Export limit exceeded: 359089 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 359089 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (359089 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-33795 | 1 Netbox | 1 Netbox | 2024-11-27 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability in the Create Contact Roles (/tenancy/contact-roles/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field. | ||||
| CVE-2023-35042 | 1 Geoserver | 1 Geoserver | 2024-11-27 | 9.8 Critical |
| GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData within a wps:Execute request, as exploited in the wild in June 2023. NOTE: the vendor states that they are unable to reproduce this in any version. | ||||
| CVE-2023-33592 | 1 Oretnom23 | 1 Lost And Found Information System | 2024-11-27 | 9.8 Critical |
| Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=system_info/contact_information. | ||||
| CVE-2023-33661 | 1 Churchcrm | 1 Churchcrm | 2024-11-27 | 6.1 Medium |
| Multiple cross-site scripting (XSS) vulnerabilities were discovered in Church CRM v4.5.3 in GroupReports.php via GroupRole, ReportModel, and OnlyCart parameters. | ||||
| CVE-2023-34647 | 1 Phpgurukul | 1 Hostel Management System | 2024-11-27 | 6.1 Medium |
| PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS). | ||||
| CVE-2023-34833 | 1 Thinkadmin | 1 Thinkadmin | 2024-11-27 | 6.1 Medium |
| An arbitrary file upload vulnerability in the component /api/upload.php of ThinkAdmin v6 allows attackers to execute arbitrary code via a crafted file. | ||||
| CVE-2023-34650 | 1 Small Crm Project | 1 Small Crm | 2024-11-27 | 6.1 Medium |
| PHPgurukl Small CRM v.1.0 is vulnerable to Cross Site Scripting (XSS). | ||||
| CVE-2023-34651 | 1 Hospital Management System Project | 1 Hospital Management System | 2024-11-27 | 6.1 Medium |
| PHPgurukl Hospital Management System v.1.0 is vulnerable to Cross Site Scripting (XSS). | ||||
| CVE-2023-34652 | 1 Phpgurukul | 1 Hostel Management System | 2024-11-27 | 6.1 Medium |
| PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS) via Add New Course. | ||||
| CVE-2023-23163 | 1 Phpgurukul | 1 Art Gallery Management System | 2024-11-27 | 9.8 Critical |
| Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter. | ||||
| CVE-2022-48328 | 1 Misp-project | 1 Misp | 2024-11-27 | 9.8 Critical |
| app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters. | ||||
| CVE-2023-34738 | 1 Chemex | 1 Chemex | 2024-11-27 | 9.8 Critical |
| Chemex through 3.7.1 is vulnerable to arbitrary file upload. | ||||
| CVE-2022-46395 | 1 Arm | 4 Avalon Gpu Kernel Driver, Bifrost Gpu Kernel Driver, Midgard Gpu Kernel Driver and 1 more | 2024-11-27 | 8.8 High |
| An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Midgard r0p0 through r32p0, Bifrost r0p0 through r41p0 before r42p0, Valhall r19p0 through r41p0 before r42p0, and Avalon r41p0 before r42p0. | ||||
| CVE-2023-24734 | 1 Sigb | 1 Pmb | 2024-11-27 | 9.8 Critical |
| An arbitrary file upload vulnerability in the camera_upload.php component of PMB v7.4.6 allows attackers to execute arbitrary code via a crafted image file. | ||||
| CVE-2023-25304 | 1 Prismlauncher | 1 Prism Launcher | 2024-11-27 | 7.8 High |
| An issue in Prism Launcher up to v6.1 allows attackers to perform a directory traversal via importing a crafted .mrpack file. | ||||
| CVE-2023-34843 | 1 Traggo | 1 Traggo | 2024-11-27 | 7.5 High |
| Traggo Server 0.3.0 is vulnerable to directory traversal via a crafted GET request. | ||||
| CVE-2022-27665 | 1 Progress | 1 Ws Ftp Server | 2024-11-27 | 6.1 Medium |
| Reflected XSS (via AngularJS sandbox escape expressions) exists in Progress Ipswitch WS_FTP Server 8.6.0. This can lead to execution of malicious code and commands on the client due to improper handling of user-provided input. By inputting malicious payloads in the subdirectory searchbar or Add folder filename boxes, it is possible to execute client-side commands. For example, there is Client-Side Template Injection via subFolderPath to the ThinClient/WtmApiService.asmx/GetFileSubTree URI. | ||||
| CVE-2023-32623 | 1 2inc | 1 Snow Monkey Forms | 2024-11-27 | 9.1 Critical |
| Directory traversal vulnerability in Snow Monkey Forms v5.1.1 and earlier allows a remote unauthenticated attacker to delete arbitrary files on the server. | ||||
| CVE-2023-26134 | 1 Git-commit-info Project | 1 Git-commit-info | 2024-11-27 | 9.8 Critical |
| Versions of the package git-commit-info before 2.0.2 are vulnerable to Command Injection such that the package-exported method gitCommitInfo () fails to sanitize its parameter commit, which later flows into a sensitive command execution API. As a result, attackers may inject malicious commands once they control the hash content. | ||||
| CVE-2023-36475 | 1 Parseplatform | 1 Parse-server | 2024-11-27 | 9.8 Critical |
| Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 5.5.2 and 6.2.1, an attacker can use a prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser. A patch is available in versions 5.5.2 and 6.2.1. | ||||