Search Results (329602 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-20057 2 Google, Mediatek 38 Android, Mt6761, Mt6765 and 35 more 2025-04-30 7.2 High
In keyInstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08587881; Issue ID: ALPS08587881.
CVE-2025-29017 1 Codeastro 1 Internet Banking System 2025-04-30 8.8 High
A Remote Code Execution (RCE) vulnerability exists in Code Astro Internet Banking System 2.0.0 due to improper file upload validation in the profile_pic parameter within pages_view_client.php.
CVE-2024-20058 2 Google, Mediatek 26 Android, Mt6765, Mt6768 and 23 more 2025-04-30 4.4 Medium
In keyInstall, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580204; Issue ID: ALPS08580204.
CVE-2025-22926 1 Os4ed 1 Opensis 2025-04-30 9.8 Critical
An issue in OS4ED openSIS v8.0 through v9.1 allows attackers to execute a directory traversal by sending a crafted POST request to /Modules.php?modname=messaging/Inbox.php&modfunc=save&filename.
CVE-2024-20059 2 Google, Mediatek 26 Android, Mt6580, Mt6739 and 23 more 2025-04-30 6.7 Medium
In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue ID: ALPS08541749.
CVE-2024-38985 1 Janrywang 1 Depath 2025-04-30 9.8 Critical
janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() method at setIn (lib/index.js:90). This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
CVE-2024-20060 2 Google, Mediatek 26 Android, Mt6580, Mt6739 and 23 more 2025-04-30 5.9 Medium
In da, there is a possible escalation of privilege due to an incorrect status check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541749; Issue ID: ALPS08541754.
CVE-2024-37765 1 Machform 1 Machform 2025-04-30 8.8 High
Machform up to version 19 is affected by an authenticated Blind SQL injection in the user account settings page.
CVE-2024-37764 1 Machform 1 Machform 2025-04-30 5.4 Medium
MachForm up to version 19 is affected by an authenticated stored cross-site scripting.
CVE-2024-37763 1 Machform 1 Machform 2025-04-30 5.4 Medium
MachForm up to version 19 is affected by an unauthenticated stored cross-site scripting which affects users with valid sessions whom can view compiled forms results.
CVE-2024-37762 1 Machform 1 Machform 2025-04-30 9.9 Critical
MachForm up to version 21 is affected by an authenticated unrestricted file upload which leads to a remote code execution.
CVE-2024-48951 1 Logpoint 2 Logpoint, Siem 2025-04-30 7.5 High
An issue was discovered in Logpoint before 7.5.0. Server-Side Request Forgery (SSRF) on SOAR can be used to leak Logpoint's API Token leading to authentication bypass.
CVE-2024-48952 1 Logpoint 1 Soar 2025-04-30 6.4 Medium
An issue was discovered in Logpoint before 7.5.0. SOAR uses a static JWT secret key to generate tokens that allow access to SOAR API endpoints without authentication. This static key vulnerability enables attackers to create custom JWT secret keys for unauthorized access to these endpoints.
CVE-2024-48953 1 Logpoint 2 Logpoint, Siem 2025-04-30 7.5 High
An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed unauthenticated users to register their own authentication plugins in Logpoint, resulting in unauthorized access.
CVE-2025-46228 1 Avecnous 1 Event Post 2025-04-30 6.5 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bastien Ho Event post allows DOM-Based XSS. This issue affects Event post: from n/a through 5.9.11.
CVE-2025-46229 1 Textmetrics 1 Textmetrics 2025-04-30 5.9 Medium
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Israpil Textmetrics allows Stored XSS. This issue affects Textmetrics: from n/a through 3.6.2.
CVE-2024-51004 1 Netgear 4 R7000p, R7000p Firmware, R8500 and 1 more 2025-04-30 5.7 Medium
Netgear R8500 v1.0.2.160 and R7000P v1.3.3.154 were discovered to multiple stack overflow vulnerabilities in the component usb_device.cgi via the cifs_user, read_access, and write_access parameters. These vulnerabilities allow attackers to cause a Denial of Service (DoS) via a crafted POST request.
CVE-2024-51002 1 Netgear 9 R6400 Firmware, R6400v2, R6400v2 Firmware and 6 more 2025-04-30 5.7 Medium
Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a stack overflow via the l2tp_user_ip parameter at l2tp.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
CVE-2025-46231 1 Servit 1 Affiliate-toolkit 2025-04-30 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in SERVIT Software Solutions affiliate-toolkit allows Cross Site Request Forgery. This issue affects affiliate-toolkit: from n/a through 3.7.3.
CVE-2025-46232 1 Alttext 1 Alt Text Ai 2025-04-30 4.3 Medium
Missing Authorization vulnerability in alttextai Download Alt Text AI allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Download Alt Text AI: from n/a through 1.9.93.