Search Results (328251 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-26687 1 Cs-cart 1 Cs-cart Multivendor 2025-04-24 8.8 High
Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to obtain sensitive information via the product_data parameter in the PDF Add-on.
CVE-2023-26688 1 Cs-cart 1 Cs-cart Multivendor 2025-04-24 5.4 Medium
Cross Site Scripting (XSS) vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via the product_data parameter of add/edit product in the administration interface.
CVE-2023-26689 1 Cs-cart 1 Cs-cart Multivendor 2025-04-24 9.8 Critical
An issue discovered in CS-Cart MultiVendor 4.16.1 allows attackers to alter arbitrary user account profiles via crafted post request.
CVE-2023-26690 1 Cs-cart 1 Cs-cart Multivendor 2025-04-24 8.8 High
File Upload vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via File Manager/Editor component in the vendor or admin menu.
CVE-2023-26691 1 Cs-cart 1 Cs-cart Multivendor 2025-04-24 7.2 High
Directory Traversal vulnerability in CS-Cart MultiVendor 4.16.1 allows remote attackers to run arbitrary code via crafted zip file when installing a new add-on.
CVE-2024-49995 1 Redhat 1 Enterprise Linux 2025-04-24 7.1 High
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2022-46414 1 Veritas 2 Access Appliance, Netbackup Flex Scale Appliance 2025-04-24 9.8 Critical
An issue was discovered in Veritas NetBackup Flex Scale through 3.0 and Access Appliance through 8.0.100. Unauthenticated remote command execution can occur via the management portal.
CVE-2022-45990 1 Ecommerce-website Project 1 Ecommerce-website 2025-04-24 6.1 Medium
A cross-site scripting (XSS) vulnerability in the component /signup_script.php of Ecommerce-Website v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the eMail parameter.
CVE-2022-45912 1 Zimbra 1 Collaboration 2025-04-24 7.2 High
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0. Remote code execution can occur through ClientUploader by an authenticated admin user. An authenticated admin user can upload files through the ClientUploader utility, and traverse to any other directory for remote code execution.
CVE-2022-45771 1 Pwndoc Project 1 Pwndoc 2025-04-24 8.8 High
An issue in the /api/audits component of Pwndoc v0.5.3 allows attackers to escalate privileges and execute arbitrary code via uploading a crafted audit file.
CVE-2022-45769 1 Clicshopping 1 Clicshopping V3 2025-04-24 6.1 Medium
A cross-site scripting (XSS) vulnerability in ClicShopping_V3 v3.402 allows attackers to execute arbitrary web scripts or HTML via a crafted URL parameter.
CVE-2022-45656 1 Tendacn 2 Ac6, Ac6 Firmware 2025-04-24 7.5 High
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the time parameter in the fromSetSysTime function.
CVE-2022-45655 1 Tendacn 2 Ac6, Ac6 Firmware 2025-04-24 7.5 High
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the timeZone parameter in the form_fast_setting_wifi_set function.
CVE-2022-45654 1 Tendacn 2 Ac6, Ac6 Firmware 2025-04-24 7.5 High
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the ssid parameter in the form_fast_setting_wifi_set function.
CVE-2022-45653 1 Tendacn 2 Ac6, Ac6 Firmware 2025-04-24 7.5 High
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the page parameter in the fromNatStaticSetting function.
CVE-2022-45652 1 Tendacn 2 Ac6, Ac6 Firmware 2025-04-24 9.1 Critical
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the startIp parameter in the formSetPPTPServer function.
CVE-2022-45651 1 Tendacn 2 Ac6, Ac6 Firmware 2025-04-24 9.1 Critical
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the list parameter in the formSetVirtualSer function.
CVE-2022-45647 1 Tendacn 2 Ac6, Ac6 Firmware 2025-04-24 7.5 High
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the limitSpeed parameter in the formSetClientState function.
CVE-2022-45646 1 Tendacn 2 Ac6, Ac6 Firmware 2025-04-24 7.5 High
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the limitSpeedUp parameter in the formSetClientState function.
CVE-2022-45644 1 Tendacn 2 Ac6, Ac6 Firmware 2025-04-24 7.5 High
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the deviceId parameter in the formSetClientState function.