Export limit exceeded: 383877 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 383877 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (383877 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-36995 | 1 Travianz Project | 1 Travianz | 2024-11-21 | 6.1 Medium |
| TravianZ through 8.3.4 allows XSS via the Alliance tag/name, the statistics page, the link preferences, the Admin Logs, or the COOKUSR cookie. | ||||
| CVE-2023-36994 | 1 Travianz Project | 1 Travianz | 2024-11-21 | 9.8 Critical |
| In TravianZ 8.3.4 and 8.3.3, Incorrect Access Control in the installation script allows an attacker to overwrite the server configuration and inject PHP code. | ||||
| CVE-2023-36993 | 1 Travianz Project | 1 Travianz | 2024-11-21 | 9.8 Critical |
| The cryptographically insecure random number generator being used in TravianZ 8.3.4 and 8.3.3 in the password reset function allows an attacker to guess the password reset.parameters and to take over accounts. | ||||
| CVE-2023-36992 | 1 Travianz Project | 1 Travianz | 2024-11-21 | 7.2 High |
| PHP injection in TravianZ 8.3.4 and 8.3.3 in the config editor in the admin page allows remote attackers to execute PHP code. | ||||
| CVE-2023-36984 | 1 Lavalite | 1 Lavalite | 2024-11-21 | 7.5 High |
| LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure. | ||||
| CVE-2023-36983 | 1 Lavalite | 1 Lavalite | 2024-11-21 | 7.5 High |
| LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure. | ||||
| CVE-2023-36980 | 1 Ethereum | 1 Blockchain | 2024-11-21 | 5.3 Medium |
| An issue in Ethereum Blockchain v0.1.1+commit.6ff4cd6 cause the balance to be zeroed out when the value of betsize+casino.balance exceeds the threshold. | ||||
| CVE-2023-36970 | 1 Cmsmadesimple | 1 Cms Made Simple | 2024-11-21 | 5.4 Medium |
| A Cross-site scripting (XSS) vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web script or HTML via the File Upload function. | ||||
| CVE-2023-36969 | 1 Cmsmadesimple | 1 Cms Made Simple | 2024-11-21 | 8.8 High |
| CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function. | ||||
| CVE-2023-36968 | 1 Food Ordering System Project | 1 Food Ordering System | 2024-11-21 | 7.2 High |
| A SQL Injection vulnerability detected in Food Ordering System v1.0 allows attackers to run commands on the database by sending crafted SQL queries to the ID parameter. | ||||
| CVE-2023-36955 | 1 Totolink | 2 Cp300\+, Cp300\+ Firmware | 2024-11-21 | 9.8 Critical |
| TOTOLINK CP300+ <=V5.2cu.7594_B20200910 was discovered to contain a stack overflow via the File parameter in the function UploadCustomModule. | ||||
| CVE-2023-36954 | 1 Totolink | 2 Cp300\+, Cp300\+ Firmware | 2024-11-21 | 9.8 Critical |
| TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection. | ||||
| CVE-2023-36953 | 1 Totolink | 2 Cp300\+, Cp300\+ Firmware | 2024-11-21 | 9.8 Critical |
| TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection. | ||||
| CVE-2023-36952 | 1 Totolink | 2 Cp300\+, Cp300\+ Firmware | 2024-11-21 | 9.8 Critical |
| TOTOLINK CP300+ V5.2cu.7594_B20200910 was discovered to contain a stack overflow via the pingIp parameter in the function setDiagnosisCfg. | ||||
| CVE-2023-36950 | 1 Totolink | 4 A7000r, A7000r Firmware, X5000r and 1 more | 2024-11-21 | 8.8 High |
| TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth. | ||||
| CVE-2023-36947 | 1 Totolink | 4 A7000r, A7000r Firmware, X5000r and 1 more | 2024-11-21 | 8.8 High |
| TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the File parameter in the function UploadCustomModule. | ||||
| CVE-2023-36942 | 1 Phpgurukul | 1 Online Fire Reporting System | 2024-11-21 | 6.1 Medium |
| A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the website title field. | ||||
| CVE-2023-36941 | 1 Phpgurukul | 1 Online Fire Reporting System | 2024-11-21 | 6.1 Medium |
| A cross-site scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL 1.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the team name, leader, and member fields. | ||||
| CVE-2023-36940 | 1 Phpgurukul | 1 Online Fire Reporting System | 2024-11-21 | 4.8 Medium |
| Cross Site Scripting (XSS) vulnerability in PHPGurukul Online Fire Reporting System Using PHP and MySQL v.1.2 allows attackers to execute arbitrary code via a crafted payload injected into the search field. | ||||
| CVE-2023-36939 | 1 Phpgurukul | 1 Hostel Management System | 2024-11-21 | 6.1 Medium |
| Cross-Site Scripting (XSS) vulnerability in Hostel Management System v2.1 allows an attacker to execute arbitrary code via a crafted payload to the search booking field. | ||||