Export limit exceeded: 29280 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 29280 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 29280 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 29280 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Export limit exceeded: 29280 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (29280 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-39158 1 Multidots 1 Banner Management For Woocommerce 2024-11-21 4.3 Medium
Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Banner Management For WooCommerce plugin <= 2.4.2 versions.
CVE-2023-39144 1 Element55 1 Knowmore 2024-11-21 7.5 High
Element55 KnowMore appliances version 21 and older was discovered to store passwords in plaintext.
CVE-2023-39122 1 Bmc 1 Control-m 2024-11-21 9.8 Critical
BMC Control-M through 9.0.20.200 allows SQL injection via the /RF-Server/report/deleteReport report-id parameter. This is fixed in 9.0.21 (and is also fixed by a patch for 9.0.20.200).
CVE-2023-39121 1 Emlog 1 Emlog 2024-11-21 7.2 High
emlog v2.1.9 was discovered to contain a SQL injection vulnerability via the component /admin/user.php.
CVE-2023-39115 1 Campcodes 1 Complete Online Matrimonial Website System Script 2024-11-21 9.8 Critical
install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG document.
CVE-2023-39114 1 Miniupnp Project 1 Ngiflib 2024-11-21 5.5 Medium
ngiflib commit 84a75 was discovered to contain a segmentation violation via the function SDL_LoadAnimatedGif at ngiflibSDL.c. This vulnerability is triggered when running the program SDLaffgif.
CVE-2023-39113 1 Miniupnp Project 1 Ngiflib 2024-11-21 5.5 Medium
ngiflib commit fb271 was discovered to contain a segmentation violation via the function "main" at gif2tag.c. This vulnerability is triggered when running the program gif2tga.
CVE-2023-39112 1 Shopex 1 Ecshop 2024-11-21 6.5 Medium
ECShop v4.1.16 contains an arbitrary file deletion vulnerability in the Admin Panel.
CVE-2023-39110 1 Rconfig 1 Rconfig 2024-11-21 8.8 High
rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path parameter at /ajaxGetFileByPath.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.
CVE-2023-39109 1 Rconfig 1 Rconfig 2024-11-21 8.8 High
rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_a parameter in the doDiff Function of /classes/compareClass.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.
CVE-2023-39108 1 Rconfig 1 Rconfig 2024-11-21 8.8 High
rconfig v3.9.4 was discovered to contain a Server-Side Request Forgery (SSRF) via the path_b parameter in the doDiff Function of /classes/compareClass.php. This vulnerability allows authenticated attackers to make arbitrary requests via injection of crafted URLs.
CVE-2023-39107 2 Apple, Nomachine 4 Macos, Enterprise Client, Free Edition and 1 more 2024-11-21 9.1 Critical
An arbitrary file overwrite vulnerability in NoMachine Free Edition and Enterprise Client for macOS before v8.8.1 allows attackers to overwrite root-owned files by using hardlinks.
CVE-2023-39097 1 Webboss 1 Webboss.io Cms 2024-11-21 5.4 Medium
WebBoss.io CMS v3.7.0.1 contains a stored cross-site scripting (XSS) vulnerability.
CVE-2023-39096 1 Webboss 1 Webboss.io Cms 2024-11-21 5.4 Medium
WebBoss.io CMS v3.7.0.1 contains a stored Cross-Site Scripting (XSS) vulnerability due to lack of input validation and output encoding.
CVE-2023-39075 1 Renault 2 Zoe Ev 2021, Zoe Ev 2021 Firmware 2024-11-21 4.6 Medium
Renault Zoe EV 2021 automotive infotainment system versions 283C35202R to 283C35519R (builds 11.10.2021 to 16.01.2023) allows attackers to crash the infotainment system by sending arbitrary USB data via a USB device.
CVE-2023-38991 1 Jeesite 1 Jeesite 2024-11-21 5.4 Medium
An issue in the delete function in the ActModelController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete models created by the Administrator.
CVE-2023-38990 1 Jeesite 1 Jeesite 2024-11-21 4.3 Medium
An issue in the delete function in the MenuController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete menus created by the Administrator.
CVE-2023-38989 1 Jeesite 1 Jeesite 2024-11-21 4.3 Medium
An issue in the delete function in the UserController class of jeesite v1.2.6 allows authenticated attackers to arbitrarily delete the Administrator's role information.
CVE-2023-38964 1 Creativeitem 1 Academy Lms 2024-11-21 6.1 Medium
Creative Item Academy LMS 6.0 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2023-38958 1 Zkteco 1 Bioaccess Ivs 2024-11-21 5.3 Medium
An access control issue in ZKTeco BioAccess IVS v3.3.1 allows unauthenticated attackers to arbitrarily close and open the doors managed by the platform remotely via sending a crafted web request.