Export limit exceeded: 369098 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (369098 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-48679 | 3 Acronis, Linux, Microsoft | 3 Cyber Protect, Linux Kernel, Windows | 2025-02-06 | 5.4 Medium |
| Stored cross-site scripting (XSS) vulnerability due to missing origin validation in postMessage. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391. | ||||
| CVE-2023-48680 | 3 Acronis, Apple, Microsoft | 3 Cyber Protect, Macos, Windows | 2025-02-06 | 5.5 Medium |
| Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Cyber Protect 16 (macOS, Windows) before build 37391. | ||||
| CVE-2023-28440 | 1 Discourse | 1 Discourse | 2025-02-06 | 2.7 Low |
| Discourse is an open source platform for community discussion. In affected versions a maliciously crafted request from a Discourse administrator can lead to a long-running request and eventual timeout. This has the greatest potential impact in shared hosting environments where admins are untrusted. This issue has been addressed in versions 3.0.3 and 3.1.0.beta4. Users are advised to upgrade. There are no known workarounds for this vulnerability. | ||||
| CVE-2024-45717 | 1 Solarwinds | 1 Solarwinds Platform | 2025-02-06 | 7 High |
| The SolarWinds Platform was susceptible to a XSS vulnerability that affects the search and node information section of the user interface. This vulnerability requires authentication and requires user interaction. | ||||
| CVE-2023-48681 | 3 Acronis, Linux, Microsoft | 3 Cyber Protect, Linux Kernel, Windows | 2025-02-06 | 6.1 Medium |
| Self cross-site scripting (XSS) vulnerability in storage nodes search field. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391. | ||||
| CVE-2023-48682 | 3 Acronis, Linux, Microsoft | 3 Cyber Protect, Linux Kernel, Windows | 2025-02-06 | 5.4 Medium |
| Stored cross-site scripting (XSS) vulnerability in unit name. The following products are affected: Acronis Cyber Protect 16 (Linux, Windows) before build 37391. | ||||
| CVE-2023-2106 | 1 Janeczku | 1 Calibre-web | 2025-02-06 | 9.8 Critical |
| Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20. | ||||
| CVE-2023-2105 | 1 Easyappointments | 1 Easyappointments | 2025-02-06 | 8.8 High |
| Session Fixation in GitHub repository alextselegidis/easyappointments prior to 1.5.0. | ||||
| CVE-2023-2104 | 1 Easyappointments | 1 Easyappointments | 2025-02-06 | 5.4 Medium |
| Improper Access Control in GitHub repository alextselegidis/easyappointments prior to 1.5.0. | ||||
| CVE-2023-2103 | 1 Easyappointments | 1 Easyappointments | 2025-02-06 | 5.4 Medium |
| Cross-site Scripting (XSS) - Stored in GitHub repository alextselegidis/easyappointments prior to 1.5.0. | ||||
| CVE-2023-2102 | 1 Easyappointments | 1 Easyappointments | 2025-02-06 | 4.8 Medium |
| Cross-site Scripting (XSS) - Stored in GitHub repository alextselegidis/easyappointments prior to 1.5.0. | ||||
| CVE-2023-29774 | 1 Iteachyou | 1 Dreamer Cms | 2025-02-06 | 5.4 Medium |
| Dreamer CMS 3.0.1 is vulnerable to stored Cross Site Scripting (XSS). | ||||
| CVE-2023-27911 | 1 Autodesk | 1 Fbx Software Development Kit | 2025-02-06 | 7.8 High |
| A user may be tricked into opening a malicious FBX file that may exploit a heap buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior which may lead to code execution. | ||||
| CVE-2023-27910 | 1 Autodesk | 1 Fbx Software Development Kit | 2025-02-06 | 7.8 High |
| A user may be tricked into opening a malicious FBX file that may exploit a stack buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior which may lead to code execution. | ||||
| CVE-2023-27844 | 1 Litextension | 1 Leurlrewrite | 2025-02-06 | 9.8 Critical |
| SQL injection vulnerability found in PrestaShopleurlrewrite v.1.0 and before allow a remote attacker to gain privileges via the Dispatcher::getController component. | ||||
| CVE-2023-27755 | 1 71note | 1 Go-bbs | 2025-02-06 | 8.8 High |
| go-bbs v1 was discovered to contain an arbitrary file download vulnerability via the component /api/v1/download. | ||||
| CVE-2023-27733 | 1 Dedecms | 1 Dedecms | 2025-02-06 | 7.2 High |
| DedeCMS v5.7.106 was discovered to contain a SQL injection vulnerability via the component /dede/sys_sql_query.php. | ||||
| CVE-2023-27705 | 1 Apng Optimizer Project | 1 Apng Optimizer | 2025-02-06 | 7.5 High |
| APNG_Optimizer v1.4 was discovered to contain a buffer overflow via the component /apngopt/ubuntu.png. | ||||
| CVE-2023-27092 | 1 Jbootfly Project | 1 Jbootfly | 2025-02-06 | 6.1 Medium |
| Cross Site Scripting vulnerability found in Jbootfly allows attackers to obtain sensitive information via the username parameter. | ||||
| CVE-2023-25010 | 1 Autodesk | 1 Maya Usd | 2025-02-06 | 7.8 High |
| A malicious actor may convince a victim to open a malicious USD file that may trigger an uninitialized variable which may result in code execution. | ||||