Export limit exceeded: 364165 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (364165 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-23205 1 Mz-automation 1 Lib60870 2025-03-12 5.5 Medium
An issue was discovered in lib60870 v2.3.2. There is a memory leak in lib60870/lib60870-C/examples/multi_client_server/multi_client_server.c.
CVE-2023-22427 1 Ss-proj 1 Shirasagi 2025-03-12 4.8 Medium
Stored cross-site scripting vulnerability in Theme switching function of SHIRASAGI v1.16.2 and earlier versions allows a remote attacker with an administrative privilege to inject an arbitrary script.
CVE-2023-22425 1 Ss-proj 1 Shirasagi 2025-03-12 5.4 Medium
Stored cross-site scripting vulnerability in Schedule function of SHIRASAGI v1.16.2 and earlier versions allows a remote authenticated attacker to inject an arbitrary script.
CVE-2023-0481 2 Quarkus, Redhat 2 Quarkus, Quarkus 2025-03-12 3.3 Low
In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user.
CVE-2023-0453 1 Apusthemes 1 Wp Private Messaging 2025-03-12 4.3 Medium
The WP Private Message WordPress plugin (bundled with the Superio theme as a required plugin) before 1.0.6 does not ensure that private messages to be accessed belong to the user making the requests. This allowing any authenticated users to access private messages belonging to other users by tampering the ID.
CVE-2023-0419 1 Smg-webdesign 1 Shortcode For Font Awesome 2025-03-12 5.4 Medium
The Shortcode for Font Awesome WordPress plugin before 1.4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
CVE-2023-0285 1 Devowl 1 Real Media Library 2025-03-12 5.4 Medium
The Real Media Library WordPress plugin before 4.18.29 does not sanitise and escape the created folder names, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks.
CVE-2022-4777 1 Bootstrap Shortcodes Project 1 Bootstrap Shortcodes 2025-03-12 5.4 Medium
The Bootstrap Shortcodes WordPress plugin through 3.4.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
CVE-2022-4754 1 Easy Social Box Project 1 Easy Social Box 2025-03-12 5.4 Medium
The Easy Social Box / Page Plugin WordPress plugin through 4.1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
CVE-2022-4386 1 Intuitive Custom Post Order Project 1 Intuitive Custom Post Order 2025-03-12 4.3 Medium
The Intuitive Custom Post Order WordPress plugin before 3.1.4 lacks CSRF protection in its update-menu-order ajax action, allowing an attacker to trick any user to change the menu order via a CSRF attack
CVE-2022-48345 1 Paypal 1 Braintree\/sanitize-url 2025-03-12 6.1 Medium
sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities.
CVE-2022-46440 1 Swftools 1 Swftools 2025-03-12 5.5 Medium
ttftool v0.9.2 was discovered to contain a segmentation violation via the readU16 function at ttf.c.
CVE-2022-44310 1 Ecdh Project 1 Ecdh 2025-03-12 7.5 High
In Development IL ecdh before 0.2.0, an attacker can send an invalid point (not on the curve) as the public key, and obtain the derived shared secret.
CVE-2021-35370 1 Txjia 1 Imcat 2025-03-12 9.8 Critical
An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function.
CVE-2021-34249 1 Online Book Store Project 1 Online Book Store 2025-03-12 7.5 High
SQL injection vulnerability in sourcecodester online-book-store 1.0 allows remote attackers to view sensitive information via the id paremeter in application URL.
CVE-2021-34167 1 Taogogo 1 Taocms 2025-03-12 8.8 High
Cross Site Request Forgery (CSRF) vulnerability in taoCMS 3.0.2 allows remote attackers to gain escalated privileges via taocms/admin/admin.php.
CVE-2021-33387 1 1234n 1 Minicms 2025-03-12 9.6 Critical
Cross Site Scripting Vulnerability in MiniCMS v.1.10 allows attacker to execute arbitrary code via a crafted get request.
CVE-2023-24575 1 Dell 1 Multifunction Printer E525w Driver And Software Suite 2025-03-12 7.8 High
Dell Multifunction Printer E525w Driver and Software Suite, versions prior to 1.047.2022, A05, contain a local privilege escalation vulnerability that could be exploited by malicious users to compromise the affected system
CVE-2021-4325 1 Nhncloud 1 Toast Ui Chart 2025-03-12 3.5 Low
A vulnerability, which was classified as problematic, has been found in NHN TOAST UI Chart 4.1.4. This issue affects some unknown processing of the component Legend Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 4.2.0 is able to address this issue. The identifier of the patch is 1a3f455d17df379e11b501bb5ba1dd1bcc41d63e. It is recommended to upgrade the affected component. The identifier VDB-221501 was assigned to this vulnerability.
CVE-2023-0067 1 Timed Content Project 1 Timed Content 2025-03-12 5.4 Medium
The Timed Content WordPress plugin before 2.73 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.