Search

Search Results (359125 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-6045 1 Openatom 1 Openharmony 2024-11-21 5.9 Medium
in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through type confusion.
CVE-2023-6038 1 H2o 1 H2o 2024-11-21 7.5 High
A Local File Inclusion (LFI) vulnerability exists in the h2o-3 REST API, allowing unauthenticated remote attackers to read arbitrary files on the server with the permissions of the user running the h2o-3 instance. This issue affects the default installation and does not require user interaction. The vulnerability can be exploited by making specific GET or POST requests to the ImportFiles and ParseSetup endpoints, respectively. This issue was identified in version 3.40.0.4 of h2o-3.
CVE-2023-6035 1 Spider-themes 1 Eazydocs 2024-11-21 8.8 High
The EazyDocs WordPress plugin before 2.3.4 does not properly sanitize and escape "data" parameter before using it in an SQL statement via an AJAX action, which could allow any authenticated users, such as subscribers, to perform SQL Injection attacks.
CVE-2023-6032 1 Schneider-electric 4 Galaxy Vl, Galaxy Vl Firmware, Galaxy Vs and 1 more 2024-11-21 5.3 Medium
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause a file system enumeration and file download when an attacker navigates to the Network Management Card via HTTPS.
CVE-2023-6028 1 Br-automation 1 Automation Runtime 2024-11-21 6.1 Medium
A reflected cross-site scripting (XSS) vulnerability exists in the SVG version of System Diagnostics Manager of B&R Automation Runtime versions <= G4.93 that enables a remote attacker to execute arbitrary JavaScript code in the context of the attacked user’s browser session.
CVE-2023-6027 1 Elijaa 1 Phpmemcachedadmin 2024-11-21 6.1 Medium
A critical flaw has been identified in elijaa/phpmemcachedadmin affecting version 1.3.0, specifically related to a stored XSS vulnerability. This vulnerability allows malicious actors to insert a carefully crafted JavaScript payload. The issue arises from improper encoding of user-controlled entries in the "/pmcadmin/configure.php" parameter.
CVE-2023-6026 1 Elijaa 1 Phpmemcachedadmin 2024-11-21 9.8 Critical
A Path traversal vulnerability has been reported in elijaa/phpmemcachedadmin affecting version 1.3.0. This vulnerability allows an attacker to delete files stored on the server due to lack of proper verification of user-supplied input.
CVE-2023-6023 1 Vertaai 1 Modeldb 2024-11-21 7.5 High
An attacker can read any file on the filesystem on the server hosting ModelDB through an LFI in the artifact_path URL parameter.
CVE-2023-6022 1 Prefect 1 Prefect 2024-11-21 8.8 High
Cross-Site Request Forgery (CSRF) in GitHub repository prefecthq/prefect prior to 2.16.5.
CVE-2023-6020 1 Ray Project 1 Ray 2024-11-21 7.5 High
LFI in Ray's /static/ directory allows attackers to read any file on the server without authentication.
CVE-2023-6018 1 Lfprojects 1 Mlflow 2024-11-21 9.8 Critical
An attacker can overwrite any file on the server hosting MLflow without any authentication.
CVE-2023-6017 1 H2o 1 H2o 2024-11-21 7.1 High
H2O included a reference to an S3 bucket that no longer existed allowing an attacker to take over the S3 bucket URL.
CVE-2023-6016 1 H2o 1 H2o 2024-11-21 9.8 Critical
An attacker is able to gain remote code execution on a server hosting the H2O dashboard through it's POJO model import feature.
CVE-2023-6015 1 Lfprojects 1 Mlflow 2024-11-21 7.5 High
MLflow allowed arbitrary files to be PUT onto the server.
CVE-2023-6014 1 Lfprojects 1 Mlflow 2024-11-21 9.8 Critical
An attacker is able to arbitrarily create an account in MLflow bypassing any authentication requirment.
CVE-2023-6012 1 Lanaccess 1 Onsafe Monitorhm 2024-11-21 8.3 High
An improper input validation vulnerability has been found in Lanaccess ONSAFE MonitorHM affecting version 3.7.0. This vulnerability could lead a remote attacker to exploit the checkbox element and perform remote code execution, compromising the entire infrastructure.
CVE-2023-6002 1 Yugabyte 1 Yugabytedb 2024-11-21 6.5 Medium
YugabyteDB is vulnerable to cross site scripting (XSS) via log injection. Writing invalidated user input to log files can allow an unprivileged attacker to forge log entries or inject malicious content into the logs.
CVE-2023-6001 1 Yugabyte 1 Yugabytedb 2024-11-21 5.3 Medium
Prometheus metrics are available without authentication. These expose detailed and sensitive information about the YugabyteDB Anywhere environment.
CVE-2023-5998 1 Gpac 1 Gpac 2024-11-21 7.5 High
Out-of-bounds Read in GitHub repository gpac/gpac prior to 2.3.0-DEV.
CVE-2023-5993 2 Microsoft, Thalesgroup 2 Windows, Safenet Authentication Client 2024-11-21 7.8 High
A flaw in the Windows Installer in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to escalate their privilege level via local access.