Export limit exceeded: 385178 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (385178 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-43979 | 1 Prestahero | 1 Ybc Blog | 2024-11-21 | 9.8 Critical |
| ETS Soft ybc_blog before v4.4.0 was discovered to contain a SQL injection vulnerability via the component Ybc_blogBlogModuleFrontController::getPosts(). | ||||
| CVE-2023-43976 | 1 Catonetworks | 1 Cato Client | 2024-11-21 | 8.1 High |
| An issue in CatoNetworks CatoClient before v.5.4.0 allows attackers to escalate privileges and winning the race condition (TOCTOU) via the PrivilegedHelperTool component. | ||||
| CVE-2023-43961 | 1 Dromara | 1 Sa-token | 2024-11-21 | 8.8 High |
| An issue in Dromara SaToken version 1.3.50RC and before when using Spring dynamic controllers, a specially crafted request may cause an authentication bypass. | ||||
| CVE-2023-43960 | 2 D-link, Dlink | 3 Dph-400se Fru, Dph-400se, Dph-400se Firmware | 2024-11-21 | 8.8 High |
| An issue in DLINK DPH-400SE FRU 2.2.15.8 allows a remote attacker to escalate privileges via the User Modify function in the Maintenance/Access function component. | ||||
| CVE-2023-43959 | 1 Yealink | 2 Sip-t19p-e2, Sip-t19p-e2 Firmware | 2024-11-21 | 8.8 High |
| An issue in YeaLinkSIP-T19P-E2 v.53.84.0.15 allows a remote privileged attacker to execute arbitrary code via a crafted request the ping function of the diagnostic component. | ||||
| CVE-2023-43955 | 1 Fedirtsapana | 1 Tv Bro | 2024-11-21 | 9.8 Critical |
| The com.phlox.tvwebbrowser TV Bro application through 2.0.0 for Android mishandles external intents through WebView. This allows attackers to execute arbitrary code, create arbitrary files. and perform arbitrary downloads via JavaScript that uses takeBlobDownloadData. | ||||
| CVE-2023-43952 | 1 Sscms Project | 1 Sscms | 2024-11-21 | 5.4 Medium |
| SSCMS 7.2.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Material Management component. | ||||
| CVE-2023-43951 | 1 Sscms Project | 1 Sscms | 2024-11-21 | 5.4 Medium |
| SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Column Management component. | ||||
| CVE-2023-43909 | 2 Hospital Management System, Hospital Management System Project | 2 Hospital Management System, Hospital Management System | 2024-11-21 | 9.1 Critical |
| Hospital Management System thru commit 4770d was discovered to contain a SQL injection vulnerability via the app_contact parameter in appsearch.php. | ||||
| CVE-2023-43907 | 1 Optipng Project | 1 Optipng | 2024-11-21 | 7.8 High |
| OptiPNG v0.7.7 was discovered to contain a global buffer overflow via the 'buffer' variable at gifread.c. | ||||
| CVE-2023-43906 | 1 Onworks | 1 Xolo Cms | 2024-11-21 | 6.1 Medium |
| Xolo CMS v0.11 was discovered to contain a reflected cross-site scripting (XSS) vulnerability. | ||||
| CVE-2023-43905 | 1 Writercms | 1 Writercms | 2024-11-21 | 7.5 High |
| Incorrect access control in writercms v1.1.0 allows attackers to directly obtain backend account passwords via unspecified vectors. | ||||
| CVE-2023-43899 | 1 Hansuncms Project | 1 Hansuncms | 2024-11-21 | 9.8 Critical |
| hansun CMS v1.0 was discovered to contain a SQL injection vulnerability via the component /ajax/ajax_login.ashx. | ||||
| CVE-2023-43896 | 1 Macrium | 1 Reflect | 2024-11-21 | 7.8 High |
| A buffer overflow in Macrium Reflect 8.1.7544 and below allows attackers to escalate privileges or execute arbitrary code. | ||||
| CVE-2023-43893 | 1 Netis-systems | 2 N3m, N3m Firmware | 2024-11-21 | 9.8 Critical |
| Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the wakeup_mac parameter in the Wake-On-LAN (WoL) function. This vulnerability is exploited via a crafted payload. | ||||
| CVE-2023-43891 | 1 Netis-systems | 2 N3m, N3m Firmware | 2024-11-21 | 9.8 Critical |
| Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the Changing Username and Password function. This vulnerability is exploited via a crafted payload. | ||||
| CVE-2023-43890 | 1 Netis-systems | 2 N3m, N3m Firmware | 2024-11-21 | 8.8 High |
| Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the diagnostic tools page. This vulnerability is exploited via a crafted HTTP request. | ||||
| CVE-2023-43886 | 1 Tenda | 2 Rx9 Pro, Rx9 Pro Firmware | 2024-11-21 | 7.1 High |
| A buffer overflow in the HTTP server component of Tenda RX9 Pro v22.03.02.20 might allow an authenticated attacker to overwrite memory. | ||||
| CVE-2023-43885 | 1 Tenda | 2 Rx9 Pro, Rx9 Pro Firmware | 2024-11-21 | 8.1 High |
| Missing error handling in the HTTP server component of Tenda RX9 Pro Firmware V22.03.02.20 allows authenticated attackers to arbitrarily lock the device. | ||||
| CVE-2023-43884 | 1 Intelliants | 1 Subrion | 2024-11-21 | 5.4 Medium |
| A Cross-site scripting (XSS) vulnerability in Reference ID from the panel Transactions, of Subrion v4.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into 'Reference ID' parameter. | ||||