Export limit exceeded: 358200 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 358200 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 358200 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (358200 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-49278 | 1 Umbraco | 1 Umbraco Cms | 2024-11-21 | 5.3 Medium |
| Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.4, a brute force exploit can be used to collect valid usernames. Versions 8.18.10, 10.8.1, and 12.3.4 contain a patch for this issue. | ||||
| CVE-2023-49277 | 1 Darrennathanael | 1 Dpaste | 2024-11-21 | 8.3 High |
| dpaste is an open source pastebin application written in Python using the Django framework. A security vulnerability has been identified in the expires parameter of the dpaste API, allowing for a POST Reflected XSS attack. This vulnerability can be exploited by an attacker to execute arbitrary JavaScript code in the context of a user's browser, potentially leading to unauthorized access, data theft, or other malicious activities. Users are strongly advised to upgrade to dpaste release v3.8 or later versions, as dpaste versions older than v3.8 are susceptible to the identified security vulnerability. No known workarounds have been identified, and applying the patch is the most effective way to remediate the vulnerability. | ||||
| CVE-2023-49276 | 1 Uptime.kuma | 1 Uptime Kuma | 2024-11-21 | 6.3 Medium |
| Uptime Kuma is an open source self-hosted monitoring tool. In affected versions the Google Analytics element in vulnerable to Attribute Injection leading to Cross-Site-Scripting (XSS). Since the custom status interface can set an independent Google Analytics ID and the template has not been sanitized, there is an attribute injection vulnerability here, which can lead to XSS attacks. This vulnerability has been addressed in commit `f28dccf4e` which is included in release version 1.23.7. Users are advised to upgrade. There are no known workarounds for this vulnerability. | ||||
| CVE-2023-49274 | 1 Umbraco | 1 Umbraco Cms | 2024-11-21 | 3.7 Low |
| Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.4, a user enumeration attack is possible when SMTP is not set up correctly, but reset password is enabled. Versions 8.18.10, 10.8.1, and 12.3.4 contain a patch for this issue. | ||||
| CVE-2023-49273 | 1 Umbraco | 1 Umbraco Cms | 2024-11-21 | 5.4 Medium |
| Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.4, users with low privileges (Editor, etc.) are able to access some unintended endpoints. Versions 8.18.10, 10.8.1, and 12.3.4 contain a patch for this issue. | ||||
| CVE-2023-49261 | 1 Hongdian | 2 H8951-4g-esp, H8951-4g-esp Firmware | 2024-11-21 | 7.5 High |
| The "tokenKey" value used in user authorization is visible in the HTML source of the login page. | ||||
| CVE-2023-49248 | 1 Huawei | 2 Emui, Harmonyos | 2024-11-21 | 5.5 Medium |
| Vulnerability of unauthorized file access in the Settings app. Successful exploitation of this vulnerability may cause unauthorized file access. | ||||
| CVE-2023-49247 | 1 Huawei | 2 Emui, Harmonyos | 2024-11-21 | 7.5 High |
| Permission verification vulnerability in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality. | ||||
| CVE-2023-49245 | 1 Huawei | 2 Emui, Harmonyos | 2024-11-21 | 7.5 High |
| Unauthorized access vulnerability in the Huawei Share module. Successful exploitation of this vulnerability may affect service confidentiality. | ||||
| CVE-2023-49244 | 1 Huawei | 2 Emui, Harmonyos | 2024-11-21 | 7.5 High |
| Permission management vulnerability in the multi-user module. Successful exploitation of this vulnerability may affect service confidentiality. | ||||
| CVE-2023-49243 | 1 Huawei | 2 Emui, Harmonyos | 2024-11-21 | 7.5 High |
| Vulnerability of unauthorized access to email attachments in the email module. Successful exploitation of this vulnerability may affect service confidentiality. | ||||
| CVE-2023-49242 | 1 Huawei | 2 Emui, Harmonyos | 2024-11-21 | 7.5 High |
| Free broadcast vulnerability in the running management module. Successful exploitation of this vulnerability may affect service confidentiality. | ||||
| CVE-2023-49241 | 1 Huawei | 2 Emui, Harmonyos | 2024-11-21 | 7.5 High |
| API permission control vulnerability in the network management module. Successful exploitation of this vulnerability may affect service confidentiality. | ||||
| CVE-2023-49240 | 1 Huawei | 2 Emui, Harmonyos | 2024-11-21 | 7.5 High |
| Unauthorized access vulnerability in the launcher module. Successful exploitation of this vulnerability may affect service confidentiality. | ||||
| CVE-2023-49230 | 1 Peplink | 2 Balance Two, Balance Two Firmware | 2024-11-21 | 8.8 High |
| An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in captive portals allows attackers to modify the portals' configurations without prior authentication. | ||||
| CVE-2023-49229 | 1 Peplink | 2 Balance Two, Balance Two Firmware | 2024-11-21 | 4.3 Medium |
| An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in the administration web service allows read-only, unprivileged users to obtain sensitive information about the device configuration. | ||||
| CVE-2023-49226 | 1 Peplink | 2 Balance Two, Balance Two Firmware | 2024-11-21 | 7.2 High |
| An issue was discovered in Peplink Balance Two before 8.4.0. Command injection in the traceroute feature of the administration console allows users with admin privileges to execute arbitrary commands as root. | ||||
| CVE-2023-49216 | 1 Usedesk | 1 Usedesk | 2024-11-21 | 5.4 Medium |
| Usedesk before 1.7.57 allows profile stored XSS. | ||||
| CVE-2023-49214 | 1 Usedesk | 1 Usedesk | 2024-11-21 | 9.8 Critical |
| Usedesk before 1.7.57 allows chat template injection. | ||||
| CVE-2023-49213 | 1 Ironmansoftware | 1 Powershell Universal | 2024-11-21 | 8.8 High |
| The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to execute arbitrary commands via crafted HTTP requests if a param block is used, due to invalid sanitization of input strings. The fixed versions are 3.10.2, 4.1.10, and 4.2.1. | ||||