Export limit exceeded: 365581 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (365581 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-41539 | 1 Phpjabbers | 1 Business Directory Script | 2024-11-21 | 7.5 High |
| phpjabbers Business Directory Script 3.2 is vulnerable to SQL Injection via the column parameter. | ||||
| CVE-2023-41538 | 1 Phpjabbers | 1 Php Forum Script | 2024-11-21 | 6.1 Medium |
| phpjabbers PHP Forum Script 3.0 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter. | ||||
| CVE-2023-41508 | 1 Superstorefinder | 1 Super Store Finder | 2024-11-21 | 9.8 Critical |
| A hard coded password in Super Store Finder v3.6 allows attackers to access the administration panel. | ||||
| CVE-2023-41507 | 1 Superstorefinder | 1 Super Store Finder | 2024-11-21 | 9.8 Critical |
| Super Store Finder v3.6 was discovered to contain multiple SQL injection vulnerabilities in the store locator component via the products, distance, lat, and lng parameters. | ||||
| CVE-2023-41484 | 1 Cimg | 1 Cimg | 2024-11-21 | 8.1 High |
| An issue in cimg.eu Cimg Library v2.9.3 allows an attacker to obtain sensitive information via a crafted JPEG file. | ||||
| CVE-2023-41453 | 1 Phpkobo | 1 Ajaxnewsticker | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the cmd parameter in the index.php component. | ||||
| CVE-2023-41452 | 1 Phpkobo | 1 Ajaxnewsticker | 2024-11-21 | 8.8 High |
| Cross Site Request Forgery vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the txt parameter in the index.php component. | ||||
| CVE-2023-41451 | 1 Phpkobo | 1 Ajaxnewsticker | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the txt parameter in the index.php component. | ||||
| CVE-2023-41450 | 1 Phpkobo | 1 Ajaxnewsticker | 2024-11-21 | 8.8 High |
| An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter. | ||||
| CVE-2023-41449 | 1 Phpkobo | 1 Ajaxnewsticker | 2024-11-21 | 9.8 Critical |
| An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter. | ||||
| CVE-2023-41448 | 1 Phpkobo | 1 Ajaxnewsticker | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the ID parameter in the index.php component. | ||||
| CVE-2023-41447 | 1 Phpkobo | 1 Ajaxnewsticker | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the subcmd parameter in the index.php component. | ||||
| CVE-2023-41446 | 1 Phpkobo | 1 Ajaxnewsticker | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted script to the title parameter in the index.php component. | ||||
| CVE-2023-41445 | 1 Phpkobo | 1 Ajaxnewsticker | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the index.php component. | ||||
| CVE-2023-41444 | 2 Binalyze, Microsoft | 2 Irec, Windows | 2024-11-21 | 7.8 High |
| An issue in Binalyze IREC.sys v.3.11.0 and before allows a local attacker to execute arbitrary code and escalate privileges via the fun_1400084d0 function in IREC.sys driver. | ||||
| CVE-2023-41443 | 1 Xxyopen | 1 Novel-plus | 2024-11-21 | 7.2 High |
| SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /sys/menu/list. | ||||
| CVE-2023-41442 | 1 Kloudq | 4 Tor Equip Gateway, Tor Lenz, Tor Loco Min and 1 more | 2024-11-21 | 9.8 Critical |
| An issue in Kloudq Technologies Limited Tor Equip 1.0, Tor Loco Mini 1.0 through 3.1 allows a remote attacker to execute arbitrary code via a crafted request to the MQTT component. | ||||
| CVE-2023-41436 | 1 Cskaza | 1 Cszcms | 2024-11-21 | 5.4 Medium |
| Cross Site Scripting vulnerability in CSZCMS v.1.3.0 allows a local attacker to execute arbitrary code via a crafted script to the Additional Meta Tag parameter in the Pages Content Menu component. | ||||
| CVE-2023-41423 | 1 Terryl | 1 Wp Githuber Md | 2024-11-21 | 5.4 Medium |
| Cross Site Scripting vulnerability in WP Githuber MD plugin v.1.16.2 allows a remote attacker to execute arbitrary code via a crafted payload to the new article function. | ||||
| CVE-2023-41387 | 2 Apple, Patreon | 2 Iphone Os, Flutter Downloader | 2024-11-21 | 9.1 Critical |
| A SQL injection in the flutter_downloader component through 1.11.1 for iOS allows remote attackers to steal session tokens and overwrite arbitrary files inside the app's container. The internal database of the framework is exposed to the local user if an app uses UIFileSharingEnabled and LSSupportsOpeningDocumentsInPlace properties. As a result, local users can obtain the same attack primitives as remote attackers by tampering with the internal database of the framework on the device. | ||||