Total
286780 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2025-2603 | 2025-03-25 | 6.3 Medium | ||
A vulnerability was found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. This issue affects some unknown processing of the file deactivate.php. The manipulation of the argument ID leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | ||||
CVE-2025-29401 | 2025-03-25 | 9.8 Critical | ||
An arbitrary file upload vulnerability in the component /views/plugin.php of emlog pro v2.5.7 allows attackers to execute arbitrary code via uploading a crafted PHP file. | ||||
CVE-2025-0289 | 2025-03-25 | 7.8 High | ||
Paragon Partition Manager version 17, both community and Business versions, contain an insecure kernel resource access vulnerability facilitated by the driver not validating the MappedSystemVa pointer before passing it to HalReturnToFirmware, which can allows an attacker the ability to compromise the service. | ||||
CVE-2024-8033 | 2 Google, Microsoft | 2 Chrome, Windows | 2025-03-25 | 4.3 Medium |
Inappropriate implementation in WebApp Installs in Google Chrome on Windows prior to 128.0.6613.84 allowed an attacker who convinced a user to install a malicious application to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low) | ||||
CVE-2024-57061 | 2025-03-25 | 9.8 Critical | ||
An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to execute arbitrary code via the insecure Electron Fuses configuration. | ||||
CVE-2024-48987 | 1 Snipeitapp | 1 Snipe-it | 2025-03-25 | 6.6 Medium |
Snipe-IT before 7.0.10 allows remote code execution (associated with cookie serialization) when an attacker knows the APP_KEY. This is exacerbated by .env files, available from the product's repository, that have default APP_KEY values. | ||||
CVE-2024-45429 | 1 Wpengine | 1 Advanced Custom Fields | 2025-03-25 | 6.1 Medium |
Cross-site scripting vulnerability exists in Advanced Custom Fields versions 6.3.5 and earlier and Advanced Custom Fields Pro versions 6.3.5 and earlier. If an attacker with the 'capability' setting privilege which is set in the product settings stores an arbitrary script in the field label, the script may be executed on the web browser of the logged-in user with the same privilege as the attacker's. | ||||
CVE-2024-45372 | 1 Planex | 2 Mzk-dp300n, Mzk-dp300n Firmware | 2025-03-25 | 6.5 Medium |
MZK-DP300N firmware versions 1.04 and earlier contains a cross-site request forger vulnerability. Viewing a malicious page while logging in to the web management page of the affected product may lead the user to perform unintended operations such as changing the login password, etc. | ||||
CVE-2024-44189 | 1 Apple | 1 Macos | 2025-03-25 | 7.5 High |
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. A logic issue existed where a process may be able to capture screen contents without user consent. | ||||
CVE-2024-44177 | 1 Apple | 1 Macos | 2025-03-25 | 5.5 Medium |
A privacy issue was addressed by removing sensitive data. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to access user-sensitive data. | ||||
CVE-2024-44124 | 1 Apple | 2 Ipados, Iphone Os | 2025-03-25 | 6.5 Medium |
This issue was addressed through improved state management. This issue is fixed in iOS 18 and iPadOS 18. A malicious Bluetooth input device may bypass pairing. | ||||
CVE-2024-3477 | 2025-03-25 | 4.3 Medium | ||
The Popup Box WordPress plugin before 2.2.7 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting popups via CSRF attacks | ||||
CVE-2024-37227 | 1 Tribulant | 1 Newsletters | 2025-03-25 | 4.3 Medium |
Cross Site Request Forgery (CSRF) vulnerability in Tribulant Newsletters.This issue affects Newsletters: from n/a through 4.9.7. | ||||
CVE-2024-35560 | 1 Idccms Project | 1 Idccms | 2025-03-25 | 4.3 Medium |
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/ca_deal.php?mudi=del&dataType=&dataTypeCN. | ||||
CVE-2024-35551 | 1 Idccms Project | 1 Idccms | 2025-03-25 | 4.3 Medium |
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=add. | ||||
CVE-2024-35550 | 2025-03-25 | 6.3 Medium | ||
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/infoWeb_deal.php?mudi=rev. | ||||
CVE-2024-34947 | 2025-03-25 | 9.4 Critical | ||
Quanxun Huiju Network Technology (Beijing) Co.,Ltd IK-Q3000 3.7.10 x64 Build202401261655 was discovered to be vulnerable to an ICMP redirect attack. | ||||
CVE-2024-33328 | 1 Lumis | 1 Lumis Experience Platform | 2025-03-25 | 6.1 Medium |
A cross-site scripting (XSS) vulnerability in the component main.jsp of Lumisxp v15.0.x to v16.1.x allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the pageId parameter. | ||||
CVE-2024-30915 | 1 Objectcomputing | 1 Opendds | 2025-03-25 | 4.3 Medium |
An issue was discovered in OpenDDS commit b1c534032bb62ad4ae32609778de6b8d6c823a66, allows a local attacker to cause a denial of service and obtain sensitive information via the max_samples parameter within the DataReaderQoS component. | ||||
CVE-2024-29783 | 2025-03-25 | 6.7 Medium | ||
In tmu_get_tr_thresholds, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. |