Export limit exceeded: 339825 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (339825 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2022-41603 | 1 Huawei | 2 Emui, Harmonyos | 2025-05-14 | 3.4 Low |
| The phones have the heap overflow, out-of-bounds read, and null pointer vulnerabilities in the fingerprint trusted application (TA).Successful exploitation of this vulnerability may affect the fingerprint service. | ||||
| CVE-2022-41305 | 1 Autodesk | 1 Subassembly Composer | 2025-05-14 | 7.8 High |
| A maliciously crafted PKT file when consumed through SubassemblyComposer.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | ||||
| CVE-2022-2865 | 1 Gitlab | 1 Gitlab | 2025-05-14 | 7.3 High |
| A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, 15.2 to 15.2.4 and 15.3 prior to 15.3.2. It was possible to exploit a vulnerability in setting the labels colour feature which could lead to a stored XSS that allowed attackers to perform arbitrary actions on behalf of victims at client side. | ||||
| CVE-2024-12302 | 1 Icegram | 1 Icegram Engage | 2025-05-14 | 6.1 Medium |
| The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its Campaign settings, which could allow authors and above to perform Stored Cross-Site Scripting attacks | ||||
| CVE-2024-12311 | 1 Icegram | 1 Email Subscribers \& Newsletters | 2025-05-14 | 6.5 Medium |
| The Email Subscribers by Icegram Express WordPress plugin before 5.7.44 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks | ||||
| CVE-2022-3506 | 1 Never5 | 1 Related Posts | 2025-05-14 | 5.4 Medium |
| Cross-site Scripting (XSS) - Stored in GitHub repository barrykooij/related-posts-for-wp prior to 2.1.3. | ||||
| CVE-2024-10102 | 1 Robosoft | 1 Robo Gallery | 2025-05-14 | 2.7 Low |
| The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its Gallery settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks | ||||
| CVE-2024-8855 | 1 Wpmarka | 1 Wordpress Auction | 2025-05-14 | 9.8 Critical |
| The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitize and escape a parameter before using it in a SQL statement, allowing editors and above to perform SQL injection attacks | ||||
| CVE-2024-8857 | 1 Wpmarka | 1 Wordpress Auction | 2025-05-14 | 4.8 Medium |
| The WordPress Auction Plugin WordPress plugin through 3.7 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Stored Cross-Site Scripting attacks. | ||||
| CVE-2025-3819 | 1 Phpgurukul | 1 Men Salon Management System | 2025-05-14 | 7.3 High |
| A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/search-appointment.php. The manipulation of the argument searchdata leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | ||||
| CVE-2023-43958 | 1 Kishan0725 | 1 Hospital Management System | 2025-05-14 | 9.8 Critical |
| An arbitrary file upload vulnerability in the component /jquery-file-upload/server/php/index.php of Hospital Management System v4.0 allows an unauthenticated attacker to upload any file to the server and execute arbitrary code. | ||||
| CVE-2025-29568 | 1 Code-projects | 1 Online Class And Exam Scheduling System | 2025-05-14 | 4.8 Medium |
| A vulnerability has been discovered in the code-projects Online Class and Exam Scheduling System 1.0. The issue affects some unknown features in the file /Scheduling/pages/class_sched.php. Manipulating the class parameter can lead to cross-site scripting (XSS). | ||||
| CVE-2025-44134 | 1 Code-projects | 1 Online Class And Exam Scheduling System | 2025-05-14 | 6.5 Medium |
| A vulnerability was found in Code-Projects Online Class and Exam Scheduling System 1.0 in the file /Scheduling/pages/class_save.php. Manipulation of parameter class will lead to SQL injection attacks. | ||||
| CVE-2025-44135 | 1 Code-projects | 1 Online Class And Exam Scheduling System | 2025-05-14 | 6.5 Medium |
| A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0 in /Scheduling/pages/profile_update.php. Manipulating the parameter username will cause SQL injection attacks. | ||||
| CVE-2025-47899 | 2025-05-14 | N/A | ||
| Not used | ||||
| CVE-2025-47898 | 2025-05-14 | N/A | ||
| Not used | ||||
| CVE-2025-47897 | 2025-05-14 | N/A | ||
| Not used | ||||
| CVE-2025-47896 | 2025-05-14 | N/A | ||
| Not used | ||||
| CVE-2025-47895 | 2025-05-14 | N/A | ||
| Not used | ||||
| CVE-2025-47894 | 2025-05-14 | N/A | ||
| Not used | ||||