Export limit exceeded: 360011 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (360011 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2019-20171 2 Debian, Gpac 2 Debian Linux, Gpac 2025-03-04 5.5 Medium
An issue was discovered in GPAC version 0.5.2 and 0.9.0-development-20191109. There are memory leaks in metx_New in isomedia/box_code_base.c and abst_Read in isomedia/box_code_adobe.c.
CVE-2023-35017 1 Ibm 1 Security Verify Governance 2025-03-04 5.9 Medium
IBM Security Verify Governance 10.0.2 Identity Manager can transmit user credentials in clear text that could be obtained by an attacker using man in the middle techniques.
CVE-2023-33838 1 Ibm 1 Security Verify Governance 2025-03-04 4.4 Medium
IBM Security Verify Governance 10.0.2 Identity Manager uses a one-way cryptographic hash against an input that should not be reversible, such as a password, but the product does not also use a salt as part of the input.
CVE-2024-24581 1 Openatom 1 Openharmony 2025-03-04 6.5 Medium
in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution through out-of-bounds write.
CVE-2023-37412 1 Ibm 1 Aspera Faspex 2025-03-04 4.4 Medium
IBM Aspera Faspex 5.0.0 through 5.0.10 could allow a privileged user to make system changes without proper access controls.
CVE-2023-37413 1 Ibm 1 Aspera Faspex 2025-03-04 5.3 Medium
IBM Aspera Faspex 5.0.0 through 5.0.10 could disclose sensitive username information due to an observable response discrepancy.
CVE-2023-50309 1 Ibm 1 Sterling B2b Integrator 2025-03-04 6.4 Medium
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVE-2023-32340 1 Ibm 1 Sterling B2b Integrator 2025-03-04 4.6 Medium
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
CVE-2023-1410 2 Grafana, Redhat 2 Grafana, Ceph Storage 2025-03-04 6.2 Medium
Grafana is an open-source platform for monitoring and observability.  Grafana had a stored XSS vulnerability in the Graphite FunctionDescription tooltip. The stored XSS vulnerability was possible due the value of the Function Description was not properly sanitized. An attacker needs to have control over the Graphite data source in order to manipulate a function description and a Grafana admin needs to configure the data source, later a Grafana user needs to select a tampered function and hover over the description.  Users may upgrade to version 8.5.22, 9.2.15 and 9.3.11 to receive a fix.
CVE-2023-22436 1 Openatom 1 Openharmony 2025-03-04 7.8 High
The kernel subsystem function check_permission_for_set_tokenid within OpenHarmony-v3.1.5 and prior versions has an UAF vulnerability which local attackers can exploit this vulnerability to escalate the privilege to root.
CVE-2023-24465 1 Openatom 1 Openharmony 2025-03-04 5.5 Medium
Communication Wi-Fi subsystem within OpenHarmony-v3.1.4 and prior versions, OpenHarmony-v3.0.7 and prior versions has a null pointer reference vulnerability which local attackers can exploit this vulnerability to cause the current application to crash.
CVE-2023-22892 1 Smartbear 1 Zephyr Enterprise 2025-03-04 7.5 High
There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticated users to read arbitrary files from Zephyr instances.
CVE-2022-48365 1 Ibexa 3 Digital Experience Platform, Ez Platform, Ez Platform Kernel 2025-03-04 7.2 High
An issue was discovered in eZ Platform Ibexa Kernel before 1.3.26. The Company admin role gives excessive privileges.
CVE-2021-33639 1 Openatom 1 Openeuler Kernel 2025-03-04 7.5 High
REMAP cmd of SVM driver can be used to remap read only memory as read-write, then cause read only memory/file modified.
CVE-2025-24865 1 Myscada 1 Mypro 2025-03-04 10 Critical
The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password.
CVE-2025-23411 1 Myscada 1 Mypro 2025-03-04 6.3 Medium
mySCADA myPRO Manager is vulnerable to cross-site request forgery (CSRF), which could allow an attacker to obtain sensitive information. An attacker would need to trick the victim in to visiting an attacker-controlled website.
CVE-2025-22896 1 Myscada 1 Mypro 2025-03-04 8.6 High
mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information.
CVE-2025-27146 1 Matrix 1 Matrix Irc Bridge 2025-03-04 2.7 Low
matrix-appservice-irc is a Node.js IRC bridge for Matrix. The matrix-appservice-irc bridge up to version 3.0.3 contains a vulnerability which can lead to arbitrary IRC command execution as the puppeted user. The attacker can only inject commands executed as their own IRC user. The vulnerability has been patched in matrix-appservice-irc version 3.0.4.
CVE-2024-45426 1 Zoom 6 Meeting Software Development Kit, Rooms, Rooms Controller and 3 more 2025-03-04 4.9 Medium
Incorrect ownership assignment in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.
CVE-2023-26953 1 Onekeyadmin 1 Onekeyadmin 2025-03-04 4.8 Medium
onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Administrator module.