Export limit exceeded: 331534 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (331565 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-25934 | 1 Dell | 1 Elastic Cloud Storage | 2025-01-29 | 5.9 Medium |
| DELL ECS prior to 3.8.0.2 contains an improper verification of cryptographic signature vulnerability. A network attacker with an ability to intercept the request could potentially exploit this vulnerability to modify the body data of the request. | ||||
| CVE-2023-24958 | 1 Ibm | 6 3948-ved, 3948-ved Firmware, 3957-vec and 3 more | 2025-01-29 | 8.8 High |
| A vulnerability in the IBM TS7700 Management Interface 8.51.2.12, 8.52.200.111, 8.52.102.13, and 8.53.0.63 could allow an authenticated user to submit a specially crafted URL leading to privilege escalation and remote code execution. IBM X-Force ID: 246320. | ||||
| CVE-2023-23470 | 1 Ibm | 1 I | 2025-01-29 | 6.4 Medium |
| IBM i 7.2, 7.3, 7.4, and 7.5 could allow an authenticated privileged administrator to gain elevated privileges in non-default configurations, as a result of improper SQL processing. By using a specially crafted SQL operation, the administrator could exploit the vulnerability to perform additional administrator operations. IBM X-Force ID: 244510. | ||||
| CVE-2023-22651 | 1 Suse | 1 Rancher | 2025-01-29 | 9.9 Critical |
| Improper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admission Webhook may lead to the misconfiguration of the Webhook. This component enforces validation rules and security checks before resources are admitted into the Kubernetes cluster. The issue only affects users that upgrade from 2.6.x or 2.7.x to 2.7.2. Users that did a fresh install of 2.7.2 (and did not follow an upgrade path) are not affected. | ||||
| CVE-2023-21404 | 1 Axis | 1 Axis Os | 2025-01-29 | 4.1 Medium |
| AXIS OS 11.0.X - 11.3.x use a static RSA key in legacy LUA-components to protect Axis-specific source code. The static RSA key is not used in any other secure communication nor can it be used to compromise the device or any customer data. | ||||
| CVE-2023-1094 | 1 Monicahq | 1 Monica | 2025-01-29 | 8 High |
| MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/food` endpoint and food parameter. | ||||
| CVE-2022-48239 | 2 Google, Unisoc | 14 Android, S8000, Sc7731e and 11 more | 2025-01-29 | 4.4 Medium |
| In camera driver, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. | ||||
| CVE-2022-46720 | 1 Apple | 3 Ipados, Iphone Os, Macos | 2025-01-29 | 8.6 High |
| An integer overflow was addressed with improved input validation. This issue is fixed in iOS 16.2 and iPadOS 16.2, macOS Ventura 13.1. An app may be able to break out of its sandbox | ||||
| CVE-2022-32885 | 2 Apple, Redhat | 10 Ipados, Iphone Os, Macos and 7 more | 2025-01-29 | 8.8 High |
| A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing maliciously crafted web content may lead to arbitrary code execution | ||||
| CVE-2021-28999 | 1 Cmsmadesimple | 1 Cms Made Simple | 2025-01-29 | 8.8 High |
| SQL Injection vulnerability in CMS Made Simple through 2.2.15 allows remote attackers to execute arbitrary commands via the m1_sortby parameter to modules/News/function.admin_articlestab.php. | ||||
| CVE-2021-27280 | 1 Mblog Project | 1 Mblog | 2025-01-29 | 7.8 High |
| OS Command injection vulnerability in mblog 3.5.0 allows attackers to execute arbitrary code via crafted theme when it gets selected. | ||||
| CVE-2020-4914 | 1 Ibm | 1 Cloud Pak System | 2025-01-29 | 4.2 Medium |
| IBM Cloud Pak System Suite 2.3.3.0 through 2.3.3.5 does not invalidate session after logout which could allow a local user to impersonate another user on the system. IBM X-Force ID: 191290. | ||||
| CVE-2020-22755 | 1 Mingsoft | 1 Mcms | 2025-01-29 | 8.8 High |
| File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vulnerability than CVE-2022-31943. | ||||
| CVE-2020-22334 | 1 Beescms | 1 Beescms | 2025-01-29 | 6.5 Medium |
| Cross Site Request Forgery (CSRF) vulnerability in beescms v4 allows attackers to delete the administrator account via crafted request to /admin/admin_admin.php. | ||||
| CVE-2020-19660 | 1 Ipandao | 1 Editor.md | 2025-01-29 | 6.1 Medium |
| Cross Site Scripting (XSS) pandao editor.md 1.5.0 allows attackers to execute arbitrary code via crafted linked url values. | ||||
| CVE-2020-18282 | 1 5none | 1 Nonecms | 2025-01-29 | 6.1 Medium |
| Cross-site scripting (XSS) vulnerability in NoneCms 1.3.0 allows remote attackers to inject arbitrary web script or HTML via feedback feature. | ||||
| CVE-2020-18132 | 1 Mipcms | 1 Mipcms | 2025-01-29 | 4.8 Medium |
| Cross Site Scripting (XSS) vulnerability in MIPCMS 3.6.0 allows attackers to execute arbitrary code via the category name field to categoryEdit. | ||||
| CVE-2020-18131 | 1 Clanscripts Project | 1 Clanscripts | 2025-01-29 | 8.8 High |
| Cross Site Request Forgery (CSRF) vulnerability in Bluethrust Clan Scripts v4 allows attackers to escilate privledges to an arbitrary account via a crafted request to /members/console.php?cID=5. | ||||
| CVE-2023-2566 | 1 Open-emr | 1 Openemr | 2025-01-29 | 4.8 Medium |
| Cross-site Scripting (XSS) - Stored in GitHub repository openemr/openemr prior to 7.0.1. | ||||
| CVE-2022-38707 | 1 Ibm | 1 Cognos Command Center | 2025-01-29 | 4 Medium |
| IBM Cognos Command Center 10.2.4.1 could allow a local attacker to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 234179. | ||||