Export limit exceeded: 382106 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 382106 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (382106 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-43477 | 1 Telstra | 2 Arcadyan Lh1000, Arcadyan Lh1000 Firmware | 2024-11-21 | 6.8 Medium |
| The ping_from parameter of ping_tracerte.cgi in the web UI of Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, was not properly sanitized before being used in a system call, which could allow an authenticated attacker to achieve command injection as root on the device. | ||||
| CVE-2023-43472 | 1 Lfprojects | 1 Mlflow | 2024-11-21 | 7.5 High |
| An issue in MLFlow versions 2.8.1 and before allows a remote attacker to obtain sensitive information via a crafted request to REST API. | ||||
| CVE-2023-43470 | 1 Janobe | 1 Online Voting System | 2024-11-21 | 9.8 Critical |
| SQL injection vulnerability in janobe Online Voting System v.1.0 allows a remote attacker to execute arbitrary code via the checklogin.php component. | ||||
| CVE-2023-43469 | 1 Online Job Portal Project | 1 Online Job Portal | 2024-11-21 | 9.8 Critical |
| SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the ForPass.php component. | ||||
| CVE-2023-43468 | 1 Online Job Portal Project | 1 Online Job Portal | 2024-11-21 | 9.8 Critical |
| SQL injection vulnerability in janobe Online Job Portal v.2020 allows a remote attacker to execute arbitrary code via the login.php component. | ||||
| CVE-2023-43458 | 2 Resort Reservation System Project, Sourcecodester | 2 Resort Reservation System, Resort Reservation System | 2024-11-21 | 5.4 Medium |
| Cross Site Scripting (XSS) vulnerability in Resort Reservation System v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the room, name, and description parameters in the manage_room function. | ||||
| CVE-2023-43457 | 1 Oretnom23 | 1 Service Provider Management System | 2024-11-21 | 9.8 Critical |
| An issue in Service Provider Management System v.1.0 allows a remote attacker to gain privileges via the ID parameter in the /php-spms/admin/?page=user/ endpoint. | ||||
| CVE-2023-43456 | 1 Oretnom23 | 1 Service Provider Management System | 2024-11-21 | 5.4 Medium |
| Cross Site Scripting vulnerability in Service Provider Management System v.1.0 allows a remote attacker to execute arbitrary code and obtain sensitive information via the firstname, middlename and lastname parameters in the /php-spms/admin/?page=user endpoint. | ||||
| CVE-2023-43455 | 1 Totolink | 2 X6000r, X6000r Firmware | 2024-11-21 | 9.8 Critical |
| An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the command parameter of the setting/setTracerouteCfg component. | ||||
| CVE-2023-43453 | 1 Totolink | 2 X6000r, X6000r Firmware | 2024-11-21 | 9.8 Critical |
| An issue in TOTOLINK X6000R V9.4.0cu.652_B20230116 and V9.4.0cu.852_B20230719 allows a remote attacker to execute arbitrary code via the IP parameter of the setDiagnosisCfg component. | ||||
| CVE-2023-43382 | 1 Iteachyou | 1 Dreamer Cms | 2024-11-21 | 8.8 High |
| Directory Traversal vulnerability in itechyou dreamer CMS v.4.1.3 allows a remote attacker to execute arbitrary code via the themePath in the uploaded template function. | ||||
| CVE-2023-43381 | 1 Tianchoy | 1 Blog | 2024-11-21 | 7.5 High |
| SQL Injection vulnerability in Tianchoy Blog v.1.8.8 allows a remote attacker to obtain sensitive information via the id parameter in the login.php | ||||
| CVE-2023-43377 | 1 Digitaldruid | 1 Hoteldruid | 2024-11-21 | 5.4 Medium |
| A cross-site scripting (XSS) vulnerability in /hoteldruid/visualizza_contratto.php of Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the destinatario_email1 parameter. | ||||
| CVE-2023-43376 | 1 Digitaldruid | 1 Hoteldruid | 2024-11-21 | 5.4 Medium |
| A cross-site scripting (XSS) vulnerability in /hoteldruid/clienti.php of Hoteldruid v3.0.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the nometipotariffa1 parameter. | ||||
| CVE-2023-43375 | 1 Digitaldruid | 1 Hoteldruid | 2024-11-21 | 9.8 Critical |
| Hoteldruid v3.0.5 was discovered to contain multiple SQL injection vulnerabilities at /hoteldruid/clienti.php via the annonascita, annoscaddoc, giornonascita, giornoscaddoc, lingua_cli, mesenascita, and mesescaddoc parameters. | ||||
| CVE-2023-43374 | 1 Digitaldruid | 1 Hoteldruid | 2024-11-21 | 9.8 Critical |
| Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the id_utente_log parameter at /hoteldruid/personalizza.php. | ||||
| CVE-2023-43373 | 1 Digitaldruid | 1 Hoteldruid | 2024-11-21 | 9.8 Critical |
| Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the n_utente_agg parameter at /hoteldruid/interconnessioni.php. | ||||
| CVE-2023-43371 | 1 Digitaldruid | 1 Hoteldruid | 2024-11-21 | 9.8 Critical |
| Hoteldruid v3.0.5 was discovered to contain a SQL injection vulnerability via the numcaselle parameter at /hoteldruid/creaprezzi.php. | ||||
| CVE-2023-43364 | 1 Arjunsharda | 1 Searchor | 2024-11-21 | 9.8 Critical |
| main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution. | ||||
| CVE-2023-43360 | 1 Cmsmadesimple | 1 Cms Made Simple | 2024-11-21 | 5.4 Medium |
| Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Top Directory parameter in the File Picker Menu component. | ||||