Export limit exceeded: 357855 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 357855 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 357855 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (357855 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2024-21467 | 1 Qualcomm | 258 Csr8811, Csr8811 Firmware, Fastconnect 6800 and 255 more | 2024-11-26 | 6.5 Medium |
| Information disclosure while handling beacon probe frame during scan entry generation in client side. | ||||
| CVE-2023-47453 | 1 Sohu | 1 Video Player | 2024-11-26 | 7.8 High |
| An Untrusted search path vulnerability in Sohu Video Player 7.0.15.0 allows local users to gain escalated privileges through the version.dll file in the current working directory. | ||||
| CVE-2023-46353 | 1 Mypresta | 1 Product Tag Icons Pro | 2024-11-26 | 9.8 Critical |
| In the module "Product Tag Icons Pro" (ticons) before 1.8.4 from MyPresta.eu for PrestaShop, a guest can perform SQL injection. The method TiconProduct::getTiconByProductAndTicon() has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection. | ||||
| CVE-2024-7245 | 1 Pandasecurity | 1 Panda Dome | 2024-11-26 | 7.8 High |
| Panda Security Dome VPN Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Hydra Sdk Windows Service. The issue lies in the lack of proper permissions set on a folder created by the service. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-23429. | ||||
| CVE-2024-23353 | 1 Qualcomm | 502 205 Mobile Platform, 205 Mobile Platform Firmware, 215 Mobile Platform and 499 more | 2024-11-26 | 7.5 High |
| Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI. | ||||
| CVE-2023-43298 | 1 Linecorp | 1 Line | 2024-11-26 | 5.3 Medium |
| An issue in SCOL Members Card mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | ||||
| CVE-2023-48208 | 1 Phpjabbers | 1 Availability Booking Calendar | 2024-11-26 | 6.1 Medium |
| A Cross Site Scripting vulnerability in Availability Booking Calendar 5.0 allows an attacker to inject JavaScript via the name, plugin_sms_api_key, plugin_sms_country_code, uuid, title, or country name parameter to index.php. | ||||
| CVE-2023-48836 | 1 Phpjabbers | 1 Car Rental Script | 2024-11-26 | 5.4 Medium |
| Car Rental Script 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter. | ||||
| CVE-2023-48861 | 2 Baidu, Microsoft | 2 Ttplayer, Windows | 2024-11-26 | 7.8 High |
| DLL hijacking vulnerability in TTplayer version 7.0.2, allows local attackers to escalate privileges and execute arbitrary code via urlmon.dll. | ||||
| CVE-2023-49432 | 1 Tenda | 2 Ax9, Ax9 Firmware | 2024-11-26 | 9.8 Critical |
| Tenda AX9 V22.03.01.46 has been found to contain a stack overflow vulnerability in the 'deviceList' parameter at /goform/setMacFilterCfg. | ||||
| CVE-2024-23355 | 1 Qualcomm | 286 Ar8035, Ar8035 Firmware, Fastconnect 6200 and 283 more | 2024-11-26 | 7.8 High |
| Memory corruption when keymaster operation imports a shared key. | ||||
| CVE-2023-49999 | 1 Tenda | 2 W30e, W30e Firmware | 2024-11-26 | 9.8 Critical |
| Tenda W30E V16.01.0.12(4843) was discovered to contain a command injection vulnerability via the function setUmountUSBPartition. | ||||
| CVE-2024-34435 | 1 Coderevolution | 1 Aiomatic | 2024-11-26 | 4.3 Medium |
| Missing Authorization vulnerability in CodeRevolution Aiomatic.This issue affects Aiomatic: from n/a through 1.9.3. | ||||
| CVE-2023-33411 | 1 Supermicro | 724 B12dpe-6, B12dpe-6 Firmware, B12dpt-6 and 721 more | 2024-11-26 | 7.5 High |
| A web server in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions up to 3.17.02, allows remote unauthenticated users to perform directory traversal, potentially disclosing sensitive information. | ||||
| CVE-2023-41171 | 1 Netscout | 1 Ngeniusone | 2024-11-26 | 5.4 Medium |
| NetScout nGeniusONE 6.3.4 build 2298 allows a Stored Cross-Site scripting vulnerability (issue 3 of 4). | ||||
| CVE-2023-49462 | 1 Struktur | 1 Libheif | 2024-11-26 | 8.8 High |
| libheif v1.17.5 was discovered to contain a segmentation violation via the component /libheif/exif.cc. | ||||
| CVE-2023-50444 | 1 Primx | 3 Zed\!, Zedmail, Zonecentral | 2024-11-26 | 7.5 High |
| By default, .ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission); ZED! for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before 2023.5; ZEDMAIL for Windows before 2023.5; and ZED! for Windows, Mac, Linux before 2023.5 include an encrypted version of sensitive user information, which could allow an unauthenticated attacker to obtain it via brute force. | ||||
| CVE-2023-41621 | 1 Emlog | 1 Emlog | 2024-11-26 | 6.1 Medium |
| A Cross Site Scripting (XSS) vulnerability was discovered in Emlog Pro v2.1.14 via the component /admin/store.php. | ||||
| CVE-2023-41618 | 1 Emlog | 1 Emlog | 2024-11-26 | 6.1 Medium |
| Emlog Pro v2.1.14 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /admin/article.php?active_savedraft. | ||||
| CVE-2023-47321 | 1 Silverpeas | 1 Silverpeas | 2024-11-26 | 4.9 Medium |
| Silverpeas Core 6.3.1 is vulnerable to Incorrect Access Control via the "Porlet Deployer" which allows administrators to deploy .WAR portlets. | ||||