Export limit exceeded: 381955 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (381955 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-41253 | 1 F5 | 2 Big-ip Domain Name System, Big-ip Local Traffic Manager | 2024-11-21 | 5.5 Medium |
| When on BIG-IP DNS or BIG-IP LTM enabled with DNS Services License, and a TSIG key is created, it is logged in plaintext in the audit log. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | ||||
| CVE-2023-41252 | 1 Intel | 1 Quickassist Technology Driver | 2024-11-21 | 6.5 Medium |
| Out-of-bounds read in some Intel(R) QAT software drivers for Windows before version QAT1.7-W-1.11.0 may allow an authenticated user to potentially enable denial of service via local access. | ||||
| CVE-2023-41250 | 1 Jetbrains | 1 Teamcity | 2024-11-21 | 3.5 Low |
| In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during user registration | ||||
| CVE-2023-41249 | 1 Jetbrains | 1 Teamcity | 2024-11-21 | 4.6 Medium |
| In JetBrains TeamCity before 2023.05.3 reflected XSS was possible during copying Build Step | ||||
| CVE-2023-41248 | 1 Jetbrains | 1 Teamcity | 2024-11-21 | 4.6 Medium |
| In JetBrains TeamCity before 2023.05.3 stored XSS was possible during Cloud Profiles configuration | ||||
| CVE-2023-41244 | 1 Buildfail | 1 Localize Remote Images | 2024-11-21 | 4.3 Medium |
| Cross-Site Request Forgery (CSRF) vulnerability in Buildfail Localize Remote Images plugin <= 1.0.9 versions. | ||||
| CVE-2023-41242 | 1 Creativehassan | 1 Snap Pixel | 2024-11-21 | 5.9 Medium |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Hassan Ali Snap Pixel plugin <= 1.5.7 versions. | ||||
| CVE-2023-41241 | 1 Surecart | 1 Surecart | 2024-11-21 | 5.9 Medium |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in SureCart WordPress Ecommerce For Creating Fast Online Stores plugin <= 2.5.0 versions. | ||||
| CVE-2023-41240 | 1 Varktech | 1 Pricing Deals For Woocommerce | 2024-11-21 | 5.3 Medium |
| Missing Authorization vulnerability in Vark Pricing Deals for WooCommerce.This issue affects Pricing Deals for WooCommerce: from n/a through 2.0.3.2. | ||||
| CVE-2023-41238 | 1 Ultimatelysocial | 1 Social Media Share Buttons \& Social Sharing Icons | 2024-11-21 | 7.1 High |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in UltimatelySocial Social Media Share Buttons & Social Sharing Icons plugin <= 2.8.3 versions. | ||||
| CVE-2023-41237 | 1 Everestthemes | 1 Arya Multipurpose Theme | 2024-11-21 | 7.1 High |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest Themes Arya Multipurpose Pro theme <= 1.0.8 versions. | ||||
| CVE-2023-41236 | 1 Wedevs | 1 Happy Addons For Elementor | 2024-11-21 | 7.1 High |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Happy addons Happy Elementor Addons Pro plugin <= 2.8.0 versions. | ||||
| CVE-2023-41235 | 1 Everestthemes | 1 Everest News | 2024-11-21 | 7.1 High |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Everest Themes Everest News Pro theme <= 1.1.7 versions. | ||||
| CVE-2023-41231 | 1 Intel | 1 Assistive Context-aware Toolkit | 2024-11-21 | 6.7 Medium |
| Incorrect default permissions in some ACAT software maintained by Intel(R) before version 2.0.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | ||||
| CVE-2023-41180 | 1 Apache | 1 Nifi Minifi C\+\+ | 2024-11-21 | 5.9 Medium |
| Incorrect certificate validation in InvokeHTTP on Apache NiFi MiNiFi C++ versions 0.13 to 0.14 allows an intermediary to present a forged certificate during TLS handshake negotation. The Disable Peer Verification property of InvokeHTTP was effectively flipped, disabling verification by default, when using HTTPS. Mitigation: Set the Disable Peer Verification property of InvokeHTTP to true when using MiNiFi C++ versions 0.13.0 or 0.14.0. Upgrading to MiNiFi C++ 0.15.0 corrects the default behavior. | ||||
| CVE-2023-41172 | 1 Netscout | 1 Ngeniusone | 2024-11-21 | 5.4 Medium |
| NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 4 of 4). | ||||
| CVE-2023-41170 | 1 Netscout | 1 Ngeniusone | 2024-11-21 | 6.1 Medium |
| NetScout nGeniusONE 6.3.4 build 2298 allows a Reflected Cross-Site scripting vulnerability. | ||||
| CVE-2023-41169 | 1 Netscout | 1 Ngeniusone | 2024-11-21 | 5.4 Medium |
| NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 2 of 4). | ||||
| CVE-2023-41168 | 1 Netscout | 1 Ngeniusone | 2024-11-21 | 5.4 Medium |
| NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 1 of 4). | ||||
| CVE-2023-41167 | 1 Webiny | 1 Webiny | 2024-11-21 | 4.8 Medium |
| @webiny/react-rich-text-renderer before 5.37.2 allows XSS attacks by content managers. This is a react component to render data coming from Webiny Headless CMS and Webiny Form Builder. Webiny is an open-source serverless enterprise CMS. The @webiny/react-rich-text-renderer package depends on the editor.js rich text editor to handle rich text content. The CMS stores rich text content from the editor.js into the database. When the @webiny/react-rich-text-renderer is used to render such content, it uses the dangerouslySetInnerHTML prop, without applying HTML sanitization. The issue arises when an actor, who in this context would specifically be a content manager with access to the CMS, inserts a malicious script as part of the user-defined input. This script is then injected and executed within the user's browser when the main page or admin page loads. | ||||