Export limit exceeded: 381932 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (381932 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-40631 | 2 Google, Unisoc | 14 Android, S8000, Sc7731e and 11 more | 2024-11-21 | 4.4 Medium |
| In Dialer, there is a possible missing permission check. This could lead to local information disclosure with System execution privileges needed | ||||
| CVE-2023-40630 | 1 Joomcode | 1 Jcdashboard | 2024-11-21 | 9.8 Critical |
| Unauthenticated LFI/SSRF in JCDashboards component for Joomla. | ||||
| CVE-2023-40629 | 1 King-products | 1 Lms King Lite | 2024-11-21 | 9.8 Critical |
| SQLi vulnerability in LMS Lite component for Joomla. | ||||
| CVE-2023-40628 | 1 Extplorer | 1 Extplorer | 2024-11-21 | 6.1 Medium |
| A reflected XSS vulnerability was discovered in the Extplorer component for Joomla. | ||||
| CVE-2023-40627 | 1 Mlwebtechnologies | 1 Livingword | 2024-11-21 | 6.1 Medium |
| A reflected XSS vulnerability was discovered in the LivingWord component for Joomla. | ||||
| CVE-2023-40625 | 1 Sap | 1 S4core | 2024-11-21 | 5.4 Medium |
| S4CORE (Manage Purchase Contracts App) - versions 102, 103, 104, 105, 106, 107, does not perform necessary authorization checks for an authenticated user. This could allow an attacker to perform unintended actions resulting in escalation of privileges which has low impact on confidentiality and integrity with no impact on availibility of the system. | ||||
| CVE-2023-40624 | 1 Sap | 1 Netweaver Application Server Abap | 2024-11-21 | 5.5 Medium |
| SAP NetWeaver AS ABAP (applications based on Unified Rendering) - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, SAP_BASIS 702, SAP_BASIS 731, allows an attacker to inject JavaScript code that can be executed in the web-application. An attacker could thereby control the behavior of this web-application. | ||||
| CVE-2023-40623 | 1 Sap | 1 Businessobjects | 2024-11-21 | 6.2 Medium |
| SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory under temporary directory and link it to a directory with operating system files. On successful exploitation the attacker can delete all the operating system files causing a limited impact on integrity and completely compromising the availability of the system. | ||||
| CVE-2023-40622 | 1 Sap | 1 Businessobjects Business Intelligence | 2024-11-21 | 9.9 Critical |
| SAP BusinessObjects Business Intelligence Platform (Promotion Management) - versions 420, 430, under certain condition allows an authenticated attacker to view sensitive information which is otherwise restricted. On successful exploitation, the attacker can completely compromise the application causing high impact on confidentiality, integrity, and availability. | ||||
| CVE-2023-40621 | 1 Sap | 1 Powerdesigner | 2024-11-21 | 6.3 Medium |
| SAP PowerDesigner Client - version 16.7, allows an unauthenticated attacker to inject VBScript code in a document and have it opened by an unsuspecting user, to have it executed by the application on behalf of the user. The application has a security option to disable or prompt users before untrusted scripts are executed, but this is not set as default. | ||||
| CVE-2023-40619 | 1 Phppgadmin Project | 1 Phppgadmin | 2024-11-21 | 9.8 Critical |
| phpPgAdmin 7.14.4 and earlier is vulnerable to deserialization of untrusted data which may lead to remote code execution because user-controlled data is directly passed to the PHP 'unserialize()' function in multiple places. An example is the functionality to manage tables in 'tables.php' where the 'ma[]' POST parameter is deserialized. | ||||
| CVE-2023-40618 | 1 Openknowledgemaps | 1 Head Start | 2024-11-21 | 6.1 Medium |
| A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start versions 4, 5, 6, 7 as well as Visual Project Explorer 1.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'service' parameter in 'headstart_snapshot.php'. | ||||
| CVE-2023-40617 | 1 Openknowledgemaps | 1 Head Start | 2024-11-21 | 6.1 Medium |
| A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start 7 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'file' parameter in 'displayPDF.php'. | ||||
| CVE-2023-40612 | 1 Opennms | 2 Horizon, Meridian | 2024-11-21 | 5.3 Medium |
| In OpenMNS Horizon 31.0.8 and versions earlier than 32.0.2, the file editor which is accessible to any user with ROLE_FILESYSTEM_EDITOR privileges is vulnerable to XXE injection attacks. The solution is to upgrade to Meridian 2023.1.5 or Horizon 32.0.2 or newer. Meridian and Horizon installation instructions state that they are intended for installation within an organization's private networks and should not be directly accessible from the Internet. OpenNMS thanks Erik Wynter for reporting this issue. | ||||
| CVE-2023-40607 | 1 Cluevo | 1 Learning Management System | 2024-11-21 | 4.3 Medium |
| Cross-Site Request Forgery (CSRF) vulnerability in CLUEVO CLUEVO LMS, E-Learning Platform plugin <= 1.10.0 versions. | ||||
| CVE-2023-40605 | 1 93digital | 1 Typing Effect | 2024-11-21 | 6.5 Medium |
| Auth. (contributor) Cross-Site Scripting (XSS) vulnerability in 93digital Typing Effect plugin <= 1.3.6 versions. | ||||
| CVE-2023-40604 | 1 Jesmadsen | 1 Cookies By Jm | 2024-11-21 | 5.9 Medium |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Jes Madsen Cookies by JM plugin <= 1.0 versions. | ||||
| CVE-2023-40603 | 1 Webtechforce | 1 Simple Org Chart | 2024-11-21 | 5.3 Medium |
| Missing Authorization vulnerability in Gangesh Matta Simple Org Chart.This issue affects Simple Org Chart: from n/a through 2.3.4. | ||||
| CVE-2023-40601 | 1 Estatik | 1 Estatik Mortgage Calculator | 2024-11-21 | 7.1 High |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Estatik Estatik Mortgage Calculator plugin <= 2.0.7 versions. | ||||
| CVE-2023-40599 | 1 Synck Graphica | 1 Mailform Pro Cgi | 2024-11-21 | 7.5 High |
| Regular expression Denial-of-Service (ReDoS) exists in multiple add-ons for Mailform Pro CGI 4.3.1.3 and earlier, which allows a remote unauthenticated attacker to cause a denial-of-service condition. Affected add-ons are as follows: call/call.js, prefcodeadv/search.cgi, estimate/estimate.js, search/search.js, suggest/suggest.js, and coupon/coupon.js. | ||||