Export limit exceeded: 357917 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (357917 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-49494 | 1 Dedecms | 1 Dedecms | 2024-11-21 | 6.1 Medium |
| DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component select_media_post_wangEditor.php. | ||||
| CVE-2023-49492 | 1 Dedecms | 1 Dedecms | 2024-11-21 | 6.1 Medium |
| DedeCMS v5.7.111 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the imgstick parameter at selectimages.php. | ||||
| CVE-2023-49488 | 1 Openfiler | 1 Openfiler | 2024-11-21 | 6.1 Medium |
| A cross-site scripting (XSS) vulnerability in Openfiler ESA v2.99.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the nic parameter. | ||||
| CVE-2023-49487 | 1 Jfinalcms Project | 1 Jfinalcms | 2024-11-21 | 5.4 Medium |
| JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the navigation management department. | ||||
| CVE-2023-49486 | 1 Jfinalcms Project | 1 Jfinalcms | 2024-11-21 | 5.4 Medium |
| JFinalCMS v5.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability in the model management department. | ||||
| CVE-2023-49484 | 1 Iteachyou | 1 Dreamer Cms | 2024-11-21 | 5.4 Medium |
| Dreamer CMS v4.1.3 was discovered to contain a cross-site scripting (XSS) vulnerability in the article management department. | ||||
| CVE-2023-49469 | 1 Shaarli Project | 1 Shaarli | 2024-11-21 | 6.1 Medium |
| Reflected Cross Site Scripting (XSS) vulnerability in Shaarli v0.12.2, allows remote attackers to execute arbitrary code via search tag function. | ||||
| CVE-2023-49468 | 2 Libde265, Struktur | 2 Libde265, Libde265 | 2024-11-21 | 8.8 High |
| Libde265 v1.0.14 was discovered to contain a global buffer overflow vulnerability in the read_coding_unit function at slice.cc. | ||||
| CVE-2023-49467 | 1 Struktur | 1 Libde265 | 2024-11-21 | 8.8 High |
| Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_combined_bipredictive_merging_candidates function at motion.cc. | ||||
| CVE-2023-49465 | 1 Struktur | 1 Libde265 | 2024-11-21 | 8.8 High |
| Libde265 v1.0.14 was discovered to contain a heap-buffer-overflow vulnerability in the derive_spatial_luma_vector_prediction function at motion.cc. | ||||
| CVE-2023-49464 | 1 Struktur | 1 Libheif | 2024-11-21 | 8.8 High |
| libheif v1.17.5 was discovered to contain a segmentation violation via the function UncompressedImageCodec::get_luma_bits_per_pixel_from_configuration_unci. | ||||
| CVE-2023-49463 | 1 Struktur | 1 Libheif | 2024-11-21 | 8.8 High |
| libheif v1.17.5 was discovered to contain a segmentation violation via the function find_exif_tag at /libheif/exif.cc. | ||||
| CVE-2023-49460 | 1 Struktur | 1 Libheif | 2024-11-21 | 8.8 High |
| libheif v1.17.5 was discovered to contain a segmentation violation via the function UncompressedImageCodec::decode_uncompressed_image. | ||||
| CVE-2023-49448 | 1 Jfinalcms Project | 1 Jfinalcms | 2024-11-21 | 8.8 High |
| JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/nav/delete. | ||||
| CVE-2023-49447 | 1 Jfinalcms Project | 1 Jfinalcms | 2024-11-21 | 8.8 High |
| JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/update. | ||||
| CVE-2023-49446 | 1 Jfinalcms Project | 1 Jfinalcms | 2024-11-21 | 8.8 High |
| JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/nav/save. | ||||
| CVE-2023-49444 | 1 Html-js | 1 Doracms | 2024-11-21 | 5.4 Medium |
| An arbitrary file upload vulnerability in DoraCMS v2.1.8 allow attackers to execute arbitrary code via uploading a crafted HTML or image file to the user avatar. | ||||
| CVE-2023-49443 | 1 Html-js | 1 Doracms | 2024-11-21 | 9.8 Critical |
| DoraCMS v2.1.8 was discovered to re-use the same code for verification of valid usernames and passwords. This vulnerability allows attackers to gain access to the application via a bruteforce attack. | ||||
| CVE-2023-49436 | 1 Tenda | 2 Ax9, Ax9 Firmware | 2024-11-21 | 9.8 Critical |
| Tenda AX9 V22.03.01.46 has been discovered to contain a command injection vulnerability in the 'list' parameter at /goform/SetNetControlList. | ||||
| CVE-2023-49435 | 1 Tenda | 2 Ax9, Ax9 Firmware | 2024-11-21 | 9.8 Critical |
| Tenda AX9 V22.03.01.46 is vulnerable to command injection. | ||||