Export limit exceeded: 364165 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (364165 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-23205 | 1 Mz-automation | 1 Lib60870 | 2025-03-12 | 5.5 Medium |
| An issue was discovered in lib60870 v2.3.2. There is a memory leak in lib60870/lib60870-C/examples/multi_client_server/multi_client_server.c. | ||||
| CVE-2023-22427 | 1 Ss-proj | 1 Shirasagi | 2025-03-12 | 4.8 Medium |
| Stored cross-site scripting vulnerability in Theme switching function of SHIRASAGI v1.16.2 and earlier versions allows a remote attacker with an administrative privilege to inject an arbitrary script. | ||||
| CVE-2023-22425 | 1 Ss-proj | 1 Shirasagi | 2025-03-12 | 5.4 Medium |
| Stored cross-site scripting vulnerability in Schedule function of SHIRASAGI v1.16.2 and earlier versions allows a remote authenticated attacker to inject an arbitrary script. | ||||
| CVE-2023-0481 | 2 Quarkus, Redhat | 2 Quarkus, Quarkus | 2025-03-12 | 3.3 Low |
| In RestEasy Reactive implementation of Quarkus the insecure File.createTempFile() is used in the FileBodyHandler class which creates temp files with insecure permissions that could be read by a local user. | ||||
| CVE-2023-0453 | 1 Apusthemes | 1 Wp Private Messaging | 2025-03-12 | 4.3 Medium |
| The WP Private Message WordPress plugin (bundled with the Superio theme as a required plugin) before 1.0.6 does not ensure that private messages to be accessed belong to the user making the requests. This allowing any authenticated users to access private messages belonging to other users by tampering the ID. | ||||
| CVE-2023-0419 | 1 Smg-webdesign | 1 Shortcode For Font Awesome | 2025-03-12 | 5.4 Medium |
| The Shortcode for Font Awesome WordPress plugin before 1.4.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embedded, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | ||||
| CVE-2023-0285 | 1 Devowl | 1 Real Media Library | 2025-03-12 | 5.4 Medium |
| The Real Media Library WordPress plugin before 4.18.29 does not sanitise and escape the created folder names, which could allow users with the role of author and above to perform Stored Cross-Site Scripting attacks. | ||||
| CVE-2022-4777 | 1 Bootstrap Shortcodes Project | 1 Bootstrap Shortcodes | 2025-03-12 | 5.4 Medium |
| The Bootstrap Shortcodes WordPress plugin through 3.4.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | ||||
| CVE-2022-4754 | 1 Easy Social Box Project | 1 Easy Social Box | 2025-03-12 | 5.4 Medium |
| The Easy Social Box / Page Plugin WordPress plugin through 4.1.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks | ||||
| CVE-2022-4386 | 1 Intuitive Custom Post Order Project | 1 Intuitive Custom Post Order | 2025-03-12 | 4.3 Medium |
| The Intuitive Custom Post Order WordPress plugin before 3.1.4 lacks CSRF protection in its update-menu-order ajax action, allowing an attacker to trick any user to change the menu order via a CSRF attack | ||||
| CVE-2022-48345 | 1 Paypal | 1 Braintree\/sanitize-url | 2025-03-12 | 6.1 Medium |
| sanitize-url (aka @braintree/sanitize-url) before 6.0.2 allows XSS via HTML entities. | ||||
| CVE-2022-46440 | 1 Swftools | 1 Swftools | 2025-03-12 | 5.5 Medium |
| ttftool v0.9.2 was discovered to contain a segmentation violation via the readU16 function at ttf.c. | ||||
| CVE-2022-44310 | 1 Ecdh Project | 1 Ecdh | 2025-03-12 | 7.5 High |
| In Development IL ecdh before 0.2.0, an attacker can send an invalid point (not on the curve) as the public key, and obtain the derived shared secret. | ||||
| CVE-2021-35370 | 1 Txjia | 1 Imcat | 2025-03-12 | 9.8 Critical |
| An issue found in Peacexie Imcat v5.4 allows attackers to execute arbitrary code via the incomplete filtering function. | ||||
| CVE-2021-34249 | 1 Online Book Store Project | 1 Online Book Store | 2025-03-12 | 7.5 High |
| SQL injection vulnerability in sourcecodester online-book-store 1.0 allows remote attackers to view sensitive information via the id paremeter in application URL. | ||||
| CVE-2021-34167 | 1 Taogogo | 1 Taocms | 2025-03-12 | 8.8 High |
| Cross Site Request Forgery (CSRF) vulnerability in taoCMS 3.0.2 allows remote attackers to gain escalated privileges via taocms/admin/admin.php. | ||||
| CVE-2021-33387 | 1 1234n | 1 Minicms | 2025-03-12 | 9.6 Critical |
| Cross Site Scripting Vulnerability in MiniCMS v.1.10 allows attacker to execute arbitrary code via a crafted get request. | ||||
| CVE-2023-24575 | 1 Dell | 1 Multifunction Printer E525w Driver And Software Suite | 2025-03-12 | 7.8 High |
| Dell Multifunction Printer E525w Driver and Software Suite, versions prior to 1.047.2022, A05, contain a local privilege escalation vulnerability that could be exploited by malicious users to compromise the affected system | ||||
| CVE-2021-4325 | 1 Nhncloud | 1 Toast Ui Chart | 2025-03-12 | 3.5 Low |
| A vulnerability, which was classified as problematic, has been found in NHN TOAST UI Chart 4.1.4. This issue affects some unknown processing of the component Legend Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 4.2.0 is able to address this issue. The identifier of the patch is 1a3f455d17df379e11b501bb5ba1dd1bcc41d63e. It is recommended to upgrade the affected component. The identifier VDB-221501 was assigned to this vulnerability. | ||||
| CVE-2023-0067 | 1 Timed Content Project | 1 Timed Content | 2025-03-12 | 5.4 Medium |
| The Timed Content WordPress plugin before 2.73 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | ||||