Search

Search Results (381928 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-39854 1 Atx 1 Ucrypt 2024-11-21 6.5 Medium
The web interface of ATX Ucrypt through 3.5 allows authenticated users (or attackers using default credentials for the admin, master, or user account) to include files via a URL in the /hydra/view/get_cc_url url parameter. There can be resultant SSRF.
CVE-2023-39852 1 Doctor Appointment System Project 1 Doctor Appointment System 2024-11-21 9.8 Critical
Doctormms v1.0 was discovered to contain a SQL injection vulnerability via the $userid parameter at myAppoinment.php. NOTE: this is disputed by a third party who claims that the userid is a session variable controlled by the server, and thus cannot be used for exploitation. The original reporter counterclaims that this originates from $_SESSION["userid"]=$_POST["userid"] at line 68 in doctors\doctorlogin.php, where userid under POST is not a session variable controlled by the server.
CVE-2023-39850 1 Schoolmate Project 1 Schoolmate 2024-11-21 9.8 Critical
Schoolmate v1.3 was discovered to contain multiple SQL injection vulnerabilities via the $courseid and $teacherid parameters at DeleteFunctions.php.
CVE-2023-39846 1 Pantsel 1 Konga 2024-11-21 9.8 Critical
An issue in Konga v0.14.9 allows attackers to bypass authentication via a crafted JWT token.
CVE-2023-39843 1 Sulimet 2 5-in-1 Smart Door Lock, 5-in-1 Smart Door Lock Firmware 2024-11-21 2.4 Low
Missing encryption in the RFID tag of Suleve 5-in-1 Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity to the original device.
CVE-2023-39842 1 Mydigoo 2 Dg-hamb Smart Home Security System, Dg-hamb Smart Home Security System Firmware 2024-11-21 2.4 Low
Missing encryption in the RFID tag of Digoo DG-HAMB Smart Home Security System v1.0 allows attackers to create a cloned tag via brief physical proximity to the original device.
CVE-2023-39841 1 Etekcity 2 3-in-1 Smart Door Lock, 3-in-1 Smart Door Lock Firmware 2024-11-21 4.6 Medium
Missing encryption in the RFID tag of Etekcity 3-in-1 Smart Door Lock v1.0 allows attackers to create a cloned tag via brief physical proximity to the original device.
CVE-2023-39834 1 Pbootcms 1 Pbootcms 2024-11-21 9.8 Critical
PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via create_function.
CVE-2023-39829 1 Tenda 2 A18, A18 Firmware 2024-11-21 7.5 High
Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the wpapsk_crypto2_4g parameter in the fromSetWirelessRepeat function.
CVE-2023-39828 1 Tenda 2 A18, A18 Firmware 2024-11-21 7.5 High
Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the security parameter in the formWifiBasicSet function.
CVE-2023-39827 1 Tenda 2 A18, A18 Firmware 2024-11-21 7.5 High
Tenda A18 V15.13.07.09 was discovered to contain a stack overflow via the rule_info parameter in the formAddMacfilterRule function.
CVE-2023-39806 1 Idreamsoft 1 Icms 2024-11-21 9.8 Critical
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function.
CVE-2023-39805 1 Idreamsoft 1 Icms 2024-11-21 9.8 Critical
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.
CVE-2023-39801 1 Renault 2 Easy Link, Zoe Ev 2021 2024-11-21 4.6 Medium
A lack of exception handling in the Renault Easy Link Multimedia System Software Version 283C35519R allows attackers to cause a Denial of Service (DoS) via supplying crafted WMA files when connecting a device to the vehicle's USB plug and play feature.
CVE-2023-39796 1 Wbce 1 Wbce Cms 2024-11-21 9.8 Critical
SQL injection vulnerability in the miniform module in WBCE CMS v.1.6.0 allows remote unauthenticated attacker to execute arbitrary code via the DB_RECORD_TABLE parameter.
CVE-2023-39777 1 Vbulletin 1 Vbulletin 2024-11-21 5.4 Medium
A cross-site scripting (XSS) vulnerability in the Admin Control Panel of vBulletin 5.7.5 and 6.0.0 allows attackers to execute arbitrary web scripts or HTML via the /login.php?do=login url parameter.
CVE-2023-39776 1 Phpjabbers 1 Ticket Support Script 2024-11-21 9.8 Critical
A File Upload vulnerability in PHPJabbers Ticket Support Script v3.2 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2023-39751 1 Tp-link 3 Tl-wr941nd, Tl-wr941nd V6, Tl-wr941nd V6 Firmware 2024-11-21 9.8 Critical
TP-Link TL-WR941ND V6 were discovered to contain a buffer overflow via the pSize parameter at /userRpm/PingIframeRpm.
CVE-2023-39750 2 D-link, Dlink 3 Dap-2660, Dap-2660, Dap-2660 Firmware 2024-11-21 9.8 Critical
D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the f_ipv6_enable parameter at /bsc_ipv6. This vulnerability is exploited via a crafted POST request.
CVE-2023-39749 2 D-link, Dlink 3 Dap-2660, Dap-2660, Dap-2660 Firmware 2024-11-21 9.8 Critical
D-Link DAP-2660 v1.13 was discovered to contain a buffer overflow via the component /adv_resource. This vulnerability is exploited via a crafted GET request.