0.0
CVE-2026-29974 -
An issue was discovered in kosma minmea 0.3.0. The minmea_scan functions format specifier copies NMEA field data to a caller-provided buffer without a size parameter. Applications using minmea_scan on untrusted input are vulnerable to a stack buffer overflow.
0.0
CVE-2026-29972 -
nanoMODBUS through v1.22.0 has a stack-based buffer overflow in recv_read_registers_res() in nanomodbus.c. When a client calls nmbs_read_holding_registers() or nmbs_read_input_registers(), the library writes register data from the server response to the caller-provided buffer based on the response'β¦
6.1
CVE-2023-42343 - Crossβsite scripting via the cmis-online/type endpoint in Alkacon OpenCms before 10.5.1
A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type.
0.0
CVE-2026-37431 -
Beauty Parlour Management System v1.1 was discovered to contain a SQL injection vulnerability via the aptnumber parameter in the /appointment-detail.php endpoint. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement.
7.3
CVE-2025-67888 -
An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /admin/index.php (when the "api" parameter is set) is not properly sanitized before being used to execute OS commands. This can be exploited by unauthenticated attackers to inject β¦
5.3
CVE-2022-26523 -
The socket connection handler in aswArPot.sys in the Avast and AVG Windows Anti Rootkit driver before 22.1 allows local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) due to a double fetch vulnerability at aswArPot+0xbb94.
6.1
CVE-2022-23961 - Reflected XSS in Thruk Monitoring Login Form
In Thruk Monitoring through 2.46.3, the login field of the login form is vulnerable to reflected XSS. This vulnerability can be exploited by unauthenticated remote attackers to target users of the monitoring interface.
0.0
CVE-2025-55449 - Hardcoded Private Key in AstrBot Enables JWT Forgery and Potential Remote Code Execution
AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key used to sign a JWT.
6.5
CVE-2022-45899 - Unauthenticated OS Command Injection in Nokia Broadcast Message Center Log Scanner
Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as root via shell metacharacters in the Log Scanner Search Pattern field.
0.0
CVE-2023-42346 - XXE Vulnerability in Alkacon OpenCms Before Version 16 via External DOCTYPE
Alkacon OpenCms before 16 allows XXE when the <!DOCTYPE> refers to an external host.