Export limit exceeded: 366210 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (366210 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-32448 1 Dell 1 Powerpath 2025-01-10 5.5 Medium
PowerPath for Windows, versions 7.0, 7.1 & 7.2 contains License Key Stored in Cleartext vulnerability. A local user with access to the installation directory can retrieve the license key of the product and use it to install and license PowerPath on different systems.
CVE-2023-2998 1 Phpmyfaq 1 Phpmyfaq 2025-01-10 6.1 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.14.
CVE-2023-2999 1 Phpmyfaq 1 Phpmyfaq 2025-01-10 6.1 Medium
Cross-site Scripting (XSS) - Stored in GitHub repository thorsten/phpmyfaq prior to 3.1.14.
CVE-2023-33633 1 H3c 2 Magic R300-2100m, Magic R300-2100m Firmware 2025-01-10 7.2 High
H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the UpdateWanParams interface at /goform/aspForm.
CVE-2023-33632 1 H3c 2 Magic R300-2100m, Magic R300-2100m Firmware 2025-01-10 7.2 High
H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the ipqos_lanip_dellist interface at /goform/aspForm.
CVE-2023-33631 1 H3c 2 Magic R300-2100m, Magic R300-2100m Firmware 2025-01-10 7.2 High
H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the DelSTList interface at /goform/aspForm.
CVE-2023-33629 1 H3c 2 Magic R300-2100m, Magic R300-2100m Firmware 2025-01-10 7.2 High
H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the DeltriggerList interface at /goform/aspForm.
CVE-2023-33628 1 H3c 2 Magic R300-2100m, Magic R300-2100m Firmware 2025-01-10 7.2 High
H3C Magic R300 version R300-2100MV100R004 was discovered to contain a stack overflow via the DelvsList interface at /goform/aspForm.
CVE-2023-33509 1 Kramerav 2 Via Go2, Via Go2 Firmware 2025-01-10 9.8 Critical
KramerAV VIA GO² < 4.0.1.1326 is vulnerable to SQL Injection.
CVE-2023-33508 1 Kramerav 2 Via Go2, Via Go2 Firmware 2025-01-10 9.8 Critical
KramerAV VIA GO² < 4.0.1.1326 is vulnerable to unauthenticated file upload resulting in Remote Code Execution (RCE).
CVE-2023-33507 1 Kramerav 2 Via Go2, Via Go2 Firmware 2025-01-10 7.5 High
KramerAV VIA GO² < 4.0.1.1326 is vulnerable to Unauthenticated arbitrary file read.
CVE-2023-33485 1 Totolink 2 X5000r, X5000r Firmware 2025-01-10 8.8 High
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contains a post-authentication buffer overflow via parameter sPort/ePort in the addEffect function.
CVE-2023-33287 1 Actonic 1 Inline Table Editing 2025-01-10 5.4 Medium
A stored cross-site scripting (XSS) vulnerability in the Inline Table Editing application before 3.8.0 for Confluence allows attackers to store and execute arbitrary JavaScript via a crafted payload injected into the tables.
CVE-2024-24988 1 Mattermost 1 Mattermost Server 2025-01-10 4.3 Medium
Mattermost fails to properly validate the length of the emoji value in the custom user status, allowing an attacker to send multiple times a very long string as an emoji value causing high resource consumption and possibly crashing the server.
CVE-2024-43063 1 Qualcomm 34 Qam8255p, Qam8255p Firmware, Qam8295p and 31 more 2025-01-10 6.1 Medium
information disclosure while invoking the mailbox read API.
CVE-2024-23493 1 Mattermost 1 Mattermost Server 2025-01-10 4.3 Medium
Mattermost fails to properly authorize the requests fetching team associated AD/LDAP groups, allowing a user to fetch details of AD/LDAP groups of a team that they are not a member of. 
CVE-2024-0550 1 Mintplexlabs 1 Anythingllm 2025-01-10 6.5 Medium
A user who is privileged already `manager` or `admin` can set their profile picture via the frontend API using a relative filepath to then user the PFP GET API to download any valid files. The attacker would have to have been granted privileged permissions to the system before executing this attack.
CVE-2023-34257 1 Bmc 1 Patrol Agent 2025-01-10 9.8 Critical
An issue was discovered in BMC Patrol through 23.1.00. The agent's configuration can be remotely modified (and, by default, authentication is not required). Some configuration fields related to SNMP (e.g., masterAgentName or masterAgentStartLine) result in code execution when the agent is restarted. NOTE: the vendor's perspective is "These are not vulnerabilities for us as we have provided the option to implement the authentication."
CVE-2023-33736 1 Dcatadmin 1 Dcat Admin 2025-01-10 5.4 Medium
A stored cross-site scripting (XSS) vulnerability in Dcat-Admin v2.1.3-beta allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the URL parameter.
CVE-2023-33735 1 Dlink 2 Dir-846, Dir-846 Firmware 2025-01-10 9.8 Critical
D-Link DIR-846 v1.00A52 was discovered to contain a remote command execution (RCE) vulnerability via the tomography_ping_address parameter in the /HNAP1 interface.