Export limit exceeded: 357682 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 357682 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (357682 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-34761 | 1 7-eleven | 2 Hello Cup, Led Message Cup | 2024-11-27 | 6.5 Medium |
| An unauthenticated attacker within BLE proximity can remotely connect to a 7-Eleven LED Message Cup, Hello Cup 1.3.1 for Android, and bypass the application's client-side chat censor filter. | ||||
| CVE-2023-34658 | 1 Telegram | 1 Telegram | 2024-11-27 | 5.3 Medium |
| Telegram v9.6.3 on iOS allows attackers to hide critical information on the User Interface via calling the function SFSafariViewController. | ||||
| CVE-2023-34656 | 1 Video Management System Project | 1 Video Management System | 2024-11-27 | 8.8 High |
| An issue was discovered with the JSESSION IDs in Xiamen Si Xin Communication Technology Video management system 3.1 thru 4.1 allows attackers to gain escalated privileges. | ||||
| CVE-2022-48505 | 1 Apple | 1 Macos | 2024-11-27 | 5.5 Medium |
| This issue was addressed with improved data protection. This issue is fixed in macOS Ventura 13. An app may be able to modify protected parts of the file system | ||||
| CVE-2023-39340 | 1 Ivanti | 1 Connect Secure | 2024-11-27 | 7.5 High |
| A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker can send a specific request which may lead to Denial of Service (DoS) of the appliance. | ||||
| CVE-2023-46260 | 2 Ivanti, Microsoft | 2 Avalanche, Windows | 2024-11-27 | 9.8 Critical |
| An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | ||||
| CVE-2023-46217 | 2 Ivanti, Microsoft | 2 Avalanche, Windows | 2024-11-27 | 9.8 Critical |
| An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | ||||
| CVE-2022-46891 | 1 Arm | 3 Bifrost Gpu Kernel Driver, Midgard Gpu Kernel Driver, Valhall Gpu Kernel Driver | 2024-11-27 | 8.8 High |
| An issue was discovered in the Arm Mali GPU Kernel Driver. There is a use-after-free. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Midgard r13p0 through r32p0, Bifrost r1p0 through r40p0, and Valhall r19p0 through r40p0. | ||||
| CVE-2023-28474 | 1 Concretecms | 1 Concrete Cms | 2024-11-27 | 5.4 Medium |
| Concrete CMS (previously concrete5) in versions 9.0 through 9.1.3 is vulnerable to Stored XSS on Saved Presets on search. | ||||
| CVE-2023-33785 | 1 Netbox | 1 Netbox | 2024-11-27 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability in the Create Rack Roles (/dcim/rack-roles/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field. | ||||
| CVE-2023-33795 | 1 Netbox | 1 Netbox | 2024-11-27 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability in the Create Contact Roles (/tenancy/contact-roles/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field. | ||||
| CVE-2023-35042 | 1 Geoserver | 1 Geoserver | 2024-11-27 | 9.8 Critical |
| GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData within a wps:Execute request, as exploited in the wild in June 2023. NOTE: the vendor states that they are unable to reproduce this in any version. | ||||
| CVE-2023-33592 | 1 Oretnom23 | 1 Lost And Found Information System | 2024-11-27 | 9.8 Critical |
| Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=system_info/contact_information. | ||||
| CVE-2023-33661 | 1 Churchcrm | 1 Churchcrm | 2024-11-27 | 6.1 Medium |
| Multiple cross-site scripting (XSS) vulnerabilities were discovered in Church CRM v4.5.3 in GroupReports.php via GroupRole, ReportModel, and OnlyCart parameters. | ||||
| CVE-2023-34647 | 1 Phpgurukul | 1 Hostel Management System | 2024-11-27 | 6.1 Medium |
| PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS). | ||||
| CVE-2023-34833 | 1 Thinkadmin | 1 Thinkadmin | 2024-11-27 | 6.1 Medium |
| An arbitrary file upload vulnerability in the component /api/upload.php of ThinkAdmin v6 allows attackers to execute arbitrary code via a crafted file. | ||||
| CVE-2023-34650 | 1 Small Crm Project | 1 Small Crm | 2024-11-27 | 6.1 Medium |
| PHPgurukl Small CRM v.1.0 is vulnerable to Cross Site Scripting (XSS). | ||||
| CVE-2023-34651 | 1 Hospital Management System Project | 1 Hospital Management System | 2024-11-27 | 6.1 Medium |
| PHPgurukl Hospital Management System v.1.0 is vulnerable to Cross Site Scripting (XSS). | ||||
| CVE-2023-34652 | 1 Phpgurukul | 1 Hostel Management System | 2024-11-27 | 6.1 Medium |
| PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS) via Add New Course. | ||||
| CVE-2023-23163 | 1 Phpgurukul | 1 Art Gallery Management System | 2024-11-27 | 9.8 Critical |
| Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter. | ||||