Export limit exceeded: 40287 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (40287 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-36217 | 1 Xoops | 1 Xoops | 2024-11-21 | 9.0 Critical |
| Cross Site Scripting vulnerability in Xoops CMS v.2.5.10 allows a remote attacker to execute arbitrary code via the category name field of the image manager function. | ||||
| CVE-2023-36213 | 1 Motocms | 1 Motocms | 2024-11-21 | 9.8 Critical |
| SQL injection vulnerability in MotoCMS v.3.4.3 allows a remote attacker to gain privileges via the keyword parameter of the search function. | ||||
| CVE-2023-36212 | 1 Totalcms | 1 Total Cms | 2024-11-21 | 8.8 High |
| File Upload vulnerability in Total CMS v.1.7.4 allows a remote attacker to execute arbitrary code via a crafted PHP file to the edit page function. | ||||
| CVE-2023-36211 | 1 Cubiclesoft | 1 Barebones Cms | 2024-11-21 | 5.4 Medium |
| The Barebones CMS v2.0.2 is vulnerable to Stored Cross-Site Scripting (XSS) when an authenticated user interacts with certain features on the admin panel. | ||||
| CVE-2023-36189 | 1 Langchain | 1 Langchain | 2024-11-21 | 7.5 High |
| SQL injection vulnerability in langchain before v0.0.247 allows a remote attacker to obtain sensitive information via the SQLDatabaseChain component. | ||||
| CVE-2023-36188 | 1 Langchain | 1 Langchain | 2024-11-21 | 9.8 Critical |
| An issue in langchain v.0.0.64 allows a remote attacker to execute arbitrary code via the PALChain parameter in the Python exec method. | ||||
| CVE-2023-36159 | 1 Oretnom23 | 1 Lost And Found Information System | 2024-11-21 | 6.1 Medium |
| Cross Site Scripting (XSS) vulnerability in sourcecodester Lost and Found Information System 1.0 allows remote attackers to run arbitrary code via the First Name, Middle Name and Last Name fields on the Create User page. | ||||
| CVE-2023-36141 | 1 Phpjabbers | 1 Cleaning Business Software | 2024-11-21 | 5.3 Medium |
| User enumeration is found in in PHPJabbers Cleaning Business Software 1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | ||||
| CVE-2023-36139 | 1 Phpjabbers | 1 Cleaning Business Software | 2024-11-21 | 9.8 Critical |
| In PHPJabbers Cleaning Business Software 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts. | ||||
| CVE-2023-36138 | 1 Phpjabbers | 1 Cleaning Business Software | 2024-11-21 | 6.1 Medium |
| PHPJabbers Cleaning Business Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the theme parameter of preview.php. | ||||
| CVE-2023-36137 | 1 Phpjabbers | 1 Class Scheduling System | 2024-11-21 | 6.1 Medium |
| There is a Cross Site Scripting (XSS) vulnerability in the "theme" parameter of preview.php in PHPJabbers Class Scheduling System 1.0. | ||||
| CVE-2023-36135 | 1 Phpjabbers | 1 Class Scheduling System | 2024-11-21 | 7.5 High |
| User enumeration is found in in PHPJabbers Class Scheduling System v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users. | ||||
| CVE-2023-36134 | 1 Phpjabbers | 1 Class Scheduling System | 2024-11-21 | 9.8 Critical |
| In PHP Jabbers Class Scheduling System 1.0, lack of verification when changing an email address and/or password (on the Profile Page) allows remote attackers to take over accounts. | ||||
| CVE-2023-36133 | 1 Phpjabbers | 1 Availability Booking Calendar | 2024-11-21 | 9.8 Critical |
| PHPJabbers Availability Booking Calendar 5.0 is vulnerable to User Account Takeover through username/password change. | ||||
| CVE-2023-36132 | 1 Phpjabbers | 1 Availability Booking Calendar | 2024-11-21 | 9.8 Critical |
| PHP Jabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control. | ||||
| CVE-2023-36131 | 1 Phpjabbers | 1 Availability Booking Calendar | 2024-11-21 | 9.8 Critical |
| PHPJabbers Availability Booking Calendar 5.0 is vulnerable to Incorrect Access Control due to improper input validation of password parameter. | ||||
| CVE-2023-36121 | 1 E107 | 1 E107 | 2024-11-21 | 5.4 Medium |
| Cross Site Scripting vulnerability in e107 v.2.3.2 allows a remote attacker to execute arbitrary code via the description function in the SEO project. | ||||
| CVE-2023-36095 | 1 Langchain | 1 Langchain | 2024-11-21 | 9.8 Critical |
| An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, affected functions include from_math_prompt and from_colored_object_prompt. | ||||
| CVE-2023-36092 | 1 Dlink | 2 Dir-859, Dir-859 Firmware | 2024-11-21 | 9.8 Critical |
| Authentication Bypass vulnerability in D-Link DIR-859 FW105b03 allows remote attackers to gain escalated privileges via via phpcgi_main. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | ||||
| CVE-2023-36091 | 2 D-link, Dlink | 3 Dir-895, Dir-895l, Dir-895l Firmware | 2024-11-21 | 9.8 Critical |
| Authentication Bypass vulnerability in D-Link DIR-895 FW102b07 allows remote attackers to gain escalated privileges via via function phpcgi_main in cgibin. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | ||||