Export limit exceeded: 382348 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (382348 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-41005 | 1 Pagekit | 1 Pagekit | 2024-11-21 | 7.8 High |
| An issue in Pagekit pagekit v.1.0.18 alows a remote attacker to execute arbitrary code via thedownloadAction and updateAction functions in UpdateController.php | ||||
| CVE-2023-41000 | 1 Gpac | 1 Gpac | 2024-11-21 | 5.5 Medium |
| GPAC through 2.2.1 has a use-after-free vulnerability in the function gf_bifs_flush_command_list in bifs/memory_decoder.c. | ||||
| CVE-2023-40998 | 1 O-ran-sc | 1 Ric Message Router | 2024-11-21 | 7.5 High |
| Buffer Overflow vulnerability in O-RAN Software Community ric-plt-lib-rmr v.4.9.0 allows a remote attacker to cause a denial of service via the packet size component. | ||||
| CVE-2023-40997 | 1 O-ran-sc | 1 Ric Message Router | 2024-11-21 | 7.5 High |
| Buffer Overflow vulnerability in O-RAN Software Community ric-plt-lib-rmr v.4.9.0 allows a remote attacker to cause a denial of service via a crafted packet. | ||||
| CVE-2023-40989 | 1 Jeecg | 1 Jeecg Boot | 2024-11-21 | 9.8 Critical |
| SQL injection vulnerbility in jeecgboot jeecg-boot v 3.0, 3.5.3 that allows a remote attacker to execute arbitrary code via a crafted request to the report/jeecgboot/jmreport/queryFieldBySql component. | ||||
| CVE-2023-40986 | 1 Webmin | 1 Webmin | 2024-11-21 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability in the Usermin Configuration function of Webmin v2.100 allows attackers to execute arbitrary web sripts or HTML via a crafted payload injected into the Custom field. | ||||
| CVE-2023-40985 | 1 Webmin | 1 Webmin | 2024-11-21 | 5.4 Medium |
| An issue was discovered in Webmin 2.100. The File Manager functionality allows an attacker to exploit a Cross-Site Scripting (XSS) vulnerability. By providing a malicious payload, an attacker can inject arbitrary code, which is then executed within the context of the victim's browser when any file is searched/replaced. | ||||
| CVE-2023-40984 | 1 Webmin | 1 Webmin | 2024-11-21 | 5.4 Medium |
| A reflected cross-site scripting (XSS) vulnerability in the File Manager function of Webmin v2.100 allows attackers to execute malicious scripts via injecting a crafted payload into the Replace in Results file. | ||||
| CVE-2023-40983 | 1 Webmin | 1 Webmin | 2024-11-21 | 6.1 Medium |
| A reflected cross-site scripting (XSS) vulnerability in the File Manager function of Webmin v2.100 allows attackers to execute malicious scripts via injecting a crafted payload into the Find in Results file. | ||||
| CVE-2023-40982 | 1 Webmin | 1 Webmin | 2024-11-21 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability in Webmin v2.100 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the cloned module name parameter. | ||||
| CVE-2023-40980 | 1 Diaowen | 1 Dwsurvey | 2024-11-21 | 9.8 Critical |
| File Upload vulnerability in DWSurvey DWSurvey-OSS v.3.2.0 and before allows a remote attacker to execute arbitrary code via the saveimage method and savveFile in the action/UploadAction.java file. | ||||
| CVE-2023-40970 | 1 Slims | 1 Senayan Library Management System | 2024-11-21 | 8.8 High |
| Senayan Library Management Systems SLIMS 9 Bulian v 9.6.1 is vulnerable to SQL Injection via admin/modules/circulation/loan_rules.php. | ||||
| CVE-2023-40969 | 1 Slims | 1 Senayan Library Management System | 2024-11-21 | 6.1 Medium |
| Senayan Library Management Systems SLIMS 9 Bulian v9.6.1 is vulnerable to Server Side Request Forgery (SSRF) via admin/modules/bibliography/pop_p2p.php. | ||||
| CVE-2023-40968 | 1 Hzeller | 1 Timg | 2024-11-21 | 7.5 High |
| Buffer Overflow vulnerability in hzeller timg v.1.5.1 and before allows a remote attacker to cause a denial of service via the 0x61200000045c address. | ||||
| CVE-2023-40958 | 1 Didotech | 1 Engineering \& Lifecycle Management | 2024-11-21 | 8.8 High |
| A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the query parameter in models/base_client.py component. | ||||
| CVE-2023-40957 | 1 Didotech | 1 Engineering \& Lifecycle Management | 2024-11-21 | 8.8 High |
| A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the request parameter in models/base_client.py component. | ||||
| CVE-2023-40956 | 1 Cloudroits | 1 Wesite Job Search | 2024-11-21 | 8.8 High |
| A SQL injection vulnerability in Cloudroits Website Job Search v.15.0 allows a remote authenticated attacker to execute arbitrary code via the name parameter in controllers/main.py component. | ||||
| CVE-2023-40955 | 1 Didotech | 1 Engineering \& Lifecycle Management | 2024-11-21 | 8.8 High |
| A SQL injection vulnerability in Didotech srl Engineering & Lifecycle Management (aka pdm) v.14.0, v.15.0 and v.16.0 fixed in pdm-14.0.1.0.0, pdm-15.0.1.0.0, and pdm-16.0.1.0.0 allows a remote authenticated attacker to execute arbitrary code via the select parameter in models/base_client.py component. | ||||
| CVE-2023-40954 | 1 Gmarczynski | 1 Dynamic Progress Bar | 2024-11-21 | 9.8 Critical |
| A SQL injection vulnerability in Grzegorz Marczynski Dynamic Progress Bar (aka web_progress) v. 11.0 through 11.0.2, v12.0 through v12.0.2, v.13.0 through v13.0.2, v.14.0 through v14.0.2.1, v.15.0 through v15.0.2, and v16.0 through v16.0.2.1 allows a remote attacker to gain privileges via the recency parameter in models/web_progress.py component. | ||||
| CVE-2023-40953 | 1 Idreamsoft | 1 Icms | 2024-11-21 | 8.8 High |
| icms 7.0.16 is vulnerable to Cross Site Request Forgery (CSRF). | ||||