Export limit exceeded: 382011 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (382011 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-42331 | 1 Elitecms | 1 Elite Cms | 2024-11-21 | 8.8 High |
| A file upload vulnerability in EliteCMS v1.01 allows a remote attacker to execute arbitrary code via the manage_uploads.php component. | ||||
| CVE-2023-42328 | 1 Peppermint | 1 Peppermint | 2024-11-21 | 8.8 High |
| An issue in PeppermintLabs Peppermint v.0.2.4 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the hardcoded session cookie. | ||||
| CVE-2023-42327 | 1 Netgate | 1 Pfsense | 2024-11-21 | 5.4 Medium |
| Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page. | ||||
| CVE-2023-42326 | 1 Netgate | 2 Pfsense, Pfsense Plus | 2024-11-21 | 8.8 High |
| An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components. | ||||
| CVE-2023-42323 | 1 Mnbvcxz131421 | 1 Douhaocms | 2024-11-21 | 8.8 High |
| Cross Site Request Forgery (CSRF) vulnerability in DouHaocms v.3.3 allows a remote attacker to execute arbitrary code via the adminAction.class.php file. | ||||
| CVE-2023-42322 | 1 Icmsdev | 1 Icms | 2024-11-21 | 9.8 Critical |
| Insecure Permissions vulnerability in icmsdev iCMS v.7.0.16 allows a remote attacker to obtain sensitive information. | ||||
| CVE-2023-42321 | 1 Icmsdev | 1 Icms | 2024-11-21 | 8.8 High |
| Cross Site Request Forgery (CSRF) vulnerability in icmsdev iCMSv.7.0.16 allows a remote attacker to execute arbitrary code via the user.admincp.php, members.admincp.php, and group.admincp.php files. | ||||
| CVE-2023-42320 | 1 Tenda | 3 Ac10, Ac10 Firmware, Ac10v4 | 2024-11-21 | 9.8 Critical |
| Buffer Overflow vulnerability in Tenda AC10V4 v.US_AC10V4.0si_V16.03.10.13_cn_TDC01 allows a remote attacker to cause a denial of service via the mac parameter in the GetParentControlInfo function. | ||||
| CVE-2023-42319 | 1 Ethereum | 1 Go Ethereum | 2024-11-21 | 7.5 High |
| Geth (aka go-ethereum) through 1.13.4, when --http --graphql is used, allows remote attackers to cause a denial of service (memory consumption and daemon hang) via a crafted GraphQL query. NOTE: the vendor's position is that the "graphql endpoint [is not] designed to withstand attacks by hostile clients, nor handle huge amounts of clients/traffic. | ||||
| CVE-2023-42299 | 1 Openimageio | 1 Openimageio | 2024-11-21 | 9.8 Critical |
| Buffer Overflow vulnerability in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service via the read_subimage_data function. | ||||
| CVE-2023-42298 | 1 Gpac | 1 Gpac | 2024-11-21 | 5.5 Medium |
| An issue in GPAC GPAC v.2.2.1 and before allows a local attacker to cause a denial of service via the Q_DecCoordOnUnitSphere function of file src/bifs/unquantize.c. | ||||
| CVE-2023-42295 | 1 Openimageio | 1 Openimageio | 2024-11-21 | 8.8 High |
| An issue in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service via the read_rle_image function of file bifs/unquantize.c | ||||
| CVE-2023-42284 | 1 Tyk | 1 Tyk | 2024-11-21 | 9.8 Critical |
| Blind SQL injection in api_version parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query. | ||||
| CVE-2023-42283 | 1 Tyk | 1 Tyk | 2024-11-21 | 9.8 Critical |
| Blind SQL injection in api_id parameter in Tyk Gateway version 5.0.3 allows attacker to access and dump the database via a crafted SQL query. | ||||
| CVE-2023-42280 | 1 Springernature | 1 Mee-admin | 2024-11-21 | 7.5 High |
| mee-admin 1.5 is vulnerable to Directory Traversal. The download method in the CommonFileController.java file does not verify the incoming data, resulting in arbitrary file reading. | ||||
| CVE-2023-42279 | 1 Iteachyou | 1 Dreamer Cms | 2024-11-21 | 9.8 Critical |
| Dreamer CMS v4.1.3 was discovered to contain a SQL injection vulnerability via the model-form-management-field form. | ||||
| CVE-2023-42278 | 1 Hutool | 1 Hutool | 2024-11-21 | 7.5 High |
| hutool v5.8.21 was discovered to contain a buffer overflow via the component JSONUtil.parse(). | ||||
| CVE-2023-42277 | 1 Hutool | 1 Hutool | 2024-11-21 | 9.8 Critical |
| hutool v5.8.21 was discovered to contain a buffer overflow via the component jsonObject.putByPath. | ||||
| CVE-2023-42270 | 1 Grocy Project | 1 Grocy | 2024-11-21 | 8.8 High |
| Grocy <= 4.0.2 is vulnerable to Cross Site Request Forgery (CSRF). | ||||
| CVE-2023-42268 | 1 Jeecg | 1 Jeecg Boot | 2024-11-21 | 9.8 Critical |
| Jeecg boot up to v3.5.3 was discovered to contain a SQL injection vulnerability via the component /jeecg-boot/jmreport/show. | ||||