Export limit exceeded: 368042 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (368042 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-0587 | 1 Trendmicro | 1 Apex One | 2025-03-27 | 9.1 Critical |
| A file upload vulnerability in exists in Trend Micro Apex One server build 11110. Using a malformed Content-Length header in an HTTP PUT message sent to URL /officescan/console/html/cgi/fcgiOfcDDA.exe, an unauthenticated remote attacker can upload arbitrary files to the SampleSubmission directory (i.e., \PCCSRV\TEMP\SampleSubmission) on the server. The attacker can upload a large number of large files to fill up the file system on which the Apex One server is installed. | ||||
| CVE-2023-0524 | 1 Tenable | 3 Nessus, Tenable.io, Tenable.sc | 2025-03-27 | 8.8 High |
| As part of our Security Development Lifecycle, a potential privilege escalation issue was identified internally. This could allow a malicious actor with sufficient permissions to modify environment variables and abuse an impacted plugin in order to escalate privileges. We have resolved the issue and also made several defense-in-depth fixes alongside. While the probability of successful exploitation is low, Tenable is committed to securing our customers’ environments and our products. The updates have been distributed via the Tenable plugin feed in feed serial numbers equal to or greater than #202212212055. | ||||
| CVE-2023-0454 | 1 Orangescrum | 1 Orangescrum | 2025-03-27 | 8.1 High |
| OrangeScrum version 2.0.11 allows an authenticated external attacker to delete arbitrary local files from the server. This is possible because the application uses an unsanitized attacker-controlled parameter to construct an internal path. | ||||
| CVE-2022-4898 | 1 Octopus | 1 Octopus Server | 2025-03-27 | 5.4 Medium |
| In affected versions of Octopus Server the help sidebar can be customized to include a Cross-Site Scripting payload in the support link. This was initially resolved in advisory 2022-07 however it was identified that the fix could be bypassed in certain circumstances. A different approach was taken to prevent the possibility of the support link being susceptible to XSS | ||||
| CVE-2022-4254 | 2 Fedoraproject, Redhat | 16 Sssd, Enterprise Linux, Enterprise Linux Desktop and 13 more | 2025-03-27 | 8.8 High |
| sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters | ||||
| CVE-2022-4206 | 1 Gitlab | 1 Dast Api Scanner | 2025-03-27 | 5 Medium |
| A sensitive information leak issue has been discovered in all versions of DAST API scanner from 1.6.50 prior to 2.0.102, exposing the Authorization header in the vulnerability report | ||||
| CVE-2022-48624 | 2 Greenwoodsoftware, Redhat | 4 Less, Enterprise Linux, Logging and 1 more | 2025-03-27 | 7.8 High |
| close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE. | ||||
| CVE-2022-48161 | 1 Easy Images Project | 1 Easy Images | 2025-03-27 | 7.5 High |
| Easy Images v2.0 was discovered to contain an arbitrary file download vulnerability via the component /application/down.php. This vulnerability is exploited via a crafted GET request. | ||||
| CVE-2022-48094 | 1 Lmxcms | 1 Lmxcms | 2025-03-27 | 4.9 Medium |
| lmxcms v1.41 was discovered to contain an arbitrary file read vulnerability via TemplateAction.class.php. | ||||
| CVE-2022-48093 | 1 Seacms | 1 Seacms | 2025-03-27 | 7.2 High |
| Seacms v12.7 was discovered to contain a remote code execution (RCE) vulnerability via the ip parameter at admin_ ip.php. | ||||
| CVE-2022-47873 | 1 Netcad | 1 Keos | 2025-03-27 | 9.8 Critical |
| Netcad KEOS 1.0 is vulnerable to XML External Entity (XXE) resulting in SSRF with XXE (remote). | ||||
| CVE-2022-47780 | 1 Bangresto Project | 1 Bangresto | 2025-03-27 | 9.8 Critical |
| SQL Injection vulnerability in Bangresto 1.0 via the itemID parameter. | ||||
| CVE-2022-47768 | 1 Serinf | 1 Fast Checkin | 2025-03-27 | 7.5 High |
| Serenissima Informatica Fast Checkin 1.0 is vulnerable to Directory Traversal. | ||||
| CVE-2022-47717 | 1 Lastyard | 1 Last Yard | 2025-03-27 | 7.5 High |
| Last Yard 22.09.8-1 is vulnerable to Cross-origin resource sharing (CORS). | ||||
| CVE-2022-47715 | 1 Lastyard | 1 Last Yard | 2025-03-27 | 5.3 Medium |
| In Last Yard 22.09.8-1, the cookie can be stolen via via unencrypted traffic. | ||||
| CVE-2022-47714 | 1 Lastyard | 1 Last Yard | 2025-03-27 | 9.8 Critical |
| Last Yard 22.09.8-1 does not enforce HSTS headers | ||||
| CVE-2022-47701 | 1 Comfast Project | 2 Cf-wr623n, Cf-wr623n Firmware | 2025-03-27 | 6.1 Medium |
| COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 is vulnerable to Cross Site Scripting (XSS). | ||||
| CVE-2022-47700 | 1 Comfast Project | 2 Cf-wr623n, Cf-wr623n Firmware | 2025-03-27 | 7.5 High |
| COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 and before is vulnerable to Incorrect Access Control. Improper authentication allows requests to be made to back-end scripts without a valid session or authentication. | ||||
| CVE-2022-47699 | 1 Comfast Project | 2 Cf-wr623n, Cf-wr623n Firmware | 2025-03-27 | 9.8 Critical |
| COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd) CF-WR623N Router firmware V2.3.0.1 is vulnerable to Incorrect Access Control. | ||||
| CVE-2022-47003 | 1 Murasoftware | 1 Mura Cms | 2025-03-27 | 9.8 Critical |
| A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request. | ||||