Export limit exceeded: 368558 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (368558 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-37225 | 1 Pexip | 1 Pexip Infinity | 2024-11-21 | 6.1 Medium |
| Pexip Infinity before 32 allows Webapp1 XSS via preconfigured links. | ||||
| CVE-2023-37224 | 1 Archerirm | 1 Archer | 2024-11-21 | 6 Medium |
| An issue in Archer Platform before v.6.13 fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to obtain sensitive information via the log files. | ||||
| CVE-2023-37223 | 1 Archerirm | 1 Archer | 2024-11-21 | 5.4 Medium |
| Cross Site Scripting (XSS) vulnerability in Archer Platform before v.6.13 and fixed in v.6.12.0.6 and v.6.13.0 allows a remote authenticated attacker to execute arbitrary code via a crafted malicious script. | ||||
| CVE-2023-37222 | 1 Farsight | 1 Provide Server | 2024-11-21 | 4.8 Medium |
| Farsight Tech Nordic AB ProVide version 14.5 - Multiple XSS vulnerabilities (CWE-79) can be exploited by a user with administrator privilege. | ||||
| CVE-2023-37221 | 1 7-twenty | 1 Bot | 2024-11-21 | 8.8 High |
| 7Twenty BOT - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'). | ||||
| CVE-2023-37220 | 1 Synel | 43 Bioentry-w2, Bioentry-w2 Firmware, Bioentry P2 and 40 more | 2024-11-21 | 7.2 High |
| Synel Terminals - CWE-494: Download of Code Without Integrity Check | ||||
| CVE-2023-37219 | 1 Tadirantele | 1 Aeonix | 2024-11-21 | 7.3 High |
| Tadiran Telecom Composit - CWE-1236: Improper Neutralization of Formula Elements in a CSV File | ||||
| CVE-2023-37218 | 1 Tadirantele | 1 Aeonix | 2024-11-21 | 7.5 High |
| Tadiran Telecom Aeonix - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | ||||
| CVE-2023-37217 | 1 Tadirantele | 1 Aeonix | 2024-11-21 | 5.3 Medium |
| Tadiran Telecom Aeonix - CWE-204: Observable Response Discrepancy | ||||
| CVE-2023-37216 | 1 Anasystem | 2 Sensmini M4, Sensmini M4 Firmware | 2024-11-21 | 7.5 High |
| AnaSystem SensMini M4 – Using the configuration tool, an authenticated user can cause Denial of Service for the device | ||||
| CVE-2023-37215 | 1 Jbl | 2 Jbl Bar 5.1 Surround, Jbl Bar 5.1 Surround Firmware | 2024-11-21 | 6.2 Medium |
| JBL soundbar multibeam 5.1 - CWE-798: Use of Hard-coded Credentials | ||||
| CVE-2023-37214 | 1 Heights-t | 2 Ero1xs-pro, Ero1xs-pro Firmware | 2024-11-21 | 9.8 Critical |
| Heights Telecom ERO1xS-Pro Dual-Band FW version BZ_ERO1XP.025. | ||||
| CVE-2023-37213 | 1 Synel | 3 Synergy\/a, Synergy\/a Firmware, Synergy Fingerprint Terminals | 2024-11-21 | 8.8 High |
| Synel SYnergy Fingerprint Terminals - CWE-78: 'OS Command Injection' | ||||
| CVE-2023-37208 | 3 Debian, Mozilla, Redhat | 9 Debian Linux, Firefox, Firefox Esr and 6 more | 2024-11-21 | 7.8 High |
| When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13. | ||||
| CVE-2023-37200 | 1 Se | 1 Ecostruxure Opc Ua Server Expert | 2024-11-21 | 5.5 Medium |
| A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause loss of confidentiality when replacing a project file on the local filesystem and after manual restart of the server. | ||||
| CVE-2023-37199 | 1 Schneider-electric | 1 Struxureware Data Center Expert | 2024-11-21 | 6.8 Medium |
| A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE tampers with backups which are then manually restored. | ||||
| CVE-2023-37198 | 1 Schneider-electric | 1 Struxureware Data Center Expert | 2024-11-21 | 6.8 Medium |
| A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE uploads or tampers with install packages. | ||||
| CVE-2023-37197 | 1 Schneider-electric | 1 Struxureware Data Center Expert | 2024-11-21 | 8.8 High |
| A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, change, or delete content, or perform unauthorized actions when tampering with the mass configuration settings of endpoints on DCE. | ||||
| CVE-2023-37196 | 1 Schneider-electric | 1 Struxureware Data Center Expert | 2024-11-21 | 8.8 High |
| A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, change, or delete content, or perform unauthorized actions when tampering with the alert settings of endpoints on DCE. | ||||
| CVE-2023-37195 | 1 Siemens | 10 Simatic Cp 1604, Simatic Cp 1604 Firmware, Simatic Cp 1616 and 7 more | 2024-11-21 | 4.4 Medium |
| A vulnerability has been identified in SIMATIC CP 1604 (All versions), SIMATIC CP 1616 (All versions), SIMATIC CP 1623 (All versions), SIMATIC CP 1626 (All versions), SIMATIC CP 1628 (All versions). Affected devices insufficiently control continuous mapping of direct memory access (DMA) requests. This could allow local attackers with administrative privileges to cause a denial of service situation on the host. A physical power cycle is required to get the system working again. | ||||