Export limit exceeded: 382011 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (382011 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-42439 | 1 Geosolutionsgroup | 1 Geonode | 2024-11-21 | 7.5 High |
| GeoNode is an open source platform that facilitates the creation, sharing, and collaborative use of geospatial data. A SSRF vulnerability exists starting in version 3.2.0, bypassing existing controls on the software. This can allow a user to request internal services for a full read SSRF, returning any data from the internal network. The application is using a whitelist, but the whitelist can be bypassed. The bypass will trick the application that the first host is a whitelisted address, but the browser will use `@` or `%40` as a credential to the host geoserver on port 8080, this will return the data to that host on the response. Version 4.1.3.post1 is the first available version that contains a patch. | ||||
| CVE-2023-42436 | 1 Weseek | 1 Growi | 2024-11-21 | 5.4 Medium |
| Stored cross-site scripting vulnerability exists in the presentation feature of GROWI versions prior to v3.4.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product. | ||||
| CVE-2023-42435 | 1 Dexma | 1 Dexgate | 2024-11-21 | 5.5 Medium |
| The affected product is vulnerable to a cross-site request forgery vulnerability, which may allow an attacker to perform actions with the permissions of a victim user. | ||||
| CVE-2023-42431 | 1 Hallowelt | 1 Bluespice | 2024-11-21 | 2.1 Low |
| Cross-site Scripting (XSS) vulnerability in BlueSpiceAvatars extension of BlueSpice allows logged in user to inject arbitrary HTML into the profile image dialog on Special:Preferences. This only applies to the genuine user context. | ||||
| CVE-2023-42428 | 1 Cubecart | 1 Cubecart | 2024-11-21 | 6.5 Medium |
| Directory traversal vulnerability in CubeCart prior to 6.5.3 allows a remote authenticated attacker with an administrative privilege to delete directories and files in the system. | ||||
| CVE-2023-42426 | 1 Froala | 1 Froala Editor | 2024-11-21 | 6.1 Medium |
| Cross-site scripting (XSS) vulnerability in Froala Froala Editor v.4.1.1 allows remote attackers to execute arbitrary code via the 'Insert link' parameter in the 'Insert Image' component. | ||||
| CVE-2023-42425 | 1 Turing | 2 Edge\+ Evc5fd, Edge\+ Evc5fd Firmware | 2024-11-21 | 9.8 Critical |
| An issue in Turing Video Turing Edge+ EVC5FD v.1.38.6 allows remote attacker to execute arbitrary code and obtain sensitive information via the cloud connection components. | ||||
| CVE-2023-42406 | 1 Dlink | 2 Dar-7000, Dar-7000 Firmware | 2024-11-21 | 9.8 Critical |
| SQL injection vulnerability in D-Link Online behavior audit gateway DAR-7000 V31R02B1413C allows a remote attacker to obtain sensitive information and execute arbitrary code via the editrole.php component. | ||||
| CVE-2023-42405 | 1 Fit2cloud | 1 Rackshift | 2024-11-21 | 9.8 Critical |
| SQL injection vulnerability in FIT2CLOUD RackShift v1.7.1 allows attackers to execute arbitrary code via the `sort` parameter to taskService.list(), bareMetalService.list(), and switchService.list(). | ||||
| CVE-2023-42399 | 1 Xdsoft | 1 Joditeditor | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting vulnerability in xdsoft.net Jodit Editor v.4.0.0-beta.86 allows a remote attacker to obtain sensitive information via the rich text editor component. | ||||
| CVE-2023-42398 | 1 Zzcms | 1 Zzcms | 2024-11-21 | 9.8 Critical |
| An issue in zzCMS v.2023 allows a remote attacker to execute arbitrary code and obtain sensitive information via the ueditor component in controller.php. | ||||
| CVE-2023-42387 | 1 Tdsql Chitu Project | 1 Tdsql Chitu | 2024-11-21 | 7.5 High |
| An issue in TDSQL Chitu management platform v.10.3.19.5.0 allows a remote attacker to obtain sensitive information via get_db_info function in install.php. | ||||
| CVE-2023-42371 | 1 Summernote | 1 Rich Text Editor | 2024-11-21 | 5.4 Medium |
| Cross Site Scripting vulnerability in Summernote Rich Text Editor v.0.8.18 and before allows a remote attacker to execute arbitrary code via a crafted script to the insert link function in the editor component. | ||||
| CVE-2023-42363 | 1 Busybox | 1 Busybox | 2024-11-21 | 5.5 Medium |
| A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1. | ||||
| CVE-2023-42362 | 1 Teller | 1 Teller | 2024-11-21 | 5.4 Medium |
| An arbitrary file upload vulnerability in Teller Web App v.4.4.0 allows a remote attacker to execute arbitrary commands and obtain sensitive information via uploading a crafted file. | ||||
| CVE-2023-42361 | 1 Midori-global | 1 Better Pdf Exporter | 2024-11-21 | 7.8 High |
| Local File Inclusion vulnerability in Midori-global Better PDF Exporter for Jira Server and Jira Data Center v.10.3.0 and before allows an attacker to view arbitrary files and cause other impacts via use of crafted image during PDF export. | ||||
| CVE-2023-42359 | 1 Exam Form Submission In Php With Source Code Project | 1 Exam Form Submission In Php With Source Code | 2024-11-21 | 9.8 Critical |
| SQL injection vulnerability in Exam Form Submission in PHP with Source Code v.1.0 allows a remote attacker to escalate privileges via the val-username parameter in /index.php. | ||||
| CVE-2023-42336 | 1 Netis-systems | 2 Wf2409e, Wf2409e Firmware | 2024-11-21 | 9.8 Critical |
| An issue in NETIS SYSTEMS WF2409Ev4 v.1.0.1.705 allows a remote attacker to execute arbitrary code and obtain sensitive information via the password parameter in the /etc/shadow.sample component. | ||||
| CVE-2023-42335 | 1 Fl3xx | 2 Crew, Dispatch | 2024-11-21 | 8.8 High |
| Unrestricted File Upload vulnerability in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to execute arbitrary code via the add attachment function in the New Expense component. | ||||
| CVE-2023-42334 | 1 Fl3xx | 2 Crew, Dispatch | 2024-11-21 | 6.5 Medium |
| An Indirect Object Reference (IDOR) in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to escalate privileges via the user parameter. | ||||