Export limit exceeded: 48857 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 367271 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (367271 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-37679 | 1 Nextgen | 1 Mirth Connect | 2024-11-21 | 9.8 Critical |
| A remote command execution (RCE) vulnerability in NextGen Mirth Connect v4.3.0 allows attackers to execute arbitrary commands on the hosting server. | ||||
| CVE-2023-37677 | 1 Pligg | 1 Pligg Cms | 2024-11-21 | 9.8 Critical |
| Pligg CMS v2.0.2 (also known as Kliqqi) was discovered to contain a remote code execution (RCE) vulnerability in the component admin_editor.php. | ||||
| CVE-2023-37659 | 1 Xalpha Project | 1 Xalpha | 2024-11-21 | 9.8 Critical |
| xalpha v0.11.4 is vulnerable to Remote Command Execution (RCE). | ||||
| CVE-2023-37658 | 1 Fastposter | 1 Fast-poster | 2024-11-21 | 5.4 Medium |
| fast-poster v2.15.0 is vulnerable to Cross Site Scripting (XSS). File upload check binary of img, but without strictly check file suffix at /server/fast.py -> ApiUploadHandler.post causes stored XSS | ||||
| CVE-2023-37657 | 1 Lm21 | 1 Twonav | 2024-11-21 | 5.4 Medium |
| TwoNav v2.0.28-20230624 is vulnerable to Cross Site Scripting (XSS). | ||||
| CVE-2023-37656 | 1 Websiteguide Project | 1 Websiteguide | 2024-11-21 | 9.8 Critical |
| WebsiteGuide v0.2 is vulnerable to Remote Command Execution (RCE) via image upload. | ||||
| CVE-2023-37650 | 1 Agentejo | 1 Cockpit | 2024-11-21 | 8.8 High |
| A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows attackers to execute arbitrary Administrator commands. | ||||
| CVE-2023-37649 | 1 Agentejo | 1 Cockpit | 2024-11-21 | 7.5 High |
| Incorrect access control in the component /models/Content of Cockpit CMS v2.5.2 allows unauthorized attackers to access sensitive data. | ||||
| CVE-2023-37647 | 1 Sem-cms | 1 Semcms | 2024-11-21 | 9.8 Critical |
| SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php. | ||||
| CVE-2023-37646 | 1 Bitberry | 1 File Opener | 2024-11-21 | 7.8 High |
| An issue in the CAB file extraction function of Bitberry File Opener v23.0 allows attackers to execute a directory traversal. | ||||
| CVE-2023-37645 | 1 Eyoucms | 1 Eyoucms | 2024-11-21 | 5.3 Medium |
| eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt. | ||||
| CVE-2023-37636 | 1 Webkul | 1 Uvdesk | 2024-11-21 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability in UVDesk Community Skeleton v1.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Message field when creating a ticket. | ||||
| CVE-2023-37635 | 1 Uvdesk | 1 Community-skeleton | 2024-11-21 | 9.8 Critical |
| UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to gain access to the application. | ||||
| CVE-2023-37630 | 1 Simple Online Piggery Management System Project | 1 Simple Online Piggery Management System | 2024-11-21 | 6.1 Medium |
| Online Piggery Management System 1.0 is vulnerable to Cross Site Scripting (XSS). An unauthenticated user can POST JavaScript code to "manage-breed.php" resulting in Persistent XSS. | ||||
| CVE-2023-37629 | 1 Simple Online Piggery Management System Project | 1 Simple Online Piggery Management System | 2024-11-21 | 9.8 Critical |
| Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by sending a POST request to "add-pig.php." | ||||
| CVE-2023-37628 | 1 Simple Online Piggery Management System Project | 1 Simple Online Piggery Management System | 2024-11-21 | 9.8 Critical |
| Online Piggery Management System 1.0 is vulnerable to SQL Injection. | ||||
| CVE-2023-37627 | 1 Code-projects | 1 Online Restaurant Management System | 2024-11-21 | 9.8 Critical |
| Code-projects Online Restaurant Management System 1.0 is vulnerable to SQL Injection. Through SQL injection, an attacker can bypass the admin panel and view order records, add items, delete items etc. | ||||
| CVE-2023-37625 | 1 Netbox | 1 Netbox | 2024-11-21 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability in Netbox v3.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Link templates. | ||||
| CVE-2023-37624 | 1 Netdisco | 1 Netdisco | 2024-11-21 | 6.1 Medium |
| Netdisco before v2.063000 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links. | ||||
| CVE-2023-37623 | 1 Netdisco | 1 Netdisco | 2024-11-21 | 4.8 Medium |
| Netdisco before v2.063000 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Web/TypeAhead.pm. | ||||