Search

Search Results (360494 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-46943 1 Evershop 1 Evershop 2024-11-21 9.1 Critical
An issue was discovered in NPM's package @evershop/evershop before version 1.0.0-rc.8. The HMAC secret used for generating tokens is hardcoded as "secret". A weak HMAC secret poses a risk because attackers can use the predictable secret to create valid JSON Web Tokens (JWTs), allowing them access to important information and actions within the application.
CVE-2023-46935 1 Eyoucms 1 Eyoucms 2024-11-21 5.4 Medium
eyoucms v1.6.4 is vulnerable Cross Site Scripting (XSS), which can lead to stealing sensitive information of logged-in users.
CVE-2023-46931 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
GPAC 2.3-DEV-rev605-gfc9e29089-master contains a heap-buffer-overflow in ffdmx_parse_side_data /afltest/gpac/src/filters/ff_dmx.c:202:14 in gpac/MP4Box.
CVE-2023-46930 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
GPAC 2.3-DEV-rev605-gfc9e29089-master contains a SEGV in gpac/MP4Box in gf_isom_find_od_id_for_track /afltest/gpac/src/isomedia/media_odf.c:522:14.
CVE-2023-46928 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
GPAC 2.3-DEV-rev605-gfc9e29089-master contains a SEGV in gpac/MP4Box in gf_media_change_pl /afltest/gpac/src/media_tools/isom_tools.c:3293:42.
CVE-2023-46927 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
GPAC 2.3-DEV-rev605-gfc9e29089-master contains a heap-buffer-overflow in gf_isom_use_compact_size gpac/src/isomedia/isom_write.c:3403:3 in gpac/MP4Box.
CVE-2023-46925 1 Reportico 1 Reportico 2024-11-21 4.8 Medium
Reportico 7.1.21 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-46918 1 Fedirtsapana 1 Simple Http Server Plus 2024-11-21 4.6 Medium
Phlox com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus has an Android manifest file that contains an entry with the android:allowBackup attribute set to true. This could be leveraged by an attacker with physical access to the device.
CVE-2023-46916 1 Maximawatches 2 Maxima Max Pro Power, Maxima Max Pro Power Firmware 2024-11-21 4.3 Medium
Maxima Max Pro Power 1.0 486A devices allow BLE traffic replay. An attacker can use GATT characteristic handle 0x0012 to perform potentially disruptive actions such as starting a Heart Rate monitor.
CVE-2023-46914 1 Bookingcalendar Project 1 Bookingcalendar 2024-11-21 9.8 Critical
SQL Injection vulnerability in RM bookingcalendar module for PrestaShop versions 2.7.9 and before, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via ics_export.php.
CVE-2023-46911 1 Jspxcms 1 Jspxcms 2024-11-21 6.1 Medium
There is a Cross Site Scripting (XSS) vulnerability in the choose_style_tree.do interface of Jspxcms v10.2.0 backend.
CVE-2023-46894 1 Espressif 1 Esptool 2024-11-21 7.5 High
An issue discovered in esptool 4.6.2 allows attackers to view sensitive information via weak cryptographic algorithm.
CVE-2023-46871 1 Gpac 1 Gpac 2024-11-21 5.3 Medium
GPAC version 2.3-DEV-rev602-ged8424300-master in MP4Box contains a memory leak in NewSFDouble scenegraph/vrml_tools.c:300. This vulnerability may lead to a denial of service.
CVE-2023-46867 1 Color 1 Demoiccmax 2024-11-21 6.5 Medium
In International Color Consortium DemoIccMAX 79ecb74, CIccXformMatrixTRC::GetCurve in IccCmm.cpp in libSampleICC.a has a NULL pointer dereference.
CVE-2023-46866 1 Color 1 Demoiccmax 2024-11-21 6.5 Medium
In International Color Consortium DemoIccMAX 79ecb74, CIccCLUT::Interp3d in IccProfLib/IccTagLut.cpp in libSampleICC.a attempts to access array elements at out-of-bounds indexes.
CVE-2023-46865 1 Craterapp 1 Crater 2024-11-21 7.2 High
/api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an image/png IDAT chunk of a Company Logo image.
CVE-2023-46864 1 Peppermint 1 Peppermint 2024-11-21 5.3 Medium
Peppermint Ticket Management through 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/ticket/1/file/download?filepath=../ POST request.
CVE-2023-46863 1 Peppermint 1 Peppermint 2024-11-21 7.5 High
Peppermint Ticket Management before 0.2.4 allows remote attackers to read arbitrary files via a /api/v1/users/file/download?filepath=./../ POST request.
CVE-2023-46862 2 Linux, Redhat 2 Linux Kernel, Enterprise Linux 2024-11-21 4.7 Medium
An issue was discovered in the Linux kernel through 6.5.9. During a race with SQ thread exit, an io_uring/fdinfo.c io_uring_show_fdinfo NULL pointer dereference can occur.
CVE-2023-46858 1 Moodle 1 Moodle 2024-11-21 5.4 Medium
Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their courses ... admins and teachers can post XSS-capable content, but students can not."