Vulnerabilities (CVE)

Total 79929 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-22912 1 Swftools 1 Swftools 2025-06-17 N/A 7.8 HIGH
A global-buffer-overflow was found in SWFTools v0.9.2, in the function countline at swf5compiler.flex:327. It allows an attacker to cause code execution.
CVE-2024-22567 1 Mingsoft 1 Mcms 2025-06-17 N/A 8.8 HIGH
File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do.
CVE-2023-5041 1 Tracktheclick 1 Track The Click 2025-06-17 N/A 8.8 HIGH
The Track The Click WordPress plugin before 0.3.12 does not properly sanitize query parameters to the stats REST endpoint before using them in a database query, allowing a logged in user with an author role or higher to perform time based blind SQLi attacks on the database.
CVE-2023-51282 1 Mingsoft 1 Mcms 2025-06-17 N/A 7.5 HIGH
An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter.
CVE-2023-25365 1 Octobercms 1 October 2025-06-17 N/A 7.8 HIGH
Cross Site Scripting vulnerability found in October CMS v.3.2.0 allows local attacker to execute arbitrary code via the file type .mp3
CVE-2024-34469 1 Rukovoditel 1 Rukovoditel 2025-06-17 N/A 7.1 HIGH
Rukovoditel before 3.5.3 allows XSS via user_photo to index.php?module=users/registration&action=save.
CVE-2024-28521 1 Netentsec 2 Application Security Gateway Firmware, Ns-asg 2025-06-17 N/A 7.8 HIGH
SQL Injection vulnerability in Netcome NS-ASG Application Security Gateway v.6.3.1 allows a local attacker to execute arbitrary code and obtain sensitive information via a crafted script to the loginid parameter of the /singlelogin.php component.
CVE-2025-46568 1 Stirlingpdf 1 Stirling Pdf 2025-06-17 N/A 7.5 HIGH
Stirling-PDF is a locally hosted web application that allows you to perform various operations on PDF files. Prior to version 0.45.0, Stirling-PDF is vulnerable to SSRF-induced arbitrary file read. WeasyPrint redefines a set of HTML tags, including img, embed, object, and others. The references to several files inside, allow the attachment of content from any webpage or local file to a PDF. This allows the attacker to read any file on the server, including sensitive files and configuration files. All users utilizing this feature will be affected. This issue has been patched in version 0.45.0.
CVE-2023-41099 1 Atos 1 Eviden Cardos Api 2025-06-17 N/A 7.8 HIGH
In the Windows installer in Atos Eviden CardOS API before 5.5.5.2811, Local Privilege Escalation can occur.(from a regular user to SYSTEM).
CVE-2024-29366 1 Dlink 2 Dir-845l, Dir-845l Firmware 2025-06-17 N/A 8.8 HIGH
A command injection vulnerability exists in the cgibin binary in DIR-845L router firmware <= v1.01KRb03.
CVE-2024-58134 1 Mojolicious 1 Mojolicious 2025-06-17 N/A 8.1 HIGH
Mojolicious versions from 0.999922 through 9.40 for Perl uses a hard coded string, or the application's class name, as a HMAC session secret by default. These predictable default secrets can be exploited to forge session cookies. An attacker who knows or guesses the secret could compute valid HMAC signatures for the session cookie, allowing them to tamper with or hijack another user’s session.
CVE-2023-4818 1 Paxtechnology 2 A920, Paydroid 2025-06-17 N/A 7.6 HIGH
PAX A920 device allows to downgrade bootloader due to a bug in its version check. The signature is correctly checked and only bootloader signed by PAX can be used.  The attacker must have physical USB access to the device in order to exploit this vulnerability.
CVE-2023-27001 1 Egerie 1 Egerie 2025-06-17 N/A 8.8 HIGH
An issue discovered in Egerie Risk Manager v4.0.5 allows attackers to bypass the signature mechanism and tamper with the values inside the JWT payload resulting in privilege escalation.
CVE-2025-28062 1 Frappe 1 Erpnext 2025-06-17 N/A 8.1 HIGH
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allows an attacker to perform unauthorized actions such as user deletion, password resets, and privilege escalation due to missing CSRF protections.
CVE-2025-45242 1 Rhymix 1 Rhymix 2025-06-17 N/A 7.7 HIGH
Rhymix v2.1.22 was discovered to contain an arbitrary file deletion vulnerability via the procFileAdminEditImage method in /file/file.admin.controller.php.
CVE-2025-4932 1 Projectworlds 1 Online Lawyer Management System 2025-06-17 7.5 HIGH 7.3 HIGH
A vulnerability, which was classified as critical, has been found in projectworlds Online Lawyer Management System 1.0. Affected by this issue is some unknown functionality of the file /lawyer_registation.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-4802 1 Gnu 1 Glibc 2025-06-17 N/A 7.8 HIGH
Untrusted LD_LIBRARY_PATH environment variable vulnerability in the GNU C Library version 2.27 to 2.38 allows attacker controlled loading of dynamically shared library in statically compiled setuid binaries that call dlopen (including internal dlopen calls after setlocale or calls to NSS functions such as getaddrinfo).
CVE-2023-40284 1 Supermicro 6 X11sae-f, X11sae-f Firmware, X11sse-f and 3 more 2025-06-17 N/A 8.3 HIGH
An issue was discovered on Supermicro X11SSM-F, X11SAE-F, and X11SSE-F 1.66 devices. An attacker could exploit an XSS issue.
CVE-2024-2053 1 Articatech 1 Artica Proxy 2025-06-17 N/A 7.5 HIGH
The Artica Proxy administrative web application will deserialize arbitrary PHP objects supplied by unauthenticated users and subsequently enable code execution as the "www-data" user. This issue was demonstrated on version 4.50 of the The Artica-Proxy administrative web application attempts to prevent local file inclusion. These protections can be bypassed and arbitrary file requests supplied by unauthenticated users will be returned according to the privileges of the "www-data" user.
CVE-2024-29862 1 Chirpstack 2 Gateway Bridge, Mqtt Forwarder 2025-06-17 N/A 7.5 HIGH
The Kerlink firewall in ChirpStack chirpstack-mqtt-forwarder before 4.2.1 and chirpstack-gateway-bridge before 4.0.11 wrongly accepts certain TCP packets when a connection is not in the ESTABLISHED state.