Search Results (35019 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-46607 1 Thecosy 1 Icecms 2025-04-28 7.6 High
Incorrect access control in IceCMS v3.4.7 and before allows attackers to authenticate by entering any arbitrary values as the username and password via the loginAdmin method in the UserController.java file.
CVE-2024-42021 1 Veeam 1 One 2025-04-28 6.5 Medium
An improper access control vulnerability allows an attacker with valid access tokens to access saved credentials.
CVE-2024-42022 1 Veeam 1 One 2025-04-28 5.3 Medium
An incorrect permission assignment vulnerability allows an attacker to modify product configuration files.
CVE-2024-44571 1 Relyum 2 Rely-pcie, Rely-pcie Firmware 2025-04-28 8.8 High
RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain incorrect access control in the mService function at phpinf.php.
CVE-2024-42794 2 Kashipara, Lopalopa 2 Music Management System, Music Management System 2025-04-28 4.7 Medium
Kashipara Music Management System v1.0 is vulnerable to Incorrect Access Control via /music/ajax.php?action=save_user.
CVE-2024-42795 2 Kashipara, Lopalopa 2 Music Management System, Music Management System 2025-04-28 4.2 Medium
An Incorrect Access Control vulnerability was found in /music/view_user.php?id=3 and /music/controller.php?page=edit_user&id=3 in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to view valid user details.
CVE-2024-42796 2 Kashipara, Lopalopa 2 Music Management System, Music Management System 2025-04-28 5.9 Medium
An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_genre in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music genre entries.
CVE-2024-42798 2 Kashipara, Lopalopa 2 Music Management System, Music Management System 2025-04-28 7.6 High
An Incorrect Access Control vulnerability was found in /music/index.php?page=user_list and /music/index.php?page=edit_user in Kashipara Music Management System v1.0. This allows a low privileged attacker to take over the administrator account.
CVE-2024-38909 2 Std42, Studio42 2 Elfinder, Elfinder 2025-04-28 9.8 Critical
Studio 42 elFinder 2.1.64 is vulnerable to Incorrect Access Control. Copying files with an unauthorized extension between server directories allows an arbitrary attacker to expose secrets, perform RCE, etc.
CVE-2024-42995 1 Vtiger 1 Vtiger Crm 2025-04-28 8.3 High
VTiger CRM <= 8.1.0 does not correctly check user privileges. A low-privileged user can interact directly with the "Migration" administrative module to disable arbitrary modules.
CVE-2022-39833 1 Filecloud 1 Filecloud 2025-04-25 7.2 High
FileCloud Versions 20.2 and later allows remote attackers to potentially cause unauthorized remote code execution and access to reported API endpoints via a crafted HTTP request.
CVE-2022-38753 1 Microfocus 1 Netiq Advanced Authentication 2025-04-25 6.3 Medium
This update resolves a multi-factor authentication bypass attack
CVE-2022-36784 1 Elsight 2 Halo, Halo Firmware 2025-04-25 9.8 Critical
Elsight – Elsight Halo  Remote Code Execution (RCE) Elsight Halo web panel allows us to perform connection validation. through the POST request : /api/v1/nics/wifi/wlan0/ping we can abuse DESTINATION parameter and leverage it to remote code execution.
CVE-2022-34329 1 Ibm 1 Cics Tx 2025-04-25 5.3 Medium
IBM CICS TX 11.7 could allow an attacker to obtain sensitive information from HTTP response headers. IBM X-Force ID: 229467.
CVE-2022-45872 1 Iterm2 1 Iterm2 2025-04-25 9.8 Critical
iTerm2 before 3.4.18 mishandles a DECRQSS response.
CVE-2022-26885 1 Apache 1 Dolphinscheduler 2025-04-25 7.5 High
When using tasks to read config files, there is a risk of database password disclosure. We recommend you upgrade to version 2.0.6 or higher.
CVE-2024-20065 2 Google, Mediatek 14 Android, Mt6768, Mt6781 and 11 more 2025-04-25 4 Medium
In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08698617; Issue ID: MSV-1394.
CVE-2024-20094 1 Mediatek 21 Mt2735, Mt6833, Mt6853 and 18 more 2025-04-25 7.5 High
In Modem, there is a possible system crash due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: MOLY00843282; Issue ID: MSV-1535.
CVE-2022-36133 1 Epson 18 Tm-c3500, Tm-c3500 Firmware, Tm-c3510 and 15 more 2025-04-25 9.1 Critical
The WebConfig functionality of Epson TM-C3500 and TM-C7500 devices with firmware version WAM31500 allows authentication bypass.
CVE-2025-26268 1 Dragonflydb 1 Dragonfly 2025-04-25 3.3 Low
DragonflyDB Dragonfly before 1.27.0 allows authenticated users to cause a denial of service (daemon crash) via a crafted Redis command. The validity of the scan cursor was not checked.