Export limit exceeded: 375115 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 375115 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (375115 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-28372 1 Purestorage 1 Purity 2024-11-21 6.5 Medium
A flaw exists in FlashBlade Purity (OE) Version 4.1.0 whereby a user with privileges to extend an object’s retention period can affect the availability of the object lock.
CVE-2023-28336 2 Fedoraproject, Moodle 2 Fedora, Moodle 2024-11-21 4.3 Medium
Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.
CVE-2023-28335 1 Moodle 1 Moodle 2024-11-21 8.8 High
The link to reset all templates of a database activity did not include the necessary token to prevent a CSRF risk.
CVE-2023-28334 1 Moodle 1 Moodle 2024-11-21 4.3 Medium
Authenticated users were able to enumerate other users' names via the learning plans page.
CVE-2023-28333 2 Fedoraproject, Moodle 2 Fedora, Moodle 2024-11-21 9.8 Critical
The Mustache pix helper contained a potential Mustache injection risk if combined with user input (note: This did not appear to be implemented/exploitable anywhere in the core Moodle LMS).
CVE-2023-28332 1 Moodle 1 Moodle 2024-11-21 6.1 Medium
If the algebra filter was enabled but not functional (eg the necessary binaries were missing from the server), it presented an XSS risk.
CVE-2023-28330 1 Moodle 1 Moodle 2024-11-21 6.5 Medium
Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.
CVE-2023-28329 1 Moodle 1 Moodle 2024-11-21 6.3 Medium
Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers).
CVE-2023-28326 1 Apache 1 Openmeetings 2024-11-21 9.8 Critical
Vendor: The Apache Software Foundation Versions Affected: Apache OpenMeetings from 2.0.0 before 7.0.0 Description: Attacker can elevate their privileges in any room
CVE-2023-28324 1 Ivanti 1 Endpoint Manager 2024-11-21 8.2 High
A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execution.
CVE-2023-28199 1 Apple 1 Macos 2024-11-21 5.5 Medium
An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Ventura 13.3. An app may be able to disclose kernel memory.
CVE-2023-28179 1 Apple 1 Macos 2024-11-21 7.1 High
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. Processing a maliciously crafted AppleScript binary may result in unexpected app termination or disclosure of process memory.
CVE-2023-28174 1 Elightup 1 Erocket 2024-11-21 5.9 Medium
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in eLightUp eRocket plugin <= 1.2.4 versions.
CVE-2023-28171 1 Wpchill 1 Brilliance 2024-11-21 5.4 Medium
Auth. (subscriber+) Stored Cross-Site Scripting (XSS) vulnerability in WP Chill Brilliance theme <= 1.3.1 versions.
CVE-2023-28167 1 Vsourz 1 Cf7 Invisible Recaptcha 2024-11-21 5.4 Medium
Cross-Site Request Forgery (CSRF) vulnerability in Vsourz Digital CF7 Invisible reCAPTCHA plugin <= 1.3.3 versions.
CVE-2023-28166 1 Tags Cloud Manager Project 1 Tags Cloud Manager 2024-11-21 7.1 High
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Aakif Kadiwala Tags Cloud Manager plugin <= 1.0.0 versions.
CVE-2023-28155 1 Request Project 1 Request 2024-11-21 6.1 Medium
The Request package through 2.88.1 for Node.js allows a bypass of SSRF mitigations via an attacker-controller server that does a cross-protocol redirect (HTTP to HTTPS, or HTTPS to HTTP). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2023-28134 1 Checkpoint 1 Endpoint Security 2024-11-21 7.8 High
Local attacker can escalate privileges on affected installations of Check Point Harmony Endpoint/ZoneAlarm Extreme Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
CVE-2023-28133 1 Checkpoint 1 Endpoint Security 2024-11-21 7.8 High
Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration file
CVE-2023-28129 1 Ivanti 1 Desktop \& Server Management 2024-11-21 7.8 High
DSM 2022.2 SU2 and all prior versions allows a local low privileged account to execute arbitrary OS commands as the DSM software installation user.