Export limit exceeded: 381947 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (381947 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-40970 | 1 Slims | 1 Senayan Library Management System | 2024-11-21 | 8.8 High |
| Senayan Library Management Systems SLIMS 9 Bulian v 9.6.1 is vulnerable to SQL Injection via admin/modules/circulation/loan_rules.php. | ||||
| CVE-2023-40969 | 1 Slims | 1 Senayan Library Management System | 2024-11-21 | 6.1 Medium |
| Senayan Library Management Systems SLIMS 9 Bulian v9.6.1 is vulnerable to Server Side Request Forgery (SSRF) via admin/modules/bibliography/pop_p2p.php. | ||||
| CVE-2023-40968 | 1 Hzeller | 1 Timg | 2024-11-21 | 7.5 High |
| Buffer Overflow vulnerability in hzeller timg v.1.5.1 and before allows a remote attacker to cause a denial of service via the 0x61200000045c address. | ||||
| CVE-2023-40958 | 1 Didotech | 1 Engineering \& Lifecycle Management | 2024-11-21 | 8.8 High |
| A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the query parameter in models/base_client.py component. | ||||
| CVE-2023-40957 | 1 Didotech | 1 Engineering \& Lifecycle Management | 2024-11-21 | 8.8 High |
| A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the request parameter in models/base_client.py component. | ||||
| CVE-2023-40956 | 1 Cloudroits | 1 Wesite Job Search | 2024-11-21 | 8.8 High |
| A SQL injection vulnerability in Cloudroits Website Job Search v.15.0 allows a remote authenticated attacker to execute arbitrary code via the name parameter in controllers/main.py component. | ||||
| CVE-2023-40955 | 1 Didotech | 1 Engineering \& Lifecycle Management | 2024-11-21 | 8.8 High |
| A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the select parameter in models/base_client.py component. | ||||
| CVE-2023-40954 | 1 Gmarczynski | 1 Dynamic Progress Bar | 2024-11-21 | 9.8 Critical |
| A SQL injection vulnerability in Grzegorz Marczynski Dynamic Progress Bar (aka web_progress) v. 11.0 through 11.0.2, v12.0 through v12.0.2, v.13.0 through v13.0.2, v.14.0 through v14.0.2.1, v.15.0 through v15.0.2, and v16.0 through v16.0.2.1 allows a remote attacker to gain privileges via the recency parameter in models/web_progress.py component. | ||||
| CVE-2023-40953 | 1 Idreamsoft | 1 Icms | 2024-11-21 | 8.8 High |
| icms 7.0.16 is vulnerable to Cross Site Request Forgery (CSRF). | ||||
| CVE-2023-40946 | 1 Schoolmate Project | 1 Schoolmate | 2024-11-21 | 9.8 Critical |
| Schoolmate 1.3 is vulnerable to SQL Injection in the variable $username from SESSION in ValidateLogin.php. | ||||
| CVE-2023-40945 | 1 Doctor Appointment System Project | 1 Doctor Appointment System | 2024-11-21 | 9.8 Critical |
| Sourcecodester Doctor Appointment System 1.0 is vulnerable to SQL Injection in the variable $userid at doctors\myDetails.php. | ||||
| CVE-2023-40944 | 1 Schoolmate Project | 1 Schoolmate | 2024-11-21 | 9.8 Critical |
| Schoolmate 1.3 is vulnerable to SQL Injection in the variable $schoolname from Database at ~\header.php. | ||||
| CVE-2023-40942 | 2 Tenda, Tendacn | 3 Ac9v3.0br, Ac9, Ac9 Firmware | 2024-11-21 | 9.8 Critical |
| Tenda AC9 V3.0BR_V15.03.06.42_multi_TD01 was discovered stack overflow via parameter 'firewall_value' at url /goform/SetFirewallCfg. | ||||
| CVE-2023-40934 | 1 Nagios | 1 Nagios Xi | 2024-11-21 | 7.2 High |
| A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings. | ||||
| CVE-2023-40933 | 1 Nagios | 1 Nagios Xi | 2024-11-21 | 8.8 High |
| A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to execute arbitrary SQL commands via the ID parameter sent to the update_banner_message() function. | ||||
| CVE-2023-40932 | 1 Nagios | 1 Nagios Xi | 2024-11-21 | 5.4 Medium |
| A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo component to inject arbitrary javascript or HTML via the alt-text field. This affects all pages containing the navbar including the login page which means the attacker is able to to steal plaintext credentials. | ||||
| CVE-2023-40931 | 1 Nagios | 1 Nagios Xi | 2024-11-21 | 6.5 Medium |
| A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php | ||||
| CVE-2023-40930 | 1 Skyworth | 1 Skyworth Os | 2024-11-21 | 6.8 Medium |
| An issue in the directory /system/bin/blkid of Skyworth v3.0 allows attackers to perform a directory traversal via mounting the Udisk to /mnt/. | ||||
| CVE-2023-40924 | 2 Contec, Solar View | 3 Solarview Compact, Solarview Compact Firmware, Compact | 2024-11-21 | 7.5 High |
| SolarView Compact < 6.00 is vulnerable to Directory Traversal. | ||||
| CVE-2023-40922 | 1 Kerawen | 1 Kerawen | 2024-11-21 | 9.8 Critical |
| kerawen before v2.5.1 was discovered to contain a SQL injection vulnerability via the ocs_id_cart parameter at KerawenDeliveryModuleFrontController::initContent(). | ||||