Export limit exceeded: 381944 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (381944 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-42320 | 1 Tenda | 3 Ac10, Ac10 Firmware, Ac10v4 | 2024-11-21 | 9.8 Critical |
| Buffer Overflow vulnerability in Tenda AC10V4 v.US_AC10V4.0si_V16.03.10.13_cn_TDC01 allows a remote attacker to cause a denial of service via the mac parameter in the GetParentControlInfo function. | ||||
| CVE-2023-42319 | 1 Ethereum | 1 Go Ethereum | 2024-11-21 | 7.5 High |
| Geth (aka go-ethereum) through 1.13.4, when --http --graphql is used, allows remote attackers to cause a denial of service (memory consumption and daemon hang) via a crafted GraphQL query. NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic. | ||||
| CVE-2023-42299 | 1 Openimageio | 1 Openimageio | 2024-11-21 | 9.8 Critical |
| Buffer Overflow vulnerability in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service via the read_subimage_data function. | ||||
| CVE-2023-42298 | 1 Gpac | 1 Gpac | 2024-11-21 | 5.5 Medium |
| An issue in GPAC GPAC v.2.2.1 and before allows a local attacker to cause a denial of service via the Q_DecCoordOnUnitSphere function of file src/bifs/unquantize.c. | ||||
| CVE-2023-42295 | 1 Openimageio | 1 Openimageio | 2024-11-21 | 8.8 High |
| An issue in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service via the read_rle_image function of file bifs/unquantize.c | ||||
| CVE-2023-42284 | 1 Tyk | 1 Tyk | 2024-11-21 | 9.8 Critical |
| Blind SQL injection in api_version parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query. | ||||
| CVE-2023-42283 | 1 Tyk | 1 Tyk | 2024-11-21 | 9.8 Critical |
| Blind SQL injection in api_id parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query. | ||||
| CVE-2023-42280 | 1 Springernature | 1 Mee-admin | 2024-11-21 | 7.5 High |
| mee-admin 1.5 is vulnerable to Directory Traversal. The download method in the CommonFileController.java file does not verify the incoming data, resulting in arbitrary file reading. | ||||
| CVE-2023-42279 | 1 Iteachyou | 1 Dreamer Cms | 2024-11-21 | 9.8 Critical |
| Dreamer CMS v4.1.3 was discovered to contain a SQL injection vulnerability via the model-form-management-field form. | ||||
| CVE-2023-42278 | 1 Hutool | 1 Hutool | 2024-11-21 | 7.5 High |
| hutool v5.8.21 was discovered to contain a buffer overflow via the component JSONUtil.parse(). | ||||
| CVE-2023-42277 | 1 Hutool | 1 Hutool | 2024-11-21 | 9.8 Critical |
| hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonObject.putByPath. | ||||
| CVE-2023-42270 | 1 Grocy Project | 1 Grocy | 2024-11-21 | 8.8 High |
| Grocy <= 4.0.2 is vulnerable to Cross Site Request Forgery (CSRF). | ||||
| CVE-2023-42268 | 1 Jeecg | 1 Jeecg Boot | 2024-11-21 | 9.8 Critical |
| Jeecg boot up to v3.5.3 was discovered to contain a SQL injection vulnerability via the component /jeecg-boot/jmreport/show. | ||||
| CVE-2023-42261 | 1 Opensecurity | 1 Mobile Security Framework | 2024-11-21 | 7.5 High |
| Mobile Security Framework (MobSF) <=v3.7.8 Beta is vulnerable to Insecure Permissions. NOTE: the vendor's position is that authentication is intentionally not implemented because the product is not intended for an untrusted network environment. Use cases requiring authentication could, for example, use a reverse proxy server. | ||||
| CVE-2023-42253 | 1 Vehicle Management Project | 1 Vehicle Management | 2024-11-21 | 6.1 Medium |
| Code-Projects Vehicle Management 1.0 is vulnerable to Cross Site Scripting (XSS) in Add Accounts via Invoice No, To, and Mammul. | ||||
| CVE-2023-42222 | 1 Webcatalog | 1 Webcatalog | 2024-11-21 | 8.8 High |
| WebCatalog before 49.0 is vulnerable to Incorrect Access Control. WebCatalog calls the Electron shell.openExternal function without verifying that the URL is for an http or https resource, in some circumstances. | ||||
| CVE-2023-42188 | 1 Macwk | 1 Icecms | 2024-11-21 | 6.5 Medium |
| IceCMS v2.0.1 is vulnerable to Cross Site Request Forgery (CSRF). | ||||
| CVE-2023-42183 | 1 Lockss | 1 Classic Lockss Daemon | 2024-11-21 | 5.3 Medium |
| lockss-daemon (aka Classic LOCKSS Daemon) before 1.77.3 performs post-Unicode normalization, which may allow bypass of intended access restrictions, such as when U+1FEF is converted to a backtick. | ||||
| CVE-2023-42180 | 1 Lenosp Project | 1 Lenosp | 2024-11-21 | 8.8 High |
| An arbitrary file upload vulnerability in the /user/upload component of lenosp 1.0-1.2.0 allows attackers to execute html code via a crafted JPG file. | ||||
| CVE-2023-42147 | 1 Fit2cloud | 1 Cloudexplorer Lite | 2024-11-21 | 7.5 High |
| An issue in CloudExplorer Lite 1.3.1 allows an attacker to obtain sensitive information via the login key component. | ||||