Export limit exceeded: 381974 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (381974 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-42497 | 1 Liferay | 2 Digital Experience Platform, Liferay Portal | 2024-11-21 | 9.6 Critical |
| Reflected cross-site scripting (XSS) vulnerability on the Export for Translation page in Liferay Portal 7.4.3.4 through 7.4.3.85, and Liferay DXP 7.4 before update 86 allows remote attackers to inject arbitrary web script or HTML via the `_com_liferay_translation_web_internal_portlet_TranslationPortlet_redirect` parameter. | ||||
| CVE-2023-42495 | 1 Dasannetworks | 1 W-web | 2024-11-21 | 9.8 Critical |
| Dasan Networks - W-Web versions 1.22-1.27 - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | ||||
| CVE-2023-42494 | 1 Busbaer | 1 Eisbaer Scada | 2024-11-21 | 7.5 High |
| EisBaer Scada - CWE-749: Exposed Dangerous Method or Function | ||||
| CVE-2023-42493 | 1 Busbaer | 1 Eisbaer Scada | 2024-11-21 | 7.1 High |
| EisBaer Scada - CWE-256: Plaintext Storage of a Password | ||||
| CVE-2023-42492 | 1 Busbaer | 1 Eisbaer Scada | 2024-11-21 | 7.1 High |
| EisBaer Scada - CWE-321: Use of Hard-coded Cryptographic Key | ||||
| CVE-2023-42491 | 1 Busbaer | 1 Eisbaer Scada | 2024-11-21 | 8.8 High |
| EisBaer Scada - CWE-285: Improper Authorization | ||||
| CVE-2023-42490 | 1 Busbaer | 1 Eisbaer Scada | 2024-11-21 | 7.5 High |
| EisBaer Scada - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | ||||
| CVE-2023-42489 | 1 Busbaer | 1 Eisbaer Scada | 2024-11-21 | 7.5 High |
| EisBaer Scada - CWE-732: Incorrect Permission Assignment for Critical Resource | ||||
| CVE-2023-42488 | 1 Busbaer | 1 Eisbaer Scada | 2024-11-21 | 7.5 High |
| EisBaer Scada - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | ||||
| CVE-2023-42487 | 1 Soundminer | 1 Soundminer | 2024-11-21 | 7.5 High |
| Soundminer – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | ||||
| CVE-2023-42486 | 1 Fortect | 1 Fortect | 2024-11-21 | 6.3 Medium |
| Fortect - CWE-428: Unquoted Search Path or Element, may be used by local user to elevate privileges. | ||||
| CVE-2023-42483 | 1 Samsung | 14 Exynos 1080, Exynos 1080 Firmware, Exynos 1280 and 11 more | 2024-11-21 | 6.3 Medium |
| A TOCTOU race condition in Samsung Mobile Processor Exynos 9820, Exynos 980, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, and Exynos 1380 can cause unexpected termination of a system. | ||||
| CVE-2023-42482 | 1 Samsung | 2 Exynos 2200, Exynos 2200 Firmware | 2024-11-21 | 4.7 Medium |
| Samsung Mobile Processor Exynos 2200 allows a GPU Use After Free. | ||||
| CVE-2023-42481 | 1 Sap | 1 Commerce Cloud | 2024-11-21 | 8.1 High |
| In SAP Commerce Cloud - versions HY_COM 1905, HY_COM 2005, HY_COM2105, HY_COM 2011, HY_COM 2205, COM_CLOUD 2211, a locked B2B user can misuse the forgotten password functionality to un-block his user account again and re-gain access if SAP Commerce Cloud - Composable Storefront is used as storefront, due to weak access controls in place. This leads to a considerable impact on confidentiality and integrity. | ||||
| CVE-2023-42480 | 1 Sap | 1 Netweaver Application Server Java | 2024-11-21 | 5.3 Medium |
| The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to identify the legitimate user ids. This will have an impact on confidentiality but there is no other impact on integrity or availability. | ||||
| CVE-2023-42478 | 1 Sap | 1 Business Objects Business Intelligence Platform | 2024-11-21 | 7.5 High |
| SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to upload agnostic documents in the system which when opened by any other user could lead to high impact on integrity of the application. | ||||
| CVE-2023-42477 | 1 Sap | 1 Netweaver Application Server Java | 2024-11-21 | 6.5 Medium |
| SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a crafted request from a vulnerable web application, causing limited impact on confidentiality and integrity of the application. | ||||
| CVE-2023-42476 | 1 Sap | 1 Businessobjects Web Intelligence | 2024-11-21 | 6.8 Medium |
| SAP Business Objects Web Intelligence - version 420, allows an authenticated attacker to inject JavaScript code into Web Intelligence documents which is then executed in the victim’s browser each time the vulnerable page is visited. Successful exploitation can lead to exposure of the data that the user has access to. In the worst case, attacker could access data from reporting databases. | ||||
| CVE-2023-42475 | 1 Sap | 1 S\/4hana | 2024-11-21 | 4.3 Medium |
| The Statutory Reporting application has a vulnerable file storage location, potentially enabling low privileged attacker to read server files with minimal impact on confidentiality. | ||||
| CVE-2023-42474 | 1 Sap | 1 Businessobjects Web Intelligence | 2024-11-21 | 6.8 Medium |
| SAP BusinessObjects Web Intelligence - version 420, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to a user that would possibly allow an attacker to retrieve the sensitive information. | ||||