Latest CVE Feed
-
7.8
HIGHCVE-2022-43040
GPAC 2.1-DEV-rev368-gfd054169b-master was discovered to contain a heap buffer overflow via the function gf_isom_box_dump_start_ex at /isomedia/box_funcs.c.... Read more
Affected Products : gpac- EPSS Score: %0.05
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
9.8
CRITICALCVE-2022-43026
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the endIp parameter at /goform/SetPptpServerCfg.... Read more
- EPSS Score: %0.17
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
9.8
CRITICALCVE-2022-43025
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the startIp parameter at /goform/SetPptpServerCfg.... Read more
- EPSS Score: %0.17
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
9.8
CRITICALCVE-2022-43024
Tenda TX3 US_TX3V1.0br_V16.03.13.11_multi_TDE01 was discovered to contain a stack overflow via the list parameter at /goform/SetVirtualServerCfg.... Read more
- EPSS Score: %0.17
- Published: Oct. 19, 2022
- Modified: May. 09, 2025
-
8.8
HIGHCVE-2024-39841
A SQL Injection vulnerability exists in the service configuration functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.... Read more
Affected Products : centreon_web- Published: Aug. 23, 2024
- Modified: May. 09, 2025
-
9.1
CRITICALCVE-2024-33854
A SQL Injection vulnerability exists in the Graph Template component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.... Read more
Affected Products : centreon_web- Published: Aug. 23, 2024
- Modified: May. 09, 2025
-
9.1
CRITICALCVE-2024-33853
A SQL Injection vulnerability exists in the Timeperiod component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.... Read more
Affected Products : centreon_web- Published: Aug. 23, 2024
- Modified: May. 09, 2025
-
9.1
CRITICALCVE-2024-33852
A SQL Injection vulnerability exists in the Downtime component in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.... Read more
Affected Products : centreon_web- Published: Aug. 23, 2024
- Modified: May. 09, 2025
-
9.8
CRITICALCVE-2024-32501
A SQL Injection vulnerability exists in the updateServiceHost functionality in Centreon Web 24.04.x before 24.04.3, 23.10.x before 23.10.13, 23.04.x before 23.04.19, and 22.10.x before 22.10.23.... Read more
- Published: Aug. 23, 2024
- Modified: May. 09, 2025
-
8.0
HIGHCVE-2024-52739
D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple remote command execution (RCE) vulnerabilities in the msp_info_htm function via the flag and cmd parameters.... Read more
- Published: Nov. 20, 2024
- Modified: May. 09, 2025
-
9.9
CRITICALCVE-2024-51478
YesWiki is a wiki system written in PHP. Prior to 4.4.5, the use of a weak cryptographic algorithm and a hard-coded salt to hash the password reset key allows it to be recovered and used to reset the password of any account. This issue is fixed in 4.4.5.... Read more
Affected Products : yeswiki- Published: Oct. 31, 2024
- Modified: May. 09, 2025
-
7.6
HIGHCVE-2025-24017
YesWiki is a wiki system written in PHP. Versions up to and including 4.4.5 are vulnerable to any end-user crafting a DOM based XSS on all of YesWiki's pages which is triggered when a user clicks on a malicious link. The vulnerability makes use of the sea... Read more
Affected Products : yeswiki- Published: Jan. 21, 2025
- Modified: May. 09, 2025
- Vuln Type: Cross-Site Scripting
-
7.1
HIGHCVE-2025-24019
YesWiki is a wiki system written in PHP. In versions up to and including 4.4.5, it is possible for any authenticated user, through the use of the filemanager to delete any file owned by the user running the FastCGI Process Manager (FPM) on the host withou... Read more
Affected Products : yeswiki- Published: Jan. 21, 2025
- Modified: May. 09, 2025
- Vuln Type: Authorization
-
8.6
HIGHCVE-2025-31131
YesWiki is a wiki system written in PHP. The squelette parameter is vulnerable to path traversal attacks, enabling read access to arbitrary files on the server. This vulnerability is fixed in 4.5.2.... Read more
Affected Products : yeswiki- Published: Apr. 01, 2025
- Modified: May. 09, 2025
- Vuln Type: Path Traversal
-
7.6
HIGHCVE-2025-24018
YesWiki is a wiki system written in PHP. In versions up to and including 4.4.5, it is possible for an authenticated user with rights to edit/create a page or comment to trigger a stored XSS which will be reflected on any page where the resource is loaded.... Read more
Affected Products : yeswiki- Published: Jan. 21, 2025
- Modified: May. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-46550
YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the `/?BazaR` endpoint and `idformulaire` parameter are vulnerable to cross-site scripting. An attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated... Read more
Affected Products : yeswiki- Published: Apr. 29, 2025
- Modified: May. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-46549
YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated user by having them click on a malicious link. Stolen cookies allow the attacker to take ov... Read more
Affected Products : yeswiki- Published: Apr. 29, 2025
- Modified: May. 09, 2025
- Vuln Type: Cross-Site Scripting
-
10.0
CRITICALCVE-2025-46348
YesWiki is a wiki system written in PHP. Prior to version 4.5.4, the request to commence a site backup can be performed and downloaded without authentication. The archives are created with a predictable filename, so a malicious user could create and downl... Read more
Affected Products : yeswiki- Published: Apr. 29, 2025
- Modified: May. 09, 2025
- Vuln Type: Authentication
-
4.8
MEDIUMCVE-2025-46350
YesWiki is a wiki system written in PHP. Prior to version 4.5.4, an attacker can use a reflected cross-site scripting attack to steal cookies from an authenticated user by having them click on a malicious link. Stolen cookies allow the attacker to take ov... Read more
Affected Products : yeswiki- Published: Apr. 29, 2025
- Modified: May. 09, 2025
- Vuln Type: Cross-Site Scripting
-
7.6
HIGHCVE-2025-46349
YesWiki is a wiki system written in PHP. Prior to version 4.5.4, YesWiki is vulnerable to reflected XSS in the file upload form. This vulnerability allows any malicious unauthenticated user to create a link that can be clicked on by the victim to perform ... Read more
Affected Products : yeswiki- Published: Apr. 29, 2025
- Modified: May. 09, 2025
- Vuln Type: Cross-Site Scripting