Search Results (34344 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-26360 1 Amd 36 Enterprise Driver, Radeon Pro Software, Radeon Pro W6300m and 33 more 2025-05-01 7.8 High
An attacker with local access to the system can make unauthorized modifications of the security configuration of the SOC registers. This could allow potential corruption of AMD secure processor’s encrypted memory contents which may lead to arbitrary code execution in ASP.
CVE-2023-7165 1 Jetbackup 1 Jetbackup 2025-05-01 7.5 High
The JetBackup WordPress plugin before 2.0.9.9 doesn't use index files to prevent public directory listing of sensitive directories in certain configurations, which allows malicious actors to leak backup files.
CVE-2024-30203 3 Debian, Gnu, Redhat 4 Debian Linux, Emacs, Org Mode and 1 more 2025-05-01 5.5 Medium
In Emacs before 29.3, Gnus treats inline MIME contents as trusted.
CVE-2024-0855 1 Spiffyplugins 1 Spiffy Calendar 2025-05-01 5.3 Medium
The Spiffy Calendar WordPress plugin before 4.9.9 doesn't check the event_author parameter, and allows any user to alter it when creating an event, leading to deceiving users/admins that a page was created by a Contributor+.
CVE-2024-40407 1 Cybelesoft 1 Thinfinity Workspace 2025-05-01 7.5 High
A full path disclosure in Cybele Software Thinfinity Workspace before v7.0.2.113 allows attackers to obtain the root path of the application via unspecified vectors.
CVE-2022-45182 1 Pistar 1 Pi-star Digital Voice Dashboard 2025-05-01 9.8 Critical
Pi-Star_DV_Dash (for Pi-Star DV) before 5aa194d mishandles the module parameter.
CVE-2022-44557 1 Huawei 2 Emui, Harmonyos 2025-05-01 7.5 High
The SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system files. Successful exploitation of this vulnerability may affect data confidentiality.
CVE-2022-44555 1 Huawei 2 Emui, Harmonyos 2025-05-01 7.5 High
The DDMP/ODMF module has a service hijacking vulnerability. Successful exploit of this vulnerability may cause services to be unavailable.
CVE-2022-44554 1 Huawei 2 Emui, Harmonyos 2025-05-01 7.5 High
The power module has a vulnerability in permission verification. Successful exploitation of this vulnerability may cause abnormal status of a module on the device.
CVE-2022-44553 1 Huawei 2 Emui, Harmonyos 2025-05-01 5.3 Medium
The HiView module has a vulnerability of not filtering third-party apps out when the HiView module traverses to invoke the system provider. Successful exploitation of this vulnerability may cause third-party apps to start periodically.
CVE-2022-44089 1 Ecisp 1 Espcms 2025-05-01 9.8 Critical
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE.
CVE-2022-44088 1 Ecisp 1 Espcms 2025-05-01 9.8 Critical
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION.
CVE-2022-44087 1 Ecisp 1 Espcms 2025-05-01 9.8 Critical
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOOM_HIGHT.
CVE-2022-43679 1 Owncloud 1 Owncloud 2025-05-01 4.2 Medium
The Docker image of ownCloud Server through 10.11 contains a misconfiguration that renders the trusted_domains config useless. This could be abused to spoof the URL in password-reset e-mail messages.
CVE-2022-41339 1 Zohocorp 1 Manageengine Mobile Device Manager Plus 2025-05-01 7.8 High
In Zoho ManageEngine Mobile Device Manager Plus before 10.1.2207.5, the User Administration module allows privilege escalation.
CVE-2022-38651 1 Vmware 1 Hyperic Server 2025-05-01 9.8 Critical
A security filter misconfiguration exists in VMware Hyperic Server 5.8.6. Exploitation of this vulnerability enables a malicious party to bypass some authentication requirements when issuing requests to Hyperic Server. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2024-28753 1 Raspap 1 Raspap 2025-05-01 6.5 Medium
RaspAP (aka raspap-webgui) through 3.0.9 allows remote attackers to read the /etc/passwd file via a crafted request.
CVE-2024-28754 1 Raspap 1 Raspap 2025-05-01 7.5 High
RaspAP (aka raspap-webgui) through 3.0.9 allows remote attackers to cause a persistent denial of service (bricking) via a crafted request.
CVE-2023-6444 1 Castos 1 Seriously Simple Podcasting 2025-05-01 5.3 Medium
The Seriously Simple Podcasting WordPress plugin before 3.0.0 discloses the Podcast owner's email address (which by default is the admin email address) via an unauthenticated crafted request.
CVE-2023-7247 1 Wp-buy 1 Login As User Or Customer \(user Switching\) 2025-05-01 4.9 Medium
The Login as User or Customer WordPress plugin through 3.8 does not prevent users to log in as any other user on the site.