Latest CVE Feed
-
9.8
CRITICALCVE-2022-40115
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/delete_beneficiary.php.... Read more
Affected Products : online_banking_system- Published: Sep. 23, 2022
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2022-40114
Online Banking System v1.0 was discovered to contain a SQL injection vulnerability via the cust_id parameter at /net-banking/edit_customer.php.... Read more
Affected Products : online_banking_system- Published: Sep. 23, 2022
- Modified: May. 21, 2025
-
8.8
HIGHCVE-2022-3200
Heap buffer overflow in Internals in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
8.8
HIGHCVE-2022-3199
Use after free in Frames in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)... Read more
- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
8.8
HIGHCVE-2022-3198
Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)... Read more
- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
6.5
MEDIUMCVE-2022-38970
ieGeek IG20 hipcam RealServer V1.0 is vulnerable to Incorrect Access Control. The algorithm used to generate device IDs (UIDs) for devices that utilize Shenzhen Yunni Technology iLnkP2P suffers from a predictability flaw that allows remote attackers to es... Read more
- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
8.8
HIGHCVE-2022-36159
Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the password strength is weak, it can be cracked in few minutes. Through this credential, a malicious actor can ac... Read more
Affected Products : fxa3000_firmware fxa3020_firmware fxa3200_firmware fxa2000_firmware fxa3000 fxa3020 fxa3200 fxa2000- Published: Sep. 26, 2022
- Modified: May. 21, 2025
-
8.8
HIGHCVE-2025-25907
tianti v2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /user/ajax/save. This vulnerability allows attackers to execute arbitrary operations via a crafted GET or POST request.... Read more
Affected Products : tianti- Published: Mar. 10, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.1
MEDIUMCVE-2024-32489
TCPDF before 6.7.4 mishandles calls that use HTML syntax.... Read more
Affected Products : tcpdf- Published: Apr. 15, 2024
- Modified: May. 21, 2025
-
7.5
HIGHCVE-2024-22640
TCPDF version <=6.6.5 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page with a crafted color.... Read more
- Published: Apr. 19, 2024
- Modified: May. 21, 2025
-
7.5
HIGHCVE-2024-22641
TCPDF version 6.6.5 and before is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted SVG file.... Read more
Affected Products : tcpdf- Published: May. 28, 2024
- Modified: May. 21, 2025
-
6.1
MEDIUMCVE-2024-30885
Reflected Cross-Site Scripting (XSS) vulnerability in HadSky v7.6.3, allows remote attackers to execute arbitrary code and obtain sensitive information via the chklogin.php component .... Read more
Affected Products : hadsky- Published: Apr. 11, 2024
- Modified: May. 21, 2025
-
5.4
MEDIUMCVE-2024-30886
A stored cross-site scripting (XSS) vulnerability in the remotelink function of HadSky v7.6.3 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the url parameter.... Read more
Affected Products : hadsky- Published: Apr. 23, 2024
- Modified: May. 21, 2025
-
9.1
CRITICALCVE-2024-33661
Portainer before 2.20.0 allows redirects when the target is not index.yaml.... Read more
Affected Products : portainer- Published: Apr. 26, 2024
- Modified: May. 21, 2025
-
7.5
HIGHCVE-2024-33662
Portainer before 2.20.2 improperly uses an encryption algorithm in the AesEncrypt function.... Read more
Affected Products : portainer- Published: Oct. 02, 2024
- Modified: May. 21, 2025
-
9.8
CRITICALCVE-2024-50919
Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp. can lead to arbitrary command execution... Read more
- Published: Nov. 18, 2024
- Modified: May. 21, 2025
-
4.8
MEDIUMCVE-2025-2211
A vulnerability was found in aitangbao springboot-manager 3.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /sysDictDetail/add. The manipulation of the argument name leads to cross site scripting. The atta... Read more
Affected Products : springboot-manager- Published: Mar. 11, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-2210
A vulnerability has been found in aitangbao springboot-manager 3.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /sysJob/add. The manipulation of the argument name leads to cross site scripting. The ... Read more
Affected Products : springboot-manager- Published: Mar. 11, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-2209
A vulnerability, which was classified as problematic, was found in aitangbao springboot-manager 3.0. Affected is an unknown function of the file /sysDict/add. The manipulation of the argument name leads to cross site scripting. It is possible to launch th... Read more
Affected Products : springboot-manager- Published: Mar. 11, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2025-2208
A vulnerability, which was classified as problematic, has been found in aitangbao springboot-manager 3.0. This issue affects some unknown processing of the file /sysFiles/upload of the component Filename Handler. The manipulation of the argument name lead... Read more
Affected Products : springboot-manager- Published: Mar. 11, 2025
- Modified: May. 21, 2025
- Vuln Type: Cross-Site Scripting