Export limit exceeded: 372514 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (372514 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2025-56162 | 2 Yiovo, Yoshop | 2 Firefly Mall, Yoshop | 2025-10-30 | 6.5 Medium |
| YOSHOP 2.0 suffers from an unauthenticated SQL injection in the goodsIds parameter of the /api/goods/listByIds endpoint. The getListByIds function concatenates user input into orderRaw('field(goods_id, ...)'), allowing attackers to: (a) enumerate or modify database data, including dumping admin password hashes; (b) write web-shell files or invoke xp_cmdshell, leading to remote code execution on servers configured with sufficient DB privileges. | ||||
| CVE-2024-30130 | 1 Hcltech | 1 Nomad Server On Domino | 2025-10-30 | 3.7 Low |
| HCL Nomad server on Domino is vulnerable to the cache containing sensitive information which could potentially give an attacker the ability to acquire the sensitive information. | ||||
| CVE-2024-30128 | 1 Hcltech | 1 Nomad Server On Domino | 2025-10-30 | 8.6 High |
| HCL Nomad server on Domino is affected by an open proxy vulnerability in which an unauthenticated attacker can mask their original source IP address. This may enable an attacker to trick the user into exposing sensitive information. | ||||
| CVE-2024-30134 | 1 Hcltech | 2 Traveler, Traveler For Microsoft Outlook | 2025-10-30 | 6.7 Medium |
| The HCL Traveler for Microsoft Outlook executable (HTMO.exe) is being flagged as potentially Malicious Software or an Unrecognized Application. | ||||
| CVE-2025-8848 | 1 Librechat | 1 Librechat | 2025-10-30 | 5.4 Medium |
| A vulnerability in danny-avila/librechat version 0.7.9 allows for HTML injection via the Accept-Language header. When a logged-in user sends an HTTP GET request with a crafted Accept-Language header, arbitrary HTML can be injected into the <html lang=""> tag of the response. This can lead to potential security risks such as cross-site scripting (XSS) attacks. | ||||
| CVE-2023-38163 | 1 Microsoft | 1 Windows Defender Security Intelligence Updates | 2025-10-30 | 7.8 High |
| Windows Defender Attack Surface Reduction Security Feature Bypass | ||||
| CVE-2023-36739 | 1 Microsoft | 1 3d Viewer | 2025-10-30 | 7.8 High |
| 3D Viewer Remote Code Execution Vulnerability | ||||
| CVE-2023-36740 | 1 Microsoft | 1 3d Viewer | 2025-10-30 | 7.8 High |
| 3D Viewer Remote Code Execution Vulnerability | ||||
| CVE-2023-36777 | 1 Microsoft | 1 Exchange Server | 2025-10-30 | 5.7 Medium |
| Microsoft Exchange Server Information Disclosure Vulnerability | ||||
| CVE-2023-36760 | 1 Microsoft | 1 3d Viewer | 2025-10-30 | 7.8 High |
| 3D Viewer Remote Code Execution Vulnerability | ||||
| CVE-2023-36761 | 1 Microsoft | 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more | 2025-10-30 | 6.5 Medium |
| Microsoft Word Information Disclosure Vulnerability | ||||
| CVE-2023-36762 | 1 Microsoft | 5 365 Apps, Office, Office Long Term Servicing Channel and 2 more | 2025-10-30 | 7.3 High |
| Microsoft Word Remote Code Execution Vulnerability | ||||
| CVE-2023-36763 | 1 Microsoft | 4 365 Apps, Office, Office Long Term Servicing Channel and 1 more | 2025-10-30 | 7.5 High |
| Microsoft Outlook Information Disclosure Vulnerability | ||||
| CVE-2023-36764 | 1 Microsoft | 1 Sharepoint Server | 2025-10-30 | 8.8 High |
| Microsoft SharePoint Server Elevation of Privilege Vulnerability | ||||
| CVE-2023-36770 | 1 Microsoft | 1 3d Builder | 2025-10-30 | 7.8 High |
| 3D Builder Remote Code Execution Vulnerability | ||||
| CVE-2023-36771 | 1 Microsoft | 1 3d Builder | 2025-10-30 | 7.8 High |
| 3D Builder Remote Code Execution Vulnerability | ||||
| CVE-2023-36772 | 1 Microsoft | 1 3d Builder | 2025-10-30 | 7.8 High |
| 3D Builder Remote Code Execution Vulnerability | ||||
| CVE-2023-36773 | 1 Microsoft | 1 3d Builder | 2025-10-30 | 7.8 High |
| 3D Builder Remote Code Execution Vulnerability | ||||
| CVE-2023-36788 | 1 Microsoft | 10 .net Framework, Windows 10 1809, Windows 10 21h2 and 7 more | 2025-10-30 | 7.8 High |
| .NET Framework Remote Code Execution Vulnerability | ||||
| CVE-2023-36792 | 1 Microsoft | 16 .net, .net Framework, Visual Studio 2017 and 13 more | 2025-10-30 | 7.8 High |
| Visual Studio Remote Code Execution Vulnerability | ||||