Total
291487 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-2766 | 1 Weaver | 1 E-office | 2025-04-25 | 5.0 MEDIUM | 5.3 MEDIUM |
A vulnerability was found in Weaver OA 9.5 and classified as problematic. This issue affects some unknown processing of the file /building/backmgr/urlpage/mobileurl/configfile/jx2_config.ini. The manipulation leads to files or directories accessible. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-229271. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |||||
CVE-2023-2765 | 1 Weaver | 1 E-office | 2025-04-25 | 4.0 MEDIUM | 4.3 MEDIUM |
A vulnerability has been found in Weaver OA up to 9.5 and classified as problematic. This vulnerability affects unknown code of the file /E-mobile/App/System/File/downfile.php. The manipulation of the argument url leads to absolute path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-229270 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |||||
CVE-2023-42875 | 1 Apple | 6 Ipados, Iphone Os, Macos and 3 more | 2025-04-25 | N/A | 7.3 HIGH |
Processing web content may lead to arbitrary code execution. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17, Safari 17. The issue was addressed with improved memory handling. | |||||
CVE-2023-38614 | 1 Apple | 3 Ipados, Iphone Os, Macos | 2025-04-25 | N/A | 4.3 MEDIUM |
A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to access sensitive user data. | |||||
CVE-2025-33027 | 1 Bandisoft | 1 Bandizip | 2025-04-25 | N/A | 6.1 MEDIUM |
In Bandisoft Bandizip through 7.37, there is a Mark-of-the-Web Bypass Vulnerability. This vulnerability allows attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Bandizip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, Bandizip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. | |||||
CVE-2025-28399 | 1 Exrick | 1 Xmall | 2025-04-25 | N/A | 9.8 CRITICAL |
An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of the Address Controller class. | |||||
CVE-2020-29367 | 1 Blosc | 1 C-blosc2 | 2025-04-25 | 9.3 HIGH | 7.8 HIGH |
blosc2.c in Blosc C-Blosc2 through 2.0.0.beta.5 has a heap-based buffer overflow when there is a lack of space to write compressed data. | |||||
CVE-2023-37187 | 1 Blosc | 1 C-blosc2 | 2025-04-25 | N/A | 7.5 HIGH |
C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the zfp/blosc2-zfp.c zfp_acc_decompress. function. | |||||
CVE-2023-37186 | 1 Blosc | 1 C-blosc2 | 2025-04-25 | N/A | 7.5 HIGH |
C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference in ndlz/ndlz8x8.c via a NULL pointer to memset. | |||||
CVE-2023-37185 | 1 Blosc | 1 C-blosc2 | 2025-04-25 | N/A | 7.5 HIGH |
C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the function zfp_prec_decompress at zfp/blosc2-zfp.c. | |||||
CVE-2023-37188 | 1 Blosc | 1 C-blosc2 | 2025-04-25 | N/A | 7.5 HIGH |
C-blosc2 before 2.9.3 was discovered to contain a NULL pointer dereference via the function zfp_rate_decompress at zfp/blosc2-zfp.c. | |||||
CVE-2025-29213 | 1 Jeewms | 1 Jeewms | 2025-04-25 | N/A | 5.5 MEDIUM |
A zip slip vulnerability in the component \service\migrate\MigrateForm.java of JEEWMS v3.7 allows attackers to execute arbitrary code via a crafted Zip file. | |||||
CVE-2024-44843 | 1 Steve-community | 1 Steve | 2025-04-25 | N/A | 5.9 MEDIUM |
An issue in the web socket handshake process of SteVe v3.7.1 allows attackers to bypass authentication and execute arbitrary coammands via supplying crafted OCPP requests. | |||||
CVE-2024-3369 | 1 Anisha | 1 Car Rental | 2025-04-25 | 6.5 MEDIUM | 6.3 MEDIUM |
A vulnerability, which was classified as critical, has been found in code-projects Car Rental 1.0. Affected by this issue is some unknown functionality of the file add-vehicle.php. The manipulation of the argument Upload Image leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-259490 is the identifier assigned to this vulnerability. | |||||
CVE-2025-26268 | 1 Dragonflydb | 1 Dragonfly | 2025-04-25 | N/A | 3.3 LOW |
DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted Redis command. The validity of the scan cursor was not checked. | |||||
CVE-2024-55211 | 1 Think | 2 Tk-rt-wr135g, Tk-rt-wr135g Firmware | 2025-04-25 | N/A | 8.4 HIGH |
An issue in Think Router Tk-Rt-Wr135G V3.0.2-X000 allows attackers to bypass authentication via a crafted cookie. | |||||
CVE-2025-43015 | 1 Jetbrains | 1 Rubymine | 2025-04-25 | N/A | 8.3 HIGH |
In JetBrains RubyMine before 2025.1 remote Interpreter overwrote ports to listen on all interfaces | |||||
CVE-2024-25407 | 1 Steve-community | 1 Steve | 2025-04-25 | N/A | 7.5 HIGH |
SteVe v3.6.0 was discovered to use predictable transaction ID's when receiving a StartTransaction request. This vulnerability can allow attackers to cause a Denial of Service (DoS) by using the predicted transaction ID's to terminate other transactions. | |||||
CVE-2025-29449 | 1 Lm21 | 1 Twonav | 2025-04-25 | N/A | 6.5 MEDIUM |
An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the link identification function. | |||||
CVE-2025-29460 | 1 Mybb | 1 Mybb | 2025-04-25 | N/A | 7.6 HIGH |
An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add Mycode function. NOTE: the Supplier disputes this because of the allowed actions of Board administrators and because of SSRF mitigation. |