Export limit exceeded: 368529 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 368529 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 368529 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 368529 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (368529 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2017-1515 | 1 Ibm | 1 Engineering Requirements Management Doors | 2025-02-05 | N/A |
| IBM Doors Web Access 9.5 and 9.6 could allow an authenticated user to obtain sensitive information from HTTP internal server error responses. IBM X-Force ID: 129825. | ||||
| CVE-2024-13511 | 1 Variation Swatches For Woocommerce Project | 1 Variation Swatches For Woocommerce | 2025-02-05 | 4.3 Medium |
| The Variation Swatches for WooCommerce plugin, in all versions starting at 1.0.8 up until 1.3.2, contains a vulnerability due to improper nonce verification in its settings reset functionality. The issue exists in the settings_init() function, which processes a reset action based on specific query parameters in the URL. The related delete_settings() function performs a faulty nonce validation check, making the reset operation insecure and susceptible to unauthorized access. | ||||
| CVE-2023-21098 | 1 Google | 1 Android | 2025-02-05 | 7.8 High |
| In multiple functions of AccountManagerService.java, there is a possible loading of arbitrary code into the System Settings app due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-260567867 | ||||
| CVE-2022-48020 | 1 Vinteo | 1 Video Core | 2025-02-05 | 6.1 Medium |
| Vinteo VCC v2.36.4 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the conference parameter. This vulnerability allows attackers to inject arbitrary code which will be executed by the victim user's browser. | ||||
| CVE-2023-39308 | 1 Monsterinsights | 1 Userfeedback | 2025-02-05 | 7.1 High |
| Unauth. Stored Cross-Site Scripting (XSS) vulnerability in UserFeedback Team User Feedback plugin <= 1.0.7 versions. | ||||
| CVE-2024-57556 | 1 Nbubna | 1 Store | 2025-02-05 | 6.1 Medium |
| Cross Site Scripting vulnerability in nbubna store v.2.14.2 and before allows a remote attacker to execute arbitrary code via the store.deep.js component | ||||
| CVE-2024-28097 | 1 Schoolbox | 1 Schoolbox | 2025-02-05 | 7.3 High |
| Calendar functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting allowing authenticated attacker to perform security actions in the context of the affected users. | ||||
| CVE-2024-28096 | 1 Schoolbox | 1 Schoolbox | 2025-02-05 | 7.3 High |
| Class functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting allowing authenticated attacker to perform security actions in the context of the affected users. | ||||
| CVE-2024-28095 | 1 Schoolbox | 1 Schoolbox | 2025-02-05 | 7.3 High |
| News functionality in Schoolbox application before version 23.1.3 is vulnerable to stored cross-site scripting allowing authenticated attacker to perform security actions in the context of the affected users. | ||||
| CVE-2024-28094 | 1 Schoolbox | 1 Schoolbox | 2025-02-05 | 8.8 High |
| Chat functionality in Schoolbox application before version 23.1.3 is vulnerable to blind SQL Injection enabling the authenticated attackers to read, modify, and delete database records. | ||||
| CVE-2023-30076 | 1 Judging Management System Project | 1 Judging Management System | 2025-02-05 | 9.8 Critical |
| Sourcecodester Judging Management System v1.0 is vulnerable to SQL Injection via /php-jms/print_judges.php?print_judges.php=&se_name=&sub_event_id=. | ||||
| CVE-2023-29912 | 1 H3c | 1 Magic R200 Firmware | 2025-02-05 | 4.9 Medium |
| H3C Magic R200 R200V100R004 was discovered to contain a stack overflow via the DelvsList interface at /goform/aspForm. | ||||
| CVE-2023-29911 | 1 H3c | 1 Magic R200 Firmware | 2025-02-05 | 4.9 Medium |
| H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the AddMacList interface at /goform/aspForm. | ||||
| CVE-2023-29910 | 1 H3c | 1 Magic R200 Firmware | 2025-02-05 | 4.9 Medium |
| H3C Magic R200 version R200V100R004 was discovered to contain a stack overflow via the UpdateMacClone interface at /goform/aspForm. | ||||
| CVE-2023-28459 | 1 Pretalx | 1 Pretalx | 2025-02-05 | 6.5 Medium |
| pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Users were able to upload crafted HTML documents that trigger the reading of arbitrary files. | ||||
| CVE-2023-28458 | 1 Pretalx | 1 Pretalx | 2025-02-05 | 4.3 Medium |
| pretalx 2.3.1 before 2.3.2 allows path traversal in HTML export (a non-default feature). Organizers can trigger the overwriting (with the standard pretalx 404 page content) of an arbitrary file. | ||||
| CVE-2023-26599 | 1 Uniguest | 1 Tripleplay | 2025-02-05 | 6.1 Medium |
| XSS vulnerability in TripleSign in Tripleplay Platform releases prior to Caveman 3.4.0 allows attackers to inject client-side code to run as an authenticated user via a crafted link. | ||||
| CVE-2023-25760 | 1 Uniguest | 1 Tripleplay | 2025-02-05 | 8.8 High |
| Incorrect Access Control in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated user to modify other users passwords via a crafted request payload | ||||
| CVE-2023-25759 | 1 Uniguest | 1 Tripleplay | 2025-02-05 | 5.3 Medium |
| OS Command Injection in TripleData Reporting Engine in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated users to run unprivileged OS level commands via a crafted request payload. | ||||
| CVE-2023-22645 | 1 Linuxfoundation | 1 Kubewarden-controller | 2025-02-05 | 8 High |
| An Improper Privilege Management vulnerability in SUSE kubewarden allows attackers to read arbitrary secrets if they get access to the ServiceAccount kubewarden-controller This issue affects: SUSE kubewarden kubewarden-controller versions prior to 1.6.0. | ||||