Vulnerabilities (CVE)

Total 298001 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-46988 1 Adobe 1 Experience Manager 2025-06-13 N/A 5.4 MEDIUM
Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
CVE-2024-52771 1 Dedebiz 1 Dedebiz 2025-06-13 N/A 9.1 CRITICAL
DedeBIZ v6.3.0 was discovered to contain an arbitrary file deletion vulnerability via the component /admin/file_manage_view.
CVE-2024-52770 1 Dedebiz 1 Dedebiz 2025-06-13 N/A 9.8 CRITICAL
An arbitrary file upload vulnerability in the component /admin/file_manage_control of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2025-3623 2025-06-13 N/A 9.1 CRITICAL
The Uncanny Automator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6.4.0.1 via deserialization of untrusted input in the automator_api_decode_message() function. This makes it possible for unauthenticated to inject a PHP Object. The additional presence of a POP chain allows attackers to delete arbitrary files.
CVE-2025-28386 2025-06-13 N/A N/A
A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file.
CVE-2025-22240 2025-06-13 N/A 6.3 MEDIUM
Arbitrary directory creation or file deletion. In the find_file method of the GitFS class, a path is created using os.path.join using unvalidated input from the “tgt_env” variable. This can be exploited by an attacker to delete any file on the Master's process has permissions to.
CVE-2025-22239 2025-06-13 N/A 8.1 HIGH
Arbitrary event injection on Salt Master. The master's "_minion_event" method can be used by and authorized minion to send arbitrary events onto the master's event bus.
CVE-2025-22238 2025-06-13 N/A 4.2 MEDIUM
Directory traversal attack in minion file cache creation. The master's default cache is vulnerable to a directory traversal attack. Which could be leveraged to write or overwrite 'cache' files outside of the cache directory.
CVE-2025-22237 2025-06-13 N/A 6.7 MEDIUM
An attacker with access to a minion key can exploit the 'on demand' pillar functionality with a specially crafted git url which could cause and arbitrary command to be run on the master with the same privileges as the master process.
CVE-2025-22236 2025-06-13 N/A 8.1 HIGH
Minion event bus authorization bypass. An attacker with access to a minion key can craft a message which may be able to execute a job on other minions (>= 3007.0).
CVE-2024-38825 2025-06-13 N/A 6.4 MEDIUM
The salt.auth.pki module does not properly authenticate callers. The "password" field contains a public certificate which is validated against a CA certificate by the module. This is not pki authentication, as the caller does not need access to the corresponding private key for the authentication attempt to be accepted.
CVE-2024-38823 2025-06-13 N/A 2.7 LOW
Salt's request server is vulnerable to replay attacks when not using a TLS encrypted transport.
CVE-2024-52769 1 Dedebiz 1 Dedebiz 2025-06-13 N/A 7.2 HIGH
An arbitrary file upload vulnerability in the component /admin/friendlink_edit of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2025-26846 1 Znuny 1 Znuny 2025-06-13 N/A 9.8 CRITICAL
An issue was discovered in Znuny before 7.1.4. Permissions are not checked properly when using the Generic Interface to update ticket metadata.
CVE-2025-44830 1 Engineercms Project 1 Engineercms 2025-06-13 N/A 9.8 CRITICAL
EngineerCMS v1.02 through v.2.0.5 has a SQL injection vulnerability in the /project/addprojtemplet interface.
CVE-2025-45779 1 Tenda 2 Ac10, Ac10 Firmware 2025-06-13 N/A 9.8 CRITICAL
Tenda AC10 V1.0re_V15.03.06.46 is vulnerable to Buffer Overflow in the formSetPPTPUserList handler via the list POST parameter.
CVE-2025-44175 1 Tenda 2 Ac10, Ac10 Firmware 2025-06-13 N/A 5.4 MEDIUM
Tenda AC10 v4 V16.03.10.13 is vulnerable to Buffer Overflow in the GetParentControlInfo function.
CVE-2024-34199 1 Ritlabs 1 Tinyweb 2025-06-13 N/A 8.6 HIGH
TinyWeb 1.94 and below allows unauthenticated remote attackers to cause a denial of service (Buffer Overflow) when sending excessively large elements in the request line.
CVE-2024-34243 1 Pantsel 1 Konga 2025-06-13 N/A 5.4 MEDIUM
Konga v0.14.9 is vulnerable to Cross Site Scripting (XSS) via the username parameter.
CVE-2024-34250 1 Bytecodealliance 1 Webassembly Micro Runtime 2025-06-13 N/A 6.2 MEDIUM
A heap buffer overflow vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause at least a denial of service via the "wasm_loader_check_br" function in core/iwasm/interpreter/wasm_loader.c.