Export limit exceeded: 363183 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 363183 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (363183 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-37305 | 1 Mediawiki | 1 Mediawiki | 2024-11-26 | 5.3 Medium |
| An issue was discovered in the ProofreadPage (aka Proofread Page) extension for MediaWiki through 1.39.3. In includes/Page/PageContentHandler.php and includes/Page/PageDisplayHandler.php, hidden users can be exposed via public interfaces. | ||||
| CVE-2023-34599 | 1 Gibbonedu | 1 Gibbon | 2024-11-26 | 6.1 Medium |
| Multiple Cross-Site Scripting (XSS) vulnerabilities have been identified in Gibbon v25.0.0, which enable attackers to execute arbitrary Javascript code. | ||||
| CVE-2023-34648 | 1 User Registration \& Login And User Management System With Admin Panel Project | 1 User Registration \& Login And User Management System With Admin Panel | 2024-11-26 | 6.1 Medium |
| A Cross Site Scripting vulnerability in PHPgurukl User Registration Login and User Management System with admin panel v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the signup.php. | ||||
| CVE-2024-9768 | 1 Strategy11 | 1 Formidable Forms | 2024-11-26 | 4.8 Medium |
| The Formidable Forms WordPress plugin before 6.14.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | ||||
| CVE-2023-46499 | 1 Evershop | 1 Evershop | 2024-11-26 | 6.1 Medium |
| Cross Site Scripting vulnerability in EverShop NPM versions before v.1.0.0-rc.5 allows a remote attacker to obtain sensitive information via a crafted scripts to the Admin Panel. | ||||
| CVE-2023-41118 | 1 Enterprisedb | 1 Postgres Advanced Server | 2024-11-26 | 8.8 High |
| An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It may allow an authenticated user to bypass authorization requirements and access underlying implementation functions. When a superuser has configured file locations using CREATE DIRECTORY, these functions allow users to take a wide range of actions, including read, write, copy, rename, and delete. | ||||
| CVE-2024-33012 | 1 Qualcomm | 501 Ar8035, Ar8035 Firmware, Ar9380 and 498 more | 2024-11-26 | 7.5 High |
| Transient DOS while parsing the multiple MBSSID IEs from the beacon, when the tag length is non-zero value but with end of beacon. | ||||
| CVE-2024-35669 | 1 Bowo | 1 Debug Log Manager | 2024-11-26 | 4.3 Medium |
| Missing Authorization vulnerability in Bowo Debug Log Manager.This issue affects Debug Log Manager: from n/a through 2.3.1. | ||||
| CVE-2024-33013 | 1 Qualcomm | 342 Ar8035, Ar8035 Firmware, Csr8811 and 339 more | 2024-11-26 | 7.5 High |
| Transient DOS when driver accesses the ML IE memory and offset value is incremented beyond ML IE length. | ||||
| CVE-2024-33011 | 1 Qualcomm | 501 Ar8035, Ar8035 Firmware, Ar9380 and 498 more | 2024-11-26 | 7.5 High |
| Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero. | ||||
| CVE-2024-33010 | 1 Qualcomm | 499 Ar8035, Ar8035 Firmware, Ar9380 and 496 more | 2024-11-26 | 7.5 High |
| Transient DOS while parsing fragments of MBSSID IE from beacon frame. | ||||
| CVE-2023-37302 | 1 Mediawiki | 1 Mediawiki | 2024-11-26 | 6.1 Medium |
| An issue was discovered in SiteLinksView.php in Wikibase in MediaWiki through 1.39.3. There is XSS via a crafted badge title attribute. This is also related to lack of escaping in wbTemplate (from resources/wikibase/templates.js) for quotes (which can be in a title attribute). | ||||
| CVE-2024-23384 | 1 Qualcomm | 211 Fastconnect 6200, Fastconnect 6200 Firmware, Fastconnect 6700 and 208 more | 2024-11-26 | 8.4 High |
| Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker. | ||||
| CVE-2024-23383 | 1 Qualcomm | 145 Fastconnect 6200, Fastconnect 6200 Firmware, Fastconnect 6700 and 142 more | 2024-11-26 | 8.4 High |
| Memory corruption when kernel driver attempts to trigger hardware fences. | ||||
| CVE-2024-23382 | 1 Qualcomm | 211 Fastconnect 6200, Fastconnect 6200 Firmware, Fastconnect 6700 and 208 more | 2024-11-26 | 8.4 High |
| Memory corruption while processing graphics kernel driver request to create DMA fence. | ||||
| CVE-2023-36751 | 1 Siemens | 22 Ruggedcom Rox Mx5000, Ruggedcom Rox Mx5000 Firmware, Ruggedcom Rox Mx5000re and 19 more | 2024-11-26 | 9.1 Critical |
| A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM ROX RX1501 (All versions < V2.16.0), RUGGEDCOM ROX RX1510 (All versions < V2.16.0), RUGGEDCOM ROX RX1511 (All versions < V2.16.0), RUGGEDCOM ROX RX1512 (All versions < V2.16.0), RUGGEDCOM ROX RX1524 (All versions < V2.16.0), RUGGEDCOM ROX RX1536 (All versions < V2.16.0), RUGGEDCOM ROX RX5000 (All versions < V2.16.0). The install-app URL parameter in the web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could allow an authenticated privileged remote attacker to execute arbitrary code with root privileges. | ||||
| CVE-2024-23381 | 1 Qualcomm | 147 Fastconnect 6200, Fastconnect 6200 Firmware, Fastconnect 6700 and 144 more | 2024-11-26 | 8.4 High |
| Memory corruption when memory mapped in a VBO is not unmapped by the GPU SMMU. | ||||
| CVE-2024-23356 | 1 Qualcomm | 422 Aqt1000, Aqt1000 Firmware, Ar8031 and 419 more | 2024-11-26 | 7.8 High |
| Memory corruption during session sign renewal request calls in HLOS. | ||||
| CVE-2024-35660 | 2 Jeweltheme, Master-addons | 2 Master Addons For Elementor, Master Addons | 2024-11-26 | 6.5 Medium |
| Missing Authorization vulnerability in Jewel Theme Master Addons for Elementor.This issue affects Master Addons for Elementor: from n/a through 2.0.5.4.1. | ||||
| CVE-2024-21775 | 1 Zohocorp | 1 Manageengine Exchange Reporter Plus | 2024-11-26 | 8.3 High |
| Zoho ManageEngine Exchange Reporter Plus versions 5714 and below are vulnerable to the Authenticated SQL injection in report exporting feature. | ||||