Latest CVE Feed
-
5.4
MEDIUMCVE-2024-41446
A stored cross-site scripting (XSS) vulnerability in Alkacon OpenCMS v17.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the image parameter under the Create/Modify article function.... Read more
Affected Products : opencms- Published: Apr. 21, 2025
- Modified: Apr. 24, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2024-42699
Cross Site Scripting vulnerability in Create/Modify article function in Alkacon OpenCMS 17.0 allows remote attacker to inject javascript payload via image title sub-field in the image field... Read more
Affected Products : opencms- Published: Apr. 21, 2025
- Modified: Apr. 24, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2025-28121
code-projects Online Exam Mastering System 1.0 is vulnerable to Cross Site Scripting (XSS) in feedback.php via the "q" parameter allowing remote attackers to execute arbitrary code.... Read more
Affected Products : online_exam_mastering_system- Published: Apr. 21, 2025
- Modified: Apr. 24, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-29287
An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.... Read more
Affected Products : mcms- Published: Apr. 21, 2025
- Modified: Apr. 24, 2025
- Vuln Type: Authentication
-
6.1
MEDIUMCVE-2024-24291
An issue in the component /member/index/login of yzmcms v7.0 allows attackers to direct users to malicious sites via a crafted URL.... Read more
Affected Products : yzmcms- Published: Feb. 06, 2024
- Modified: Apr. 24, 2025
-
9.8
CRITICALCVE-2024-24026
An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions at com.java2nb.system.controller.SysUserController: uploadImg(). An attacker can pass in specially crafted filename parameter to perform arbitrary File download.... Read more
Affected Products : novel-plus- Published: Feb. 08, 2024
- Modified: Apr. 24, 2025
-
7.5
HIGHCVE-2023-6294
The Popup Builder WordPress plugin before 4.2.6 does not validate a parameter before making a request to it, which could allow users with the administrator role to perform SSRF attack in Multisite WordPress configurations.... Read more
Affected Products : popup_builder- Published: Feb. 12, 2024
- Modified: Apr. 24, 2025
-
8.8
HIGHCVE-2023-50386
Improper Control of Dynamically-Managed Code Resources, Unrestricted Upload of File with Dangerous Type, Inclusion of Functionality from Untrusted Control Sphere vulnerability in Apache Solr.This issue affects Apache Solr: from 6.0.0 through 8.11.2, from ... Read more
Affected Products : solr- Published: Feb. 09, 2024
- Modified: Apr. 24, 2025
-
6.7
MEDIUMCVE-2023-32835
In keyinstall, there is a possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08157918; Issue ID: ALPS08... Read more
- Published: Nov. 06, 2023
- Modified: Apr. 24, 2025
-
8.8
HIGHCVE-2022-46411
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. A default password is persisted after installation and may be discovered and used to escalate privileges.... Read more
- Published: Dec. 04, 2022
- Modified: Apr. 24, 2025
-
8.8
HIGHCVE-2022-46410
An issue was discovered in Veritas NetBackup Flex Scale through 3.0. An attacker with non-root privileges may escalate privileges to root by using specific commands.... Read more
Affected Products : netbackup_flex_scale_appliance- Published: Dec. 04, 2022
- Modified: Apr. 24, 2025
-
7.5
HIGHCVE-2022-46405
Mastodon through 4.0.2 allows attackers to cause a denial of service (large Sidekiq pull queue) by creating bot accounts that follow attacker-controlled accounts on certain other servers associated with a wildcard DNS A record, such that there is uncontro... Read more
Affected Products : mastodon- Published: Dec. 04, 2022
- Modified: Apr. 24, 2025
-
6.1
MEDIUMCVE-2022-46391
AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.... Read more
- Published: Dec. 04, 2022
- Modified: Apr. 24, 2025
-
6.5
MEDIUMCVE-2022-45674
Tenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.... Read more
- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
6.5
MEDIUMCVE-2022-45673
Tenda AC6V1.0 V15.03.05.19 is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolRestoreSet.... Read more
- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
7.5
HIGHCVE-2022-45672
Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the formWx3AuthorizeSet function.... Read more
- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
7.5
HIGHCVE-2022-45671
Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the appData parameter in the formSetAppFilterRule function.... Read more
- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
7.5
HIGHCVE-2022-45670
Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the ping1 parameter in the formSetAutoPing function.... Read more
- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
7.5
HIGHCVE-2022-45669
Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the index parameter in the formWifiMacFilterGet function.... Read more
- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
6.5
MEDIUMCVE-2022-45668
Tenda i22 V1.0.0.3(4687) is vulnerable to Cross Site Request Forgery (CSRF) via function fromSysToolReboot.... Read more
- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025