Export limit exceeded: 365159 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (365159 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-4967 1 Citrix 2 Netscaler Application Delivery Controller, Netscaler Gateway 2025-02-27 8.2 High
Denial of Service in NetScaler ADC and NetScaler Gateway when configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA Virtual Server
CVE-2023-46290 1 Rockwellautomation 1 Factorytalk Services Platform 2025-02-27 8.1 High
Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTalk® Services Platform web service and then use the token to log in into FactoryTalk® Services Platform . This vulnerability can only be exploited if the authorized user did not previously log in into the FactoryTalk® Services Platform web service.
CVE-2023-46289 1 Rockwellautomation 1 Factorytalk View 2025-02-27 7.5 High
Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious data bringing the product offline. If exploited, the product would become unavailable and require a restart to recover resulting in a denial-of-service condition.
CVE-2023-5867 1 Phpmyfaq 1 Phpmyfaq 2025-02-27 5.4 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.2.2.
CVE-2023-5873 1 Pimcore 1 Pimcore 2025-02-27 5.4 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository pimcore/pimcore prior to 11.1.0.
CVE-2023-3676 3 Kubernetes, Microsoft, Redhat 3 Kubernetes, Windows, Openshift 2025-02-27 8.8 High
A security issue was discovered in Kubernetes where a user that can create pods on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they include Windows nodes.
CVE-2023-5890 1 Sfu 1 Pkp Web Application Library 2025-02-27 5.4 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
CVE-2023-5893 1 Sfu 1 Pkp Web Application Library 2025-02-27 8.8 High
Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
CVE-2023-5892 1 Sfu 1 Pkp Web Application Library 2025-02-27 5.4 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
CVE-2023-5891 1 Sfu 1 Pkp Web Application Library 2025-02-27 5.4 Medium
Cross-site Scripting (XSS) - Reflected in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
CVE-2023-5894 1 Sfu 1 Open Journal Systems 2025-02-27 5.4 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository pkp/ojs prior to 3.3.0-16.
CVE-2023-5895 1 Sfu 1 Pkp Web Application Library 2025-02-27 5.4 Medium
Cross-site Scripting (XSS) - DOM in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
CVE-2023-5899 1 Pkp 1 Pkp Web Application Library 2025-02-27 8.8 High
Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
CVE-2023-5896 1 Sfu 1 Pkp Web Application Library 2025-02-27 5.4 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.4.0-4.
CVE-2023-5902 1 Sfu 1 Pkp Web Application Library 2025-02-27 4.3 Medium
Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
CVE-2023-5898 1 Pkp 1 Pkp Web Application Library 2025-02-27 8.8 High
Cross-Site Request Forgery (CSRF) in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
CVE-2023-5897 1 Sfu 1 Customlocale 2025-02-27 8.8 High
Cross-Site Request Forgery (CSRF) in GitHub repository pkp/customLocale prior to 1.2.0-1.
CVE-2023-5903 1 Sfu 1 Pkp Web Application Library 2025-02-27 5.4 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
CVE-2023-5904 1 Sfu 1 Pkp Web Application Library 2025-02-27 5.4 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository pkp/pkp-lib prior to 3.3.0-16.
CVE-2023-2621 1 Hitachienergy 1 Modular Advanced Control For Hvdc 2025-02-27 6.5 Medium
The McFeeder server (distributed as part of SSW package), is susceptible to an arbitrary file write vulnerability on the MAIN computer system. This vulnerability stems from the use of an outdated version of a third-party library, which is used to extract archives uploaded to McFeeder server. An authenticated malicious client can exploit this vulnerability by uploading a crafted ZIP archive via the network to McFeeder’s service endpoint.