Export limit exceeded: 360031 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (360031 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-27791 | 1 Ixpdata | 1 Easyinstall | 2024-11-21 | 8.1 High |
| An issue found in IXP Data Easy Install 6.6.148840 allows a remote attacker to escalate privileges via insecure PRNG. | ||||
| CVE-2023-27636 | 1 Progress | 1 Sitefinity | 2024-11-21 | 6.5 Medium |
| Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor. | ||||
| CVE-2023-27634 | 1 Intrepidity Project | 1 Intrepidity | 2024-11-21 | 8.8 High |
| Cross-Site Request Forgery (CSRF) vulnerability allows arbitrary file upload in Shingo Intrepidity plugin <= 1.5.1 versions. | ||||
| CVE-2023-27631 | 1 Mmrs151 | 1 Daily Prayer Time | 2024-11-21 | 6.5 Medium |
| Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in mmrs151 Daily Prayer Time plugin <= 2023.05.04 versions. | ||||
| CVE-2023-27629 | 1 Geminilabs | 1 Site Reviews | 2024-11-21 | 6.5 Medium |
| Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Paul Ryley Site Reviews plugin <= 6.5.1 versions. | ||||
| CVE-2023-27628 | 1 Sitekit Project | 1 Sitekit | 2024-11-21 | 6.5 Medium |
| Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Webvitaly Sitekit plugin <= 1.3 versions. | ||||
| CVE-2023-27624 | 1 Redirect After Login Project | 1 Redirect After Login | 2024-11-21 | 5.9 Medium |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Marcelotorres Redirect After Login plugin <= 0.1.9 versions. | ||||
| CVE-2023-27623 | 1 Jenst | 1 Wp Page Numbers | 2024-11-21 | 5.4 Medium |
| Cross-Site Request Forgery (CSRF) vulnerability in Jens Törnell WP Page Numbers plugin <= 0.5 versions. | ||||
| CVE-2023-27622 | 1 Guruwalk | 1 Guruwalk Affiliates | 2024-11-21 | 5.9 Medium |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Abel Ruiz GuruWalk Affiliates plugin <= 1.0.0 versions. | ||||
| CVE-2023-27621 | 1 Mrdemonwolf | 1 Livestream Notice | 2024-11-21 | 5.9 Medium |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MrDemonWolf Livestream Notice plugin <= 1.2.0 versions. | ||||
| CVE-2023-27618 | 1 Agilelogix | 1 Store Locator | 2024-11-21 | 5.9 Medium |
| Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in AGILELOGIX Store Locator WordPress plugin <= 1.4.9 versions. | ||||
| CVE-2023-27617 | 1 Carrcommunications | 1 Rsvpmaker | 2024-11-21 | 5.9 Medium |
| Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in David F. Carr RSVPMaker plugin <= 10.6.6 versions. | ||||
| CVE-2023-27616 | 1 Carrcommunications | 1 Rsvpmaker | 2024-11-21 | 7.1 High |
| Unauth. Stored Cross-Site Scripting (XSS) vulnerability in David F. Carr RSVPMaker plugin <= 10.6.6 versions. | ||||
| CVE-2023-27615 | 1 Dipakgajjar | 1 Wp Super Minify | 2024-11-21 | 5.4 Medium |
| Cross-Site Request Forgery (CSRF) vulnerability in Dipak C. Gajjar WP Super Minify plugin <= 1.5.1 versions. | ||||
| CVE-2023-27613 | 1 Monitorclick | 1 Forms Ada | 2024-11-21 | 7.1 High |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MonitorClick Forms Ada – Form Builder plugin <= 1.0 versions. | ||||
| CVE-2023-27612 | 1 Geminilabs | 1 Site Reviews | 2024-11-21 | 6.5 Medium |
| Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Paul Ryley Site Reviews plugin <= 6.5.1 versions. | ||||
| CVE-2023-27611 | 1 Jeanbaptisteaudras | 1 Reusable Blocks Extended | 2024-11-21 | 5.4 Medium |
| Cross-Site Request Forgery (CSRF) vulnerability in audrasjb Reusable Blocks Extended plugin <= 0.9 versions. | ||||
| CVE-2023-27606 | 1 Wp Reroute Email Project | 1 Wp Reroute Email | 2024-11-21 | 5.4 Medium |
| Cross-Site Request Forgery (CSRF) vulnerability in Sajjad Hossain WP Reroute Email plugin <= 1.4.6 versions. | ||||
| CVE-2023-27604 | 1 Apache | 1 Airflow Sqoop Provider | 2024-11-21 | 8.8 High |
| Apache Airflow Sqoop Provider, versions before 4.0.0, is affected by a vulnerability that allows an attacker pass parameters with the connections, which makes it possible to implement RCE attacks via ‘sqoop import --connect’, obtain airflow server permissions, etc. The attacker needs to be logged in and have authorization (permissions) to create/edit connections. It is recommended to upgrade to a version that is not affected. This issue was reported independently by happyhacking-k, And Xie Jianming and LiuHui of Caiji Sec Team also reported it. | ||||
| CVE-2023-27603 | 1 Apache | 1 Linkis | 2024-11-21 | 9.8 Critical |
| In Apache Linkis <=1.3.1, due to the Manager module engineConn material upload does not check the zip path, This is a Zip Slip issue, which will lead to a potential RCE vulnerability. We recommend users upgrade the version of Linkis to version 1.3.2. | ||||