Search Results (335704 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-8072 1 Mage 1 Mage-ai 2025-10-10 5.3 Medium
Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users
CVE-2024-4991 2 Ansanwan, Siadmin 2 Siadmin, Siadmin 2025-10-10 9.8 Critical
Vulnerability in SiAdmin 1.1 that allows SQL injection via the /modul/mod_pass/aksi_pass.php parameter in nama_lengkap. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in it.
CVE-2024-4992 2 Ansanwan, Siadmin 2 Siadmin, Siadmin 2025-10-10 9.8 Critical
Vulnerability in SiAdmin 1.1 that allows SQL injection via the /modul/mod_kuliah/aksi_kuliah.php parameter in nim. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in it.
CVE-2024-4993 2 Ansanwan, Siadmin 2 Siadmin, Siadmin 2025-10-10 6.3 Medium
Vulnerability in SiAdmin 1.1 that allows XSS via the /show.php query parameter. This vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and thereby steal their cookie session credentials.
CVE-2024-45187 1 Mage 1 Mage-ai 2025-10-10 7.1 High
Guest users in the Mage AI framework that remain logged in after their accounts are deleted, are mistakenly given high privileges and specifically given access to remotely execute arbitrary code through the Mage AI terminal server
CVE-2024-45188 1 Mage 1 Mage-ai 2025-10-10 6.5 Medium
Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal in the "File Content" request
CVE-2024-45190 1 Mage 1 Mage-ai 2025-10-10 6.5 Medium
Mage AI allows remote users with the "Viewer" role to leak arbitrary files from the Mage server due to a path traversal in the "Pipeline Interaction" request
CVE-2024-5413 1 Phpmybackuppro 1 Phpmybackuppro 2025-10-10 7.1 High
A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS through /phpmybackuppro/scheduled.php, all parameters. This vulnerabilities could allow an attacker to create a specially crafted URL and send it to a victim to retrieve their session details.
CVE-2024-5414 1 Phpmybackuppro 1 Phpmybackuppro 2025-10-10 7.1 High
A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS through /phpmybackuppro/get_file.php, 'view' parameter. This vulnerabilities could allow an attacker to create a specially crafted URL and send it to a victim to retrieve their session details.
CVE-2025-45814 1 Novelsat 4 Ns2000, Ns2000 Firmware, Ns3000 and 1 more 2025-10-10 9.8 Critical
Missing authentication checks in the query.fcgi endpoint of NS3000 v8.1.1.125110 , v7.2.8.124852 , and v7.x and NS2000 v7.02.08 allows attackers to execute a session hijacking attack.
CVE-2024-5415 1 Phpmybackuppro 1 Phpmybackuppro 2025-10-10 7.1 High
A vulnerability have been discovered in PhpMyBackupPro affecting version 2.3 that could allow an attacker to execute XSS through /phpmybackuppro/backup.php, 'comments' and 'db' parameters. This vulnerabilities could allow an attacker to create a specially crafted URL and send it to a victim to retrieve their session details.
CVE-2025-45813 1 Enensys 2 Ipguardv2, Ipguardv2 Firmware 2025-10-10 9.8 Critical
ENENSYS IPGuard v2 2.10.0 was discovered to contain hardcoded credentials.
CVE-2025-45938 1 Akeles 1 Out Of Office Assistant 2025-10-10 5.4 Medium
Akeles Out of Office Assistant for Jira 4.0.1 is vulberable to Cross Site Scripting (XSS) via the Jira fullName parameter.
CVE-2025-45479 1 Educoder 1 Challenges 2025-10-10 9.8 Critical
Insufficient security mechanisms for created containers in educoder challenges v1.0 allow attackers to execute arbitrary code via injecting crafted content into a container.
CVE-2024-44542 1 Todesk 1 Todesk 2025-10-10 9.8 Critical
SQL Injection vulnerability in todesk v.1.1 allows a remote attacker to execute arbitrary code via the /todesk.com/news.html parameter.
CVE-2025-4017 1 Xxyopen 1 Novel-plus 2025-10-10 4.3 Medium
A vulnerability classified as problematic was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This vulnerability affects the function list of the file nnovel-admin/src/main/java/com/java2nb/common/controller/LogController.java. The manipulation leads to improper authorization. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-4018 1 Xxyopen 1 Novel-plus 2025-10-10 5.3 Medium
A vulnerability, which was classified as critical, has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This issue affects the function addCrawlSource of the file novel-crawl/src/main/java/com/java2nb/novel/controller/CrawlController.java. The manipulation leads to missing authentication. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2025-0399 1 Starsea99 1 Starsea-mall 2025-10-10 4.7 Medium
A vulnerability was found in StarSea99 starsea-mall 1.0. It has been declared as critical. This vulnerability affects the function UploadController of the file src/main/java/com/siro/mall/controller/common/uploadController.java. The manipulation of the argument file leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-0400 1 Starsea99 1 Starsea-mall 2025-10-10 2.4 Low
A vulnerability was found in StarSea99 starsea-mall 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /admin/categories/update. The manipulation of the argument categoryName leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2025-4019 1 Xxyopen 1 Novel-plus 2025-10-10 7.3 High
A vulnerability, which was classified as critical, was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. Affected is the function genCode of the file novel-admin/src/main/java/com/java2nb/common/controller/GeneratorController.java. The manipulation leads to missing authentication. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.