A vulnerability classified as critical was found in Kenj_Frog 肯尼基蛙 company-financial-management 公司财务管理系统 1.0. Affected by this vulnerability is the function page of the file src/main/java/com/controller/ShangpinleixingController.java. The manipulation of the argument sort leads to sql injection.
This vulnerability is known as CVE-2025-3318. The attack can be launched remotely. Furthermore, there is an exploit available.
This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.
A vulnerability classified as problematic has been found in fumiao opencms up to a0fafa5cff58719e9b27c2a2eec204cc165ce14f. Affected is an unknown function of the file opencms-dev/src/main/webapp/view/admin/document/dataPage.jsp. The manipulation of the argument path leads to path traversal.
This vulnerability is traded as CVE-2025-3317. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available.
A vulnerability was found in FUDforum 3.1.3. It has been declared as problematic. This vulnerability affects unknown code of the file /adm/admsql.php. The manipulation of the argument statements leads to cross site scripting.
This vulnerability was named CVE-2024-30950. The attack can be initiated remotely. There is no exploit available.
A vulnerability was found in Google Chrome. It has been classified as critical. This affects an unknown part of the component V8. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2024-3914. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in Htmly 2.9.5. Affected by this issue is some unknown functionality of the component Menu Editor Module. The manipulation of the argument Link Name leads to cross site scripting.
This vulnerability is handled as CVE-2024-30953. The attack may be launched remotely. There is no exploit available.
Currently trending CVE - Hype Score: 8 - There exists a vulnerability in Quick Share/Nearby, where an attacker can bypass the accept file dialog on Quick Share Windows. Normally in Quick Share Windows app we can't send a file without the user accept from the receiving device if the visibility is set to everyone mode or ...
A vulnerability was found in PHPGurukul Men Salon Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/search-invoices.php. The manipulation of the argument searchdata leads to sql injection.
The identification of this vulnerability is CVE-2025-3316. The attack may be initiated remotely. Furthermore, there is an exploit available.
A vulnerability was found in ZendTo up to 5.04-6. It has been declared as problematic. This vulnerability affects unknown code in the library lib/NSSAuthenticator.php of the component MD5 Handler. The manipulation leads to type confusion.
This vulnerability was named CVE-2025-32352. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in ZendTo up to 6.10-6. It has been classified as very critical. This affects an unknown part in the library lib/NSSDropoff.php. The manipulation of the argument tmp_name leads to os command injection.
This vulnerability is uniquely identified as CVE-2021-47667. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in NVIDIA Graphics Driver up to 341/369.58/375.62 on Quadro/NVS/GeForce and classified as critical. Affected by this vulnerability is the function DxgDdiEscape in the library nvlddmkm.sys of the component Kernel Mode Layer. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2016-8808. An attack has to be approached locally. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
Port of Seattle is notifying 90,000 people of a data breach after personal data was stolen in a ransomware attack in August 2024. In August 2024, a cyber attack hit the Port of Seattle, which also operates the Seattle-Tacoma International Airport. The attack impacted websites and phone systems. According to The Seattle Times, the cyber […]
A vulnerability has been found in TIBCO JasperReports Server up to 8.0.3 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2024-3323. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in excalidraw up to 0.16.3/0.17.5. Affected by this issue is some unknown functionality of the component Web Embeddable. The manipulation leads to cross site scripting.
This vulnerability is handled as CVE-2024-32472. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.