Export limit exceeded: 381670 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (381670 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-39641 | 1 Activedesign | 1 Full Affiliates | 2024-11-21 | 9.8 Critical |
| Active Design psaffiliate before v1.9.8 was discovered to contain a SQL injection vulnerability via the component PsaffiliateGetaffiliatesdetailsModuleFrontController::initContent(). | ||||
| CVE-2023-39640 | 1 Uplight | 1 Cookie Law | 2024-11-21 | 9.8 Critical |
| UpLight cookiebanner before 1.5.1 was discovered to contain a SQL injection vulnerability via the component Hook::getHookModuleExecList(). | ||||
| CVE-2023-39639 | 1 Leotheme | 1 Leoblog | 2024-11-21 | 9.8 Critical |
| LeoTheme leoblog up to v3.1.2 was discovered to contain a SQL injection vulnerability via the component LeoBlogBlog::getListBlogs. | ||||
| CVE-2023-39638 | 2 D-link, Dlink | 3 Dir-859 A1, Dir-859 A1, Dir-859 A1 Firmware | 2024-11-21 | 9.8 Critical |
| D-LINK DIR-859 A1 1.05 and A1 1.06B01 Beta01 was discovered to contain a command injection vulnerability via the lxmldbc_system function at /htdocs/cgibin. | ||||
| CVE-2023-39637 | 2 D-link, Dlink | 3 Dir-816 A2, Dir-816, Dir-816 Firmware | 2024-11-21 | 9.8 Critical |
| D-Link DIR-816 A2 1.10 B05 was discovered to contain a command injection vulnerability via the component /goform/Diagnosis. | ||||
| CVE-2023-39631 | 1 Langchain | 1 Langchain | 2024-11-21 | 9.8 Critical |
| An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library. | ||||
| CVE-2023-39620 | 2 Buffalo, Buffalo America Inc | 3 Terastation Nas 5410r, Terastation Nas 5410r Firmware, Terastation Nas Ts5410r | 2024-11-21 | 7.5 High |
| An Issue in Buffalo America, Inc. TeraStation NAS TS5410R v.5.00 thru v.0.07 allows a remote attacker to obtain sensitive information via the guest account function. | ||||
| CVE-2023-39619 | 1 Teomantuncer | 1 Node Email Check | 2024-11-21 | 7.5 High |
| ReDos in NPMJS Node Email Check v.1.0.4 allows an attacker to cause a denial of service via a crafted string to the scpSyntax component. | ||||
| CVE-2023-39618 | 1 Totolink | 2 X5000r, X5000r Firmware | 2024-11-21 | 9.8 Critical |
| TOTOLINK X5000R B20210419 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCfg interface. | ||||
| CVE-2023-39617 | 1 Totolink | 2 X5000r, X5000r Firmware | 2024-11-21 | 9.8 Critical |
| TOTOLINK X5000R_V9.1.0cu.2089_B20211224 and X5000R_V9.1.0cu.2350_B20230313 were discovered to contain a remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function. | ||||
| CVE-2023-39616 | 1 Aomedia | 1 Aomedia | 2024-11-21 | 7.5 High |
| AOMedia v3.0.0 to v3.5.0 was discovered to contain an invalid read memory access via the component assign_frame_buffer_p in av1/common/av1_common_int.h. | ||||
| CVE-2023-39610 | 1 Tp-link | 2 Tapo C100, Tapo C100 Firmware | 2024-11-21 | 6.5 Medium |
| An issue in TP-Link Tapo C100 v1.1.15 Build 211130 Rel.15378n(4555) and before allows attackers to cause a Denial of Service (DoS) via supplying a crafted web request. | ||||
| CVE-2023-39600 | 1 Icewarp | 1 Icewarp | 2024-11-21 | 6.1 Medium |
| IceWarp 11.4.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the color parameter. | ||||
| CVE-2023-39598 | 1 Icewarp | 1 Webclient | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting vulnerability in IceWarp Corporation WebClient v.10.2.1 allows a remote attacker to execute arbitrary code via a crafted payload to the mid parameter. | ||||
| CVE-2023-39584 | 1 Hexo | 1 Hexo | 2024-11-21 | 7.5 High |
| Hexo up to v7.0.0 (RC2) was discovered to contain an arbitrary file read vulnerability. | ||||
| CVE-2023-39582 | 1 Chamilo | 1 Chamilo Lms | 2024-11-21 | 4.9 Medium |
| SQL Injection vulnerability in Chamilo LMS v.1.11 thru v.1.11.20 allows a remote privileged attacker to obtain sensitive information via the import sessions functions. | ||||
| CVE-2023-39578 | 1 Tribalsystems | 1 Zenario | 2024-11-21 | 4.8 Medium |
| A stored cross-site scripting (XSS) vulnerability in the Create function of Zenario CMS v9.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Menu navigation text field. | ||||
| CVE-2023-39575 | 1 Isl | 1 Arp-guard | 2024-11-21 | 5.4 Medium |
| A reflected cross-site scripting (XSS) vulnerability in the url_str URL parameter of ISL ARP Guard v4.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | ||||
| CVE-2023-39562 | 1 Gpac | 1 Gpac | 2024-11-21 | 5.5 Medium |
| GPAC v2.3-DEV-rev449-g5948e4f70-master was discovered to contain a heap-use-after-free via the gf_bs_align function at bitstream.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted file. | ||||
| CVE-2023-39560 | 1 Ectouch | 1 Ectouch | 2024-11-21 | 9.8 Critical |
| ECTouch v2 was discovered to contain a SQL injection vulnerability via the $arr['id'] parameter at \default\helpers\insert.php. | ||||