Export limit exceeded: 366359 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (366359 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-2226 1 Rapid7 1 Velociraptor 2025-02-04 3.3 Low
Due to insufficient validation in the PE and OLE parsers in Rapid7's Velociraptor versions earlier than 0.6.8 allows attacker to crash Velociraptor during parsing of maliciously malformed files.  For this attack to succeed, the attacker needs to be able to introduce malicious files to the system at the same time that Velociraptor attempts to collect any artifacts that attempt to parse PE files, Authenticode signatures, or OLE files. After crashing, the Velociraptor service will restart and it will still be possible to collect other artifacts.
CVE-2023-2139 1 3ds 1 Delmia Apriso 2025-02-04 5.4 Medium
A reflected Cross-site Scripting (XSS) Vulnerability in DELMIA Apriso Release 2017 through Release 2022 allows an attacker to execute arbitrary script code.
CVE-2023-2140 1 3ds 1 Delmia Apriso 2025-02-04 7.5 High
A Server-Side Request Forgery vulnerability in DELMIA Apriso Release 2017 through Release 2022 could allow an unauthenticated attacker to issue requests to arbitrary hosts on behalf of the server running the DELMIA Apriso application.
CVE-2023-2141 1 3ds 1 Delmia Apriso 2025-02-04 8.5 High
An unsafe .NET object deserialization in DELMIA Apriso Release 2017 through Release 2022 could lead to post-authentication remote code execution.
CVE-2023-31081 1 Linux 1 Linux Kernel 2025-02-04 5.5 Medium
An issue was discovered in drivers/media/test-drivers/vidtv/vidtv_bridge.c in the Linux kernel 6.2. There is a NULL pointer dereference in vidtv_mux_stop_thread. In vidtv_stop_streaming, after dvb->mux=NULL occurs, it executes vidtv_mux_stop_thread(dvb->mux).
CVE-2023-31061 1 Repetier-server 1 Repetier-server 2025-02-04 8.8 High
Repetier Server through 1.4.10 does not have CSRF protection.
CVE-2023-31060 1 Repetier-server 1 Repetier-server 2025-02-04 9.8 Critical
Repetier Server through 1.4.10 executes as SYSTEM. This can be leveraged in conjunction with CVE-2023-31059 for full compromise.
CVE-2023-31059 1 Repetier-server 1 Repetier-server 2025-02-04 7.5 High
Repetier Server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstrated by connectionLost.php.
CVE-2023-31056 1 Cloverdx 1 Cloverdx 2025-02-04 9.1 Critical
CloverDX before 5.17.3 writes passwords to the audit log in certain situations, if the audit log is enabled and single sign-on is not employed. The fixed versions are 5.15.4, 5.16.2, 5.17.3, and 6.0.x.
CVE-2023-30533 1 Sheetjs 1 Sheetjs 2025-02-04 7.8 High
SheetJS Community Edition before 0.19.3 allows Prototype Pollution via a crafted file. In other words. 0.19.2 and earlier are affected, whereas 0.19.3 and later are unaffected.
CVE-2023-30458 1 Medicine Tracker System Project 1 Medicine Tracker System 2025-02-04 5.3 Medium
A username enumeration issue was discovered in Medicine Tracker System 1.0. The login functionality allows a malicious user to guess a valid username due to a different response time from invalid usernames. When one enters a valid username, the response time increases depending on the length of the supplied password.
CVE-2023-30414 1 Jerryscript 1 Jerryscript 2025-02-04 5.5 Medium
Jerryscript commit 1a2c047 was discovered to contain a stack overflow via the component vm_loop at /jerry-core/vm/vm.c.
CVE-2023-30373 1 Tenda 2 Ac15, Ac15 Firmware 2025-02-04 9.8 Critical
In Tenda AC15 V15.03.05.19, the function "xian_pppoe_user" contains a stack-based buffer overflow vulnerability.
CVE-2023-30372 1 Tenda 2 Ac15, Ac15 Firmware 2025-02-04 9.8 Critical
In Tenda AC15 V15.03.05.19, The function "xkjs_ver32" contains a stack-based buffer overflow vulnerability.
CVE-2023-2118 1 Devolutions 1 Devolutions Server 2025-02-04 4.3 Medium
Insufficient access control in support ticket feature in Devolutions Server 2023.1.5.0 and below allows an authenticated attacker to send support tickets and download diagnostic files via specific endpoints.
CVE-2023-2114 1 Basixonline 1 Nex-forms 2025-02-04 7.2 High
The NEX-Forms WordPress plugin before 8.4 does not properly escape the `table` parameter, which is populated with user input, before concatenating it to an SQL query.
CVE-2023-0948 1 Artisanworkshop 1 Japanized For Woocommerce 2025-02-04 6.1 Medium
The Japanized For WooCommerce WordPress plugin before 2.5.8 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting
CVE-2023-0522 1 Enable\/disable Auto Login When Register Project 1 Enable\/disable Auto Login When Register 2025-02-04 6.5 Medium
The Enable/Disable Auto Login when Register WordPress plugin through 1.1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVE-2023-30618 1 Kitchen-terraform Project 1 Kitchen-terraform 2025-02-04 3.2 Low
Kitchen-Terraform provides a set of Test Kitchen plugins which enable the use of Test Kitchen to converge a Terraform configuration and verify the resulting infrastructure systems with InSpec controls. Kitchen-Terraform v7.0.0 introduced a regression which caused all Terraform output values, including sensitive values, to be printed at the `info` logging level during the `kitchen converge` action. Prior to v7.0.0, the output values were printed at the `debug` level to avoid writing sensitive values to the terminal by default. An attacker would need access to the local machine in order to gain access to these logs during an operation. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVE-2023-30620 1 Mindsdb 1 Mindsdb 2025-02-04 7.5 High
mindsdb is a Machine Learning platform to help developers build AI solutions. In affected versions an unsafe extraction is being performed using `tarfile.extractall()` from a remotely retrieved tarball. Which may lead to the writing of the extracted files to an unintended location. Sometimes, the vulnerability is called a TarSlip or a ZipSlip variant. An attacker may leverage this vulnerability to overwrite any local file which the server process has access to. There is no risk of file exposure with this vulnerability. This issue has been addressed in release `23.2.1.0 `. Users are advised to upgrade. There are no known workarounds for this vulnerability.