Export limit exceeded: 37280 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (37280 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-36984 | 1 Lavalite | 1 Lavalite | 2024-11-21 | 7.5 High |
| LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure. | ||||
| CVE-2023-36983 | 1 Lavalite | 1 Lavalite | 2024-11-21 | 7.5 High |
| LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure. | ||||
| CVE-2023-36858 | 3 Apple, F5, Microsoft | 5 Macos, Access Policy Manager Clients, Big-ip Access Policy Manager and 2 more | 2024-11-21 | 7.1 High |
| An insufficient verification of data vulnerability exists in BIG-IP Edge Client for Windows and macOS that may allow an attacker to modify its configured server list. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | ||||
| CVE-2023-36808 | 1 Glpi-project | 1 Glpi | 2024-11-21 | 8.6 High |
| GLPI is a free asset and IT management software package. Starting in version 0.80 and prior to version 10.0.8, Computer Virtual Machine form and GLPI inventory request can be used to perform a SQL injection attack. Version 10.0.8 has a patch for this issue. As a workaround, one may disable native inventory. | ||||
| CVE-2023-36689 | 1 Wpfactory | 1 Wpfactory Helper | 2024-11-21 | 7.1 High |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFactory WPFactory Helper plugin <= 1.5.2 versions. | ||||
| CVE-2023-36543 | 1 Apache | 1 Airflow | 2024-11-21 | 6.5 Medium |
| Apache Airflow, versions before 2.6.3, has a vulnerability where an authenticated user can use crafted input to make the current request hang. It is recommended to upgrade to a version that is not affected | ||||
| CVE-2023-36480 | 1 Aerospike | 1 Aerospike Java Client | 2024-11-21 | 9.8 Critical |
| The Aerospike Java client is a Java application that implements a network protocol to communicate with an Aerospike server. Prior to versions 7.0.0, 6.2.0, 5.2.0, and 4.5.0 some of the messages received from the server contain Java objects that the client deserializes when it encounters them without further validation. Attackers that manage to trick clients into communicating with a malicious server can include especially crafted objects in its responses that, once deserialized by the client, force it to execute arbitrary code. This can be abused to take control of the machine the client is running on. Versions 7.0.0, 6.2.0, 5.2.0, and 4.5.0 contain a patch for this issue. | ||||
| CVE-2023-36351 | 1 Viatomtech | 1 Vihealth | 2024-11-21 | 7.8 High |
| An issue in Viatom Health ViHealth for Android v.2.74.58 and before allows a remote attacker to execute arbitrary code via the com.viatom.baselib.mvvm.webWebViewActivity component. | ||||
| CVE-2023-36344 | 1 Dieboldnixdorf | 1 Vynamic View | 2024-11-21 | 7.8 High |
| An issue in Diebold Nixdorf Vynamic View Console v.5.3.1 and before allows a local attacker to execute arbitrary code via not restricting the search path for required DLLs and not verifying the signature. | ||||
| CVE-2023-36306 | 1 Adiscon | 1 Loganalyzer | 2024-11-21 | 6.1 Medium |
| A Cross Site Scripting (XSS) vulnerability in Adiscon Aiscon LogAnalyzer through 4.1.13 allows a remote attacker to execute arbitrary code via the asktheoracle.php, details.php, index.php, search.php, export.php, reports.php, and statistics.php components. | ||||
| CVE-2023-36299 | 1 Typecho | 1 Typecho | 2024-11-21 | 8.8 High |
| A File Upload vulnerability in typecho v.1.2.1 allows a remote attacker to execute arbitrary code via the upload and options-general parameters in index.php. | ||||
| CVE-2023-36298 | 1 Dedecms | 1 Dedecms | 2024-11-21 | 8.8 High |
| DedeCMS v5.7.109 has a File Upload vulnerability, leading to remote code execution (RCE). | ||||
| CVE-2023-36281 | 1 Langchain | 1 Langchain | 2024-11-21 | 9.8 Critical |
| An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt. This is related to __subclasses__ or a template. | ||||
| CVE-2023-36255 | 1 Eramba | 1 Eramba | 2024-11-21 | 8.8 High |
| An issue in Eramba Limited Eramba Enterprise and Community edition v.3.19.1 allows a remote attacker to execute arbitrary code via the path parameter in the URL. | ||||
| CVE-2023-36217 | 1 Xoops | 1 Xoops | 2024-11-21 | 9.0 Critical |
| Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image manager function. | ||||
| CVE-2023-36213 | 1 Motocms | 1 Motocms | 2024-11-21 | 9.8 Critical |
| SQL injection vulnerability in MotoCMS v.3.4.3 allows a remote attacker to gain privileges via the keyword parameter of the search function. | ||||
| CVE-2023-36212 | 1 Totalcms | 1 Total Cms | 2024-11-21 | 8.8 High |
| File Upload vulnerability in Total CMS v.1.7.4 allows a remote attacker to execute arbitrary code via a crafted PHP file to the edit page function. | ||||
| CVE-2023-36211 | 1 Cubiclesoft | 1 Barebones Cms | 2024-11-21 | 5.4 Medium |
| The Barebones CMS v2.0.2 is vulnerable to Stored Cross-Site Scripting (XSS) when an authenticated user interacts with certain features on the admin panel. | ||||
| CVE-2023-36189 | 1 Langchain | 1 Langchain | 2024-11-21 | 7.5 High |
| SQL injection vulnerability in langchain before v0.0.247 allows a remote attacker to obtain sensitive information via the SQLDatabaseChain component. | ||||
| CVE-2023-36188 | 1 Langchain | 1 Langchain | 2024-11-21 | 9.8 Critical |
| An issue in langchain v.0.0.64 allows a remote attacker to execute arbitrary code via the PALChain parameter in the Python exec method. | ||||