Vulnerabilities (CVE)

Total 291487 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-24447 1 Adobe 1 Coldfusion 2025-04-23 N/A 9.1 CRITICAL
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user resulting in a High impact to Confidentiality and Integrity. Exploitation of this issue does not require user interaction.
CVE-2025-30282 1 Adobe 1 Coldfusion 2025-04-23 N/A 9.1 CRITICAL
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass authentication mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.
CVE-2025-30294 1 Adobe 1 Coldfusion 2025-04-23 N/A 6.8 MEDIUM
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerability to bypass security protections and gain unauthorized read access. Exploitation of this issue does not require user interaction and scope is changed.
CVE-2024-4306 1 Ofofonobsdev 1 Hubbank 2025-04-23 N/A 9.9 CRITICAL
Critical unrestricted file upload vulnerability in HubBank affecting version 1.0.2. This vulnerability allows a registered user to upload malicious PHP files via upload document fields, resulting in webshell execution.
CVE-2024-4307 1 Ofofonobsdev 1 Hubbank 2025-04-23 N/A 8.1 HIGH
SQL injection vulnerability in HubBank affecting version 1.0.2. This vulnerability could allow an attacker to send a specially crafted SQL query to the database through different endpoints (/accounts/activities.php?id=1, /accounts/view-deposit.php?id=1, /accounts/view_cards. php?id=1, /accounts/wire-transfer.php?id=1 and /accounts/wiretransfer-pending.php?id=1, id parameter) and retrieve the information stored in the database.
CVE-2024-4308 1 Ofofonobsdev 1 Hubbank 2025-04-23 N/A 8.1 HIGH
SQL injection vulnerability in HubBank affecting version 1.0.2. This vulnerability could allow an attacker to send a specially crafted SQL query to the database through different endpoints (/admin/view_users.php?id=1,/admin/viewloan-trans.php?id=1,/admin/view-deposit.php?id=1,/admin/view-domtrans.php?id=1, /admin/delete_cards.php?id=1,/admin/view_cards.php?id=1 and /admin/view_users.php?id=1, id parameter) and retrieve the information stored in the database.
CVE-2024-4309 1 Ofofonobsdev 1 Hubbank 2025-04-23 N/A 8.1 HIGH
SQL injection vulnerability in HubBank affecting version 1.0.2. This vulnerability could allow an attacker to send a specially crafted SQL query to the database through different endpoints (/user/transaction.php?id=1, /user/credit-debit_transaction.php?id=1,/user/view_transaction. php?id=1 and /user/viewloantrans.php?id=1, id parameter) and retrieve the information stored in the database.
CVE-2024-4310 1 Ofofonobsdev 1 Hubbank 2025-04-23 N/A 6.3 MEDIUM
Cross-site Scripting (XSS) vulnerability in HubBank affecting version 1.0.2. This vulnerability allows an attacker to send a specially crafted JavaScript payload to registration and profile forms and trigger the payload when any authenticated user loads the page, resulting in a session takeover.
CVE-2017-18591 1 Dev4press 1 Gd Rating System 2025-04-23 4.3 MEDIUM 6.1 MEDIUM
The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php.
CVE-2025-29710 1 Torrahclef 1 Company Website Cms 2025-04-23 N/A 6.1 MEDIUM
SourceCodester Company Website CMS 1.0 is vulnerable to Cross Site Scripting (XSS) via /dashboard/Services.
CVE-2025-29709 1 Torrahclef 1 Company Website Cms 2025-04-23 N/A 9.8 CRITICAL
SourceCodester Company Website CMS 1.0 has a File upload vulnerability via the "Create portfolio" file /dashboard/portfolio.
CVE-2025-29708 1 Torrahclef 1 Company Website Cms 2025-04-23 N/A 9.8 CRITICAL
SourceCodester Company Website CMS 1.0 contains a file upload vulnerability via the "Create Services" file /dashboard/Services.
CVE-2023-24204 1 Oretnom23 1 Simple Customer Relationship Management System 2025-04-23 N/A 5.4 MEDIUM
SQL injection vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitrary code via the name parameter in get-quote.php.
CVE-2023-24203 1 Oretnom23 1 Simple Customer Relationship Management System 2025-04-23 N/A 5.4 MEDIUM
Cross Site Scripting vulnerability in SourceCodester Simple Customer Relationship Management System v1.0 allows attacker to execute arbitary code via the company or query parameter(s).
CVE-2025-27892 1 Shopware 1 Shopware 2025-04-23 N/A 6.8 MEDIUM
Shopware prior to version 6.5.8.13 is affected by a SQL injection vulnerability in the /api/search/order endpoint. NOTE: this issue exists because of a CVE-2024-22406 and CVE-2024-42357 regression.
CVE-2025-29471 1 Nagios 1 Log Server 2025-04-23 N/A 8.3 HIGH
Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code via a payload into the Email field.
CVE-2025-22911 1 Edimax 2 Re11s, Re11s Firmware 2025-04-23 N/A 5.6 MEDIUM
RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formiNICbasicREP function.
CVE-2023-43768 1 Couchbase 1 Couchbase Server 2025-04-23 N/A 7.5 HIGH
An issue was discovered in Couchbase Server 6.6.x through 7.2.0, before 7.1.5 and 7.2.1. Unauthenticated users may cause memcached to run out of memory via large commands.
CVE-2025-3698 1 Tecno 1 Carlcare 2025-04-23 N/A 7.5 HIGH
Interface exposure vulnerability in the mobile application (com.transsion.carlcare) may lead to information leakage risk.
CVE-2023-49338 1 Couchbase 1 Couchbase Server 2025-04-23 N/A 7.5 HIGH
Couchbase Server 7.1.x and 7.2.x before 7.2.4 does not require authentication for the /admin/stats and /admin/vitals endpoints on TCP port 8093 of localhost.