Export limit exceeded: 360313 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (360313 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-27211 | 1 Online Pizza Ordering System Project | 1 Online Pizza Ordering System | 2025-02-28 | 6.1 Medium |
| A cross-site scripting (XSS) vulnerability in /admin/navbar.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the page parameter. | ||||
| CVE-2023-27212 | 1 Online Pizza Ordering System Project | 1 Online Pizza Ordering System | 2025-02-28 | 6.1 Medium |
| A cross-site scripting (XSS) vulnerability in /php-opos/signup.php of Online Pizza Ordering System 1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the redirect parameter. | ||||
| CVE-2023-27213 | 1 Online Student Management System Project | 1 Online Student Management System | 2025-02-28 | 9.8 Critical |
| Online Student Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /eduauth/student/search.php. | ||||
| CVE-2023-27850 | 1 Netgear | 2 Rax30, Rax30 Firmware | 2025-02-28 | 6.8 Medium |
| NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a file sharing mechanism that allows users with access to this feature to access arbitrary files on the device. | ||||
| CVE-2023-27115 | 1 Webassembly | 1 Webassembly | 2025-02-28 | 5.5 Medium |
| WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::cat_compute_size. | ||||
| CVE-2023-27114 | 1 Radare | 1 Radare2 | 2025-02-28 | 5.5 Medium |
| radare2 v5.8.3 was discovered to contain a segmentation fault via the component wasm_dis at p/wasm/wasm.c. | ||||
| CVE-2023-26948 | 1 Onekeyadmin | 1 Onekeyadmin | 2025-02-28 | 7.5 High |
| onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/file/download. | ||||
| CVE-2023-1205 | 1 Netgear | 2 Rax30, Rax30 Firmware | 2025-02-28 | 8.8 High |
| NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 is vulnerable to cross-site request forgery attacks on all endpoints due to improperly implemented CSRF protections. | ||||
| CVE-2023-27214 | 1 Online Student Management System Project | 1 Online Student Management System | 2025-02-28 | 9.8 Critical |
| Online Student Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the fromdate and todate parameters at /eduauth/student/between-date-reprtsdetails.php. | ||||
| CVE-2023-1291 | 1 Sales Tracker Management System Project | 1 Sales Tracker Management System | 2025-02-28 | 6.3 Medium |
| A vulnerability, which was classified as critical, was found in SourceCodester Sales Tracker Management System 1.0. This affects an unknown part of the file admin/clients/manage_client.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-222645 was assigned to this vulnerability. | ||||
| CVE-2023-1287 | 1 3ds | 1 Enovia Live Collaboration | 2025-02-28 | 9 Critical |
| An XSL template vulnerability in ENOVIA Live Collaboration V6R2013xE allows Remote Code Execution. | ||||
| CVE-2021-33360 | 1 Stoqey | 1 Gnuplot | 2025-02-28 | 9.8 Critical |
| An issue found in Stoqey gnuplot v.0.0.3 and earlier allows attackers to execute arbitrary code via the src/index.ts, plotCallack, child_process, and/or filePath parameter(s). | ||||
| CVE-2022-44574 | 1 Ivanti | 1 Avalanche | 2025-02-28 | 7.5 High |
| An improper authentication vulnerability exists in Avalanche version 6.3.x and below allows unauthenticated attacker to modify properties on specific port. | ||||
| CVE-2023-1307 | 1 Froxlor | 1 Froxlor | 2025-02-28 | 9.8 Critical |
| Authentication Bypass by Primary Weakness in GitHub repository froxlor/froxlor prior to 2.0.13. | ||||
| CVE-2025-1673 | 1 Zephyrproject | 1 Zephyr | 2025-02-28 | 8.2 High |
| A malicious or malformed DNS packet without a payload can cause an out-of-bounds read, resulting in a crash (denial of service) or an incorrect computation. | ||||
| CVE-2023-23911 | 1 Rocket.chat | 1 Rocket.chat | 2025-02-28 | 7.5 High |
| An improper access control vulnerability exists prior to v6 that could allow an attacker to break the E2E encryption of a chat room by a user changing the group key of a chat room. | ||||
| CVE-2025-1674 | 1 Zephyrproject | 1 Zephyr | 2025-02-28 | 8.2 High |
| A lack of input validation allows for out of bounds reads caused by malicious or malformed packets. | ||||
| CVE-2023-27116 | 1 Webassembly | 1 Webassembly | 2025-02-28 | 5.5 Medium |
| WebAssembly v1.0.29 discovered to contain an abort in CWriter::MangleType. | ||||
| CVE-2023-27117 | 1 Webassembly | 1 Webassembly | 2025-02-28 | 7.8 High |
| WebAssembly v1.0.29 was discovered to contain a heap overflow via the component component wabt::Node::operator. | ||||
| CVE-2023-27164 | 1 Halo | 1 Halo | 2025-02-28 | 4.8 Medium |
| An arbitrary file upload vulnerability in Halo up to v1.6.1 allows attackers to execute arbitrary code via a crafted .md file. | ||||