-30 5.5 Medium
A stack overflow in the Catalog::readPageLabelTree2(Object*) function of XPDF v4.04 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
CVE-2022-42978 1 Atlassian 1 Confluence Data Center 2025-04-30 7.5 High
In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled. An unauthenticated attacker could access files on the remote system.
CVE-2021-25926 1 Sickrage 1 Sickrage 2025-04-30 6.1 Medium
In SiCKRAGE, versions 9.3.54.dev1 to 10.0.11.dev1 are vulnerable to Reflected Cross-Site-Scripting (XSS) due to user input not being validated properly in the `quicksearch` feature. Therefore, an attacker can steal a user's sessionID to masquerade as a victim user, to carry out any actions in the context of the user.