Export limit exceeded: 379189 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (379189 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-47471 | 1 Struktur | 1 Libde265 | 2024-11-21 | 6.5 Medium |
| Buffer Overflow vulnerability in strukturag libde265 v1.10.12 allows a local attacker to cause a denial of service via the slice_segment_header function in the slice.cc component. | ||||
| CVE-2023-47465 | 1 Gpac | 1 Gpac | 2024-11-21 | 5.5 Medium |
| An issue in GPAC v.2.2.1 and before allows a local attacker to cause a denial of service (DoS) via the ctts_box_read function of file src/isomedia/box_code_base.c. | ||||
| CVE-2023-47464 | 1 Gl-inet | 2 Gl-ax1800, Gl-ax1800 Firmware | 2024-11-21 | 8.8 High |
| Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via the upload API function. | ||||
| CVE-2023-47463 | 1 Gl-inet | 2 Gl-ax1800, Gl-ax1800 Firmware | 2024-11-21 | 9.8 Critical |
| Insecure Permissions vulnerability in GL.iNet AX1800 version 4.0.0 before 4.5.0 allows a remote attacker to execute arbitrary code via a crafted script to the gl_nas_sys authentication function. | ||||
| CVE-2023-47462 | 1 Gl-inet | 2 Gl-ax1800, Gl-ax1800 Firmware | 2024-11-21 | 9.8 Critical |
| Insecure Permissions vulnerability in GL.iNet AX1800 v.3.215 and before allows a remote attacker to execute arbitrary code via the file sharing function. | ||||
| CVE-2023-47456 | 1 Tenda | 2 Ax1806, Ax1806 Firmware | 2024-11-21 | 9.1 Critical |
| Tenda AX1806 V1.0.0.1 contains a stack overflow vulnerability in function sub_455D4, called by function fromSetWirelessRepeat. | ||||
| CVE-2023-47455 | 1 Tenda | 2 Ax1806, Ax1806 Firmware | 2024-11-21 | 9.1 Critical |
| Tenda AX1806 V1.0.0.1 contains a heap overflow vulnerability in setSchedWifi function, in which the src and v12 are directly obtained from http request parameter schedStartTime and schedEndTime without checking their size. | ||||
| CVE-2023-47454 | 1 Netease | 1 Cloudmusic | 2024-11-21 | 7.8 High |
| An Untrusted search path vulnerability in NetEase CloudMusic 2.10.4 for Windows allows local users to gain escalated privileges through the urlmon.dll file in the current working directory. | ||||
| CVE-2023-47452 | 1 Notepad-plus-plus | 1 Notepad\+\+ | 2024-11-21 | 7.8 High |
| An Untrusted search path vulnerability in notepad++ 6.5 allows local users to gain escalated privileges through the msimg32.dll file in the current working directory. | ||||
| CVE-2023-47446 | 1 Phpgurukul | 1 Pre-school Enrollment System | 2024-11-21 | 5.4 Medium |
| Pre-School Enrollment version 1.0 is vulnerable to Cross Site Scripting (XSS) on the profile.php page via fullname parameter. | ||||
| CVE-2023-47445 | 1 Phpgurukul | 1 Pre-school Enrollment System | 2024-11-21 | 9.8 Critical |
| Pre-School Enrollment version 1.0 is vulnerable to SQL Injection via the username parameter in preschool/admin/ page. | ||||
| CVE-2023-47444 | 1 Opencart | 1 Opencart | 2024-11-21 | 8.8 High |
| An issue discovered in OpenCart 4.0.0.0 to 4.0.2.3 allows authenticated backend users having common/security write privilege can write arbitrary untrusted data inside config.php and admin/config.php, resulting in remote code execution on the underlying server. | ||||
| CVE-2023-47440 | 1 Gladysassistant | 1 Gladys Assistant | 2024-11-21 | 6.5 Medium |
| Gladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be incomplete, allowing authenticated attackers to extract sensitive files in the host machine. | ||||
| CVE-2023-47437 | 1 Pachno | 1 Pachno | 2024-11-21 | 5.4 Medium |
| A vulnerability has been identified in Pachno 1.0.6 allowing an authenticated attacker to execute a cross-site scripting (XSS) attack. The vulnerability exists due to inadequate input validation in the Project Description and comments, which enables an attacker to inject malicious java script. | ||||
| CVE-2023-47418 | 1 Zoneland | 1 O2oa | 2024-11-21 | 9.8 Critical |
| Remote Code Execution (RCE) vulnerability in o2oa version 8.1.2 and before, allows attackers to create a new interface in the service management function to execute JavaScript. | ||||
| CVE-2023-47417 | 1 Paulrouget | 1 Dzslides | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting (XSS) vulnerability in the component /shells/embedder.html of DZSlides after v2011.07.25 allows attackers to execute arbitrary code via a crafted payload. | ||||
| CVE-2023-47397 | 1 Webidsupport | 1 Webid | 2024-11-21 | 9.8 Critical |
| WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php. | ||||
| CVE-2023-47393 | 1 Mercedes-benz | 1 Mercedes Me | 2024-11-21 | 5.3 Medium |
| An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the maintenance orders of other users and access sensitive user information via unspecified vectors. | ||||
| CVE-2023-47392 | 1 Mercedes-benz | 1 Mercedes Me | 2024-11-21 | 5.3 Medium |
| An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the carts of other users via sending a crafted add order request. | ||||
| CVE-2023-47390 | 1 Juanfont | 1 Headscale | 2024-11-21 | 7.5 High |
| Headscale through 0.22.3 writes bearer tokens to info-level logs. | ||||