Latest CVE Feed
-
5.4
MEDIUMCVE-2023-20249
A vulnerability in the web-based management interface of Cisco TelePresence Management Suite (TMS) Software could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is... Read more
Affected Products : telepresence_management_suite- Published: Apr. 24, 2024
- Modified: Apr. 24, 2025
-
9.8
CRITICALCVE-2023-36645
SQL injection vulnerability in ITB-GmbH TradePro v9.5, allows remote attackers to run SQL queries via oordershow component in customer function.... Read more
Affected Products : tradepro- Published: Apr. 04, 2024
- Modified: Apr. 24, 2025
-
7.5
HIGHCVE-2023-36644
Incorrect Access Control in ITB-GmbH TradePro v9.5, allows remote attackers to receive all order confirmations from the online shop via the printmail plugin.... Read more
Affected Products : tradepro- Published: Apr. 04, 2024
- Modified: Apr. 24, 2025
-
9.8
CRITICALCVE-2023-26686
File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the image upload feature when customizing a shop.... Read more
Affected Products : cs-cart_multivendor- Published: Sep. 25, 2024
- Modified: Apr. 24, 2025
-
8.8
HIGHCVE-2023-26687
Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to obtain sensitive information via the product_data parameter in the PDF Add-on.... Read more
Affected Products : cs-cart_multivendor- Published: Sep. 25, 2024
- Modified: Apr. 24, 2025
-
5.4
MEDIUMCVE-2023-26688
Cross Site Scripting (XSS) vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the product_data parameter of add/edit product in the administration interface.... Read more
Affected Products : cs-cart_multivendor- Published: Sep. 25, 2024
- Modified: Apr. 24, 2025
-
9.8
CRITICALCVE-2023-26689
An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.... Read more
Affected Products : cs-cart_multivendor- Published: Sep. 25, 2024
- Modified: Apr. 24, 2025
-
8.8
HIGHCVE-2023-26690
File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File Manager/Editor component in the vendor or admin menu.... Read more
Affected Products : cs-cart_multivendor- Published: Sep. 25, 2024
- Modified: Apr. 24, 2025
-
7.2
HIGHCVE-2023-26691
Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via crafted zip file when installing a new add-on.... Read more
Affected Products : cs-cart_multivendor- Published: Sep. 25, 2024
- Modified: Apr. 24, 2025
-
9.8
CRITICALCVE-2022-46414
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Unauthenticated remote command execution can occur via the management portal.... Read more
- Published: Dec. 04, 2022
- Modified: Apr. 24, 2025
-
6.1
MEDIUMCVE-2022-45990
A cross-site scripting (XSS) vulnerability in the component /signup_script.php of Ecommerce-Website v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the eMail parameter.... Read more
Affected Products : ecommerce-website- Published: Dec. 05, 2022
- Modified: Apr. 24, 2025
-
7.2
HIGHCVE-2022-45912
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. Remote code execution can occur through ClientUploader by an authenticated admin user. An authenticated admin user can upload files through the ClientUploader utility, and traverse to a... Read more
Affected Products : collaboration- Published: Dec. 05, 2022
- Modified: Apr. 24, 2025
-
8.8
HIGHCVE-2022-45771
An issue in the /api/audits component of Pwndoc v0.5.3 allows attackers to escalate privileges and execute arbitrary code via uploading a crafted audit file.... Read more
Affected Products : pwndoc- Published: Dec. 05, 2022
- Modified: Apr. 24, 2025
-
6.1
MEDIUMCVE-2022-45769
A cross-site scripting (XSS) vulnerability in ClicShopping_V3 v3.402 allows attackers to execute arbitrary web scripts or HTML via a crafted URL parameter.... Read more
Affected Products : clicshopping_v3- Published: Dec. 05, 2022
- Modified: Apr. 24, 2025
-
7.5
HIGHCVE-2022-45656
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the time parameter in the fromSetSysTime function.... Read more
- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
7.5
HIGHCVE-2022-45655
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the timeZone parameter in the form_fast_setting_wifi_set function.... Read more
- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
7.5
HIGHCVE-2022-45654
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the ssid parameter in the form_fast_setting_wifi_set function.... Read more
- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
7.5
HIGHCVE-2022-45653
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the page parameter in the fromNatStaticSetting function.... Read more
- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
9.1
CRITICALCVE-2022-45652
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the startIp parameter in the formSetPPTPServer function.... Read more
- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025
-
9.1
CRITICALCVE-2022-45651
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the list parameter in the formSetVirtualSer function.... Read more
- Published: Dec. 02, 2022
- Modified: Apr. 24, 2025