Export limit exceeded: 380900 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (380900 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-30322 | 1 Chatengine Project | 1 Chatengine | 2024-11-21 | 5.4 Medium |
| Cross Site Scripting (XSS) vulnerability in username field in /src/chatbotapp/chatWindow.java in Payatu ChatEngine v.1.0, allows attackers to execute arbitrary code. | ||||
| CVE-2023-30321 | 1 Chatengine Project | 1 Chatengine | 2024-11-21 | 9.0 Critical |
| Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/LoginServlet.java in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, allows attackers to execute arbitrary code. | ||||
| CVE-2023-30320 | 1 Chatengine Project | 1 Chatengine | 2024-11-21 | 9.0 Critical |
| Cross Site Scripting (XSS) vulnerability in textMessage field in /src/chatbotapp/chatWindow.java in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, allows attackers to execute arbitrary code. | ||||
| CVE-2023-30319 | 1 Chatengine Project | 1 Chatengine | 2024-11-21 | 9.6 Critical |
| Cross Site Scripting (XSS) vulnerability in username field in /src/chatbotapp/LoginServlet.java in wliang6 ChatEngine commit fded8e710ad59f816867ad47d7fc4862f6502f3e, allows attackers to execute arbitrary code. | ||||
| CVE-2023-30297 | 1 N-able | 1 N-central | 2024-11-21 | 7.0 High |
| An issue found in N-able Technologies N-central Server before 2023.4 allows a local attacker to execute arbitrary code via the monitoring function of the server. | ||||
| CVE-2023-30226 | 1 Rizin | 1 Rizin | 2024-11-21 | 5.5 Medium |
| An issue was discovered in function get_gnu_verneed in rizinorg Rizin prior to 0.5.0 verneed_entry allows attackers to cause a denial of service via crafted elf file. | ||||
| CVE-2023-30223 | 1 4d | 1 Server | 2024-11-21 | 7.5 High |
| A broken authentication vulnerability in 4D SAS 4D Server software v17, v18, v19 R7, and earlier allows attackers to send crafted TCP packets containing requests to perform arbitrary actions. | ||||
| CVE-2023-30222 | 1 4d | 1 Server | 2024-11-21 | 7.5 High |
| An information disclosure vulnerability in 4D SAS 4D Server Application v17, v18, v19 R7 and earlier allows attackers to retrieve password hashes for all users via eavesdropping. | ||||
| CVE-2023-30207 | 1 Kodi | 1 Kodi | 2024-11-21 | 5.5 Medium |
| A divide by zero issue discovered in Kodi Home Theater Software 19.5 and earlier allows attackers to cause a denial of service via use of crafted mp3 file. | ||||
| CVE-2023-30200 | 1 Advancedplugins | 1 Ultimateimagetool | 2024-11-21 | 7.5 High |
| In the module “Image: WebP, Compress, Zoom, Lazy load, Alt & More” (ultimateimagetool) in versions up to 2.1.02 from Advanced Plugins for PrestaShop, a guest can download personal informations without restriction by performing a path traversal attack. | ||||
| CVE-2023-30195 | 1 Lineagrafica | 1 Lgdetailedorder | 2024-11-21 | 7.5 High |
| In the module "Detailed Order" (lgdetailedorder) in version up to 1.1.20 from Linea Grafica for PrestaShop, a guest can download personal informations without restriction formatted in json. | ||||
| CVE-2023-30188 | 1 Onlyoffice | 1 Document Server | 2024-11-21 | 7.5 High |
| Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via crafted JavaScript file. | ||||
| CVE-2023-30187 | 1 Onlyoffice | 1 Document Server | 2024-11-21 | 9.8 Critical |
| An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file. | ||||
| CVE-2023-30186 | 1 Onlyoffice | 1 Document Server | 2024-11-21 | 9.8 Critical |
| A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file. | ||||
| CVE-2023-30154 | 1 Shoprunners | 1 Aftermail | 2024-11-21 | 9.8 Critical |
| Multiple improper neutralization of SQL parameters in module AfterMail (aftermailpresta) for PrestaShop, before version 2.2.1, allows remote attackers to perform SQL injection attacks via `id_customer`, `id_conf`, `id_product` and `token` parameters in `aftermailajax.php via the 'id_product' parameter in hooks DisplayRightColumnProduct and DisplayProductButtons. | ||||
| CVE-2023-30153 | 1 Prestashop | 1 Payplug | 2024-11-21 | 9.8 Critical |
| An SQL injection vulnerability in the Payplug (payplug) module for PrestaShop, in versions 3.6.0, 3.6.1, 3.6.2, 3.6.3, 3.7.0 and 3.7.1, allows remote attackers to execute arbitrary SQL commands via the ajax.php front controller. | ||||
| CVE-2023-30146 | 1 Assmann | 2 Ht-ip211hdp, Ht-ip211hdp Firmware | 2024-11-21 | 7.5 High |
| Assmann Digitus Plug&View IP Camera HT-IP211HDP, version 2.000.022 allows unauthenticated attackers to download a copy of the camera's settings and the administrator credentials. | ||||
| CVE-2023-30132 | 1 Ixpdata | 1 Easyinstall | 2024-11-21 | 7.8 High |
| An issue discovered in IXP Data EasyInstall 6.6.14907.0 allows attackers to gain escalated privileges via static Cryptographic Key. | ||||
| CVE-2023-30131 | 1 Ixpdata | 1 Easyinstall | 2024-11-21 | 9.8 Critical |
| An issue discovered in IXP EasyInstall 6.6.14884.0 allows attackers to run arbitrary commands, gain escalated privilege, and cause other unspecified impacts via unauthenticated API calls. | ||||
| CVE-2023-30058 | 1 Xxyopen | 1 Novel-plus | 2024-11-21 | 9.8 Critical |
| novel-plus 3.6.2 is vulnerable to SQL Injection. | ||||