Export limit exceeded: 381947 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (381947 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-40813 | 1 Opencrx | 1 Opencrx | 2024-11-21 | 6.1 Medium |
| OpenCRX version 5.2.0 is vulnerable to HTML injection via Activity Saved Search Creation. | ||||
| CVE-2023-40812 | 1 Opencrx | 1 Opencrx | 2024-11-21 | 6.1 Medium |
| OpenCRX version 5.2.0 is vulnerable to HTML injection via the Accounts Group Name Field. | ||||
| CVE-2023-40810 | 1 Opencrx | 1 Opencrx | 2024-11-21 | 6.1 Medium |
| OpenCRX version 5.2.0 is vulnerable to HTML injection via Product Name Field. | ||||
| CVE-2023-40809 | 1 Opencrx | 1 Opencrx | 2024-11-21 | 6.1 Medium |
| OpenCRX version 5.2.0 is vulnerable to HTML injection via the Activity Search Criteria-Activity Number. | ||||
| CVE-2023-40802 | 1 Tenda | 2 Ac23, Ac23 Firmware | 2024-11-21 | 6.5 Medium |
| The get_parentControl_list_Info function does not verify the parameters entered by the user, causing a post-authentication heap overflow vulnerability in Tenda AC23 v16.03.07.45_cn | ||||
| CVE-2023-40801 | 1 Tenda | 2 Ac23, Ac23 Firmware | 2024-11-21 | 8.8 High |
| The sub_451784 function does not validate the parameters entered by the user, resulting in a stack overflow vulnerability in Tenda AC23 v16.03.07.45_cn | ||||
| CVE-2023-40800 | 1 Tenda | 2 Ac23, Ac23 Firmware | 2024-11-21 | 8.8 High |
| The compare_parentcontrol_time function does not authenticate user input parameters, resulting in a post-authentication stack overflow vulnerability in Tenda AC23 v16.03.07.45_cn. | ||||
| CVE-2023-40799 | 1 Tenda | 2 Ac23, Ac23 Firmware | 2024-11-21 | 9.8 Critical |
| Tenda AC23 Vv16.03.07.45_cn is vulnerable to Buffer Overflow via sub_450A4C function. | ||||
| CVE-2023-40798 | 1 Tenda | 2 Ac23, Ac23 Firmware | 2024-11-21 | 8.8 High |
| In Tenda AC23 v16.03.07.45_cn, the formSetIPv6status and formGetWanParameter functions do not authenticate user input parameters, resulting in a post-authentication stack overflow vulnerability. | ||||
| CVE-2023-40797 | 1 Tenda | 2 Ac23, Ac23 Firmware | 2024-11-21 | 8.8 High |
| In Tenda AC23 v16.03.07.45_cn, the sub_4781A4 function does not validate the parameters entered by the user, resulting in a post-authentication stack overflow vulnerability. | ||||
| CVE-2023-40796 | 1 Phicomm | 2 K2, K2 Firmware | 2024-11-21 | 7.8 High |
| Phicomm k2 v22.6.529.216 was discovered to contain a command injection vulnerability via the function luci.sys.call. | ||||
| CVE-2023-40791 | 2 Linux, Netapp | 9 Linux Kernel, H300s, H300s Firmware and 6 more | 2024-11-21 | 6.3 Medium |
| extract_user_to_sg in lib/scatterlist.c in the Linux kernel before 6.4.12 fails to unpin pages in a certain situation, as demonstrated by a WARNING for try_grab_page. | ||||
| CVE-2023-40788 | 1 Bladex | 1 Springblade | 2024-11-21 | 5.3 Medium |
| SpringBlade <=V3.6.0 is vulnerable to Incorrect Access Control due to incorrect configuration in the default gateway resulting in unauthorized access to error logs | ||||
| CVE-2023-40787 | 1 Bladex | 1 Springblade | 2024-11-21 | 9.8 Critical |
| In SpringBlade V3.6.0 when executing SQL query, the parameters submitted by the user are not wrapped in quotation marks, which leads to SQL injection. | ||||
| CVE-2023-40786 | 1 Hkcms | 1 Hkcms | 2024-11-21 | 5.4 Medium |
| HKcms v2.3.0.230709 is vulnerable to Cross Site Scripting (XSS) allowing administrator cookies to be stolen. | ||||
| CVE-2023-40784 | 1 Dedecms | 1 Dedecms | 2024-11-21 | 9.8 Critical |
| DedeCMS 5.7.102 has a File Upload vulnerability via uploads/dede/module_make.php. | ||||
| CVE-2023-40781 | 1 Libming | 1 Libming | 2024-11-21 | 6.5 Medium |
| Buffer Overflow vulnerability in Libming Libming v.0.4.8 allows a remote attacker to cause a denial of service via a crafted .swf file to the makeswf function. | ||||
| CVE-2023-40779 | 1 Icewarp | 1 Deep Castle G2 | 2024-11-21 | 6.1 Medium |
| An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafted request to the URL. | ||||
| CVE-2023-40771 | 1 Dataease | 1 Dataease | 2024-11-21 | 7.5 High |
| SQL injection vulnerability in DataEase v.1.18.9 allows a remote attacker to obtain sensitive information via a crafted string outside of the blacklist function. | ||||
| CVE-2023-40767 | 1 Phpjabbers | 1 Make An Offer Widget | 2024-11-21 | 9.8 Critical |
| User enumeration is found in in PHPJabbers Make an Offer Widget v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | ||||