Vulnerabilities (CVE)

Total 88200 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-45535 1 Aerocms Project 1 Aerocms 2025-04-25 N/A 4.9 MEDIUM
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the edit parameter at \admin\categories.php. This vulnerability allows attackers to access database information.
CVE-2022-45529 1 Aerocms Project 1 Aerocms 2025-04-25 N/A 4.9 MEDIUM
AeroCMS v0.0.1 was discovered to contain a SQL Injection vulnerability via the post_category_id parameter at \admin\includes\edit_post.php. This vulnerability allows attackers to access database information.
CVE-2022-42985 1 Scratch-wiki 1 Scratch Login 2025-04-25 N/A 4.8 MEDIUM
The ScratchLogin extension through 1.1 for MediaWiki does not escape verification failure messages, which allows users with administrator privileges to perform cross-site scripting (XSS).
CVE-2022-38753 1 Microfocus 1 Netiq Advanced Authentication 2025-04-25 N/A 6.3 MEDIUM
This update resolves a multi-factor authentication bypass attack
CVE-2022-38147 1 Silverstripe 1 Framework 2025-04-25 N/A 5.4 MEDIUM
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 3 of 3).
CVE-2022-38145 1 Silverstripe 1 Framework 2025-04-25 N/A 5.4 MEDIUM
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 3) via remote attackers adding a Javascript payload to a page's meta description and get it executed in the versioned history compare view.
CVE-2022-37430 1 Silverstripe 1 Framework 2025-04-25 N/A 5.4 MEDIUM
Silverstripe silverstripe/framework through 4.11 allows XSS vulnerability via href attribute of a link (issue 2 of 2).
CVE-2022-37429 1 Silverstripe 1 Framework 2025-04-25 N/A 5.4 MEDIUM
Silverstripe silverstripe/framework through 4.11 allows XSS (issue 1 of 2) via JavaScript payload to the href attribute of a link by splitting a javascript URL with white space characters.
CVE-2022-37421 1 Silverstripe 1 Silverstripe 2025-04-25 N/A 5.4 MEDIUM
Silverstripe silverstripe/cms through 4.11.0 allows XSS.
CVE-2020-23588 1 Optilinknetwork 2 Op-xt71000n, Op-xt71000n Firmware 2025-04-25 N/A 4.3 MEDIUM
A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to "Enable or Disable Ports" and to "Change port number" through " /rmtacc.asp ".
CVE-2020-23586 1 Optilinknetwork 2 Op-xt71000n, Op-xt71000n Firmware 2025-04-25 N/A 4.3 MEDIUM
A vulnerability found in OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to Add Network Traffic Control Type Rule.
CVE-2009-1142 1 Vmware 1 Open Vm Tools 2025-04-25 N/A 6.7 MEDIUM
An issue was discovered in open-vm-tools 2009.03.18-154848. Local users can gain privileges via a symlink attack on /tmp files if vmware-user-suid-wrapper is setuid root and the ChmodChownDirectory function is enabled.
CVE-2023-49034 1 Projeqtor 1 Projeqtor 2025-04-25 N/A 6.1 MEDIUM
Cross Site Scripting (XSS) vulnerability in ProjeQtOr 11.0.2 allows a remote attacker to execute arbitrary code via a crafted script to thecheckvalidHtmlText function in the ack.php and security.php files.
CVE-2023-46967 1 Enhancesoft 1 Osticket 2025-04-25 N/A 6.1 MEDIUM
Cross Site Scripting vulnerability in the sanitize function in Enhancesoft osTicket 1.18.0 allows a remote attacker to escalate privileges via a crafted support ticket.
CVE-2024-25260 1 Elfutils Project 1 Elfutils 2025-04-25 N/A 4.0 MEDIUM
elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
CVE-2025-0671 2025-04-25 N/A 6.1 MEDIUM
The Icegram Express WordPress plugin before 5.7.50 does not sanitise and escape some of its Template settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVE-2022-45887 1 Linux 1 Linux Kernel 2025-04-25 N/A 4.7 MEDIUM
An issue was discovered in the Linux kernel through 6.0.9. drivers/media/usb/ttusb-dec/ttusb_dec.c has a memory leak because of the lack of a dvb_frontend_detach call.
CVE-2022-45280 1 Eyoucms 1 Eyoucms 2025-04-25 N/A 5.4 MEDIUM
A cross-site scripting (XSS) vulnerability in the Url parameter in /login.php of EyouCMS v1.6.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2022-45221 1 Web-based Student Clearance System Project 1 Web-based Student Clearance System 2025-04-25 N/A 4.8 MEDIUM
Web-Based Student Clearance System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability in changepassword.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the txtnew_password parameter.
CVE-2022-45214 1 Sanitization Management System Project 1 Sanitization Management System 2025-04-25 N/A 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in Sanitization Management System v1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter at /php-sms/classes/Login.php.