Search Results (359063 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-31941 1 Online Travel Agency System Project 1 Online Travel Agency System 2024-11-21 7.2 High
File Upload vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via a crafted PHP file to the employee_insert.php.
CVE-2023-31940 1 Online Travel Agency System Project 1 Online Travel Agency System 2024-11-21 7.2 High
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the page_id parameter at article_edit.php.
CVE-2023-31939 1 Online Travel Agency System Project 1 Online Travel Agency System 2024-11-21 7.2 High
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the costomer_id parameter at customer_edit.php.
CVE-2023-31938 1 Online Travel Agency System Project 1 Online Travel Agency System 2024-11-21 7.2 High
SQL injection vulnerability found in Online Travel Agency System v.1.0 allows a remote attacker to execute arbitrary code via the emp_id parameter at employee_detail.php.
CVE-2023-31937 1 Phpgurukul 1 Rail Pass Management System 2024-11-21 7.2 High
Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the editid parameter of the edit-cateogry-detail.php file.
CVE-2023-31935 1 Phpgurukul 1 Rail Pass Management System 2024-11-21 4.8 Medium
Cross Site Scripting vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to obtain sensitive information via the emial parameter of admin-profile.php.
CVE-2023-31934 1 Phpgurukul 1 Rail Pass Management System 2024-11-21 4.8 Medium
Cross Site Scripting vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to obtain sensitive information via the adminname parameter of admin-profile.php.
CVE-2023-31933 1 Phpgurukul 1 Rail Pass Management System 2024-11-21 7.2 High
Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the editid parameter of the edit-pass-detail.php file.
CVE-2023-31932 1 Phpgurukul 1 Rail Pass Management System 2024-11-21 7.2 High
Sql injection vulnerability found in Rail Pass Management System v.1.0 allows a remote attacker to execute arbitrary code via the viewid parameter of the view-enquiry.php file.
CVE-2023-31925 1 Broadcom 1 Brocade Sannav 2024-11-21 5.4 Medium
Brocade SANnav before v2.3.0 and v2.2.2a stores SNMPv3 Authentication passwords in plaintext. A privileged user could retrieve these credentials with knowledge and access to these log files. SNMP credentials could be seen in SANnav SupportSave if the capture is performed after an SNMP configuration failure causes an SNMP communication log dump.
CVE-2023-31853 1 Cudy 2 Lt400, Lt400 Firmware 2024-11-21 6.1 Medium
Cudy LT400 1.13.4 is vulnerable Cross Site Scripting (XSS) in /cgi-bin/luci/admin/network/bandwidth via the icon parameter.
CVE-2023-31851 1 Cudy 2 Lt400, Lt400 Firmware 2024-11-21 6.1 Medium
Cudy LT400 1.13.4 is has a cross-site scripting (XSS) vulnerability in /cgi-bin/luci/admin/network/wireless/status via the iface parameter.
CVE-2023-31825 1 Inageya 1 Inageya 2024-11-21 7.5 High
An issue found in Inageya v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp Inageya function.
CVE-2023-31824 1 Dericia 1 Delicia 2024-11-21 7.5 High
An issue found in DERICIA Co. Ltd, DELICIA v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp DELICIA function.
CVE-2023-31823 1 Marui 1 Marui 2024-11-21 7.5 High
An issue found in Marui Co Marui Official app v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp Marui Official Store function.
CVE-2023-31822 1 Entetsu 1 Entetsu Store 2024-11-21 7.5 High
An issue found in Entetsu Store v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp Entetsu Store function.
CVE-2023-31821 1 Albis 1 Albis 2024-11-21 7.5 High
An issue found in ALBIS Co. ALBIS v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp ALBIS function.
CVE-2023-31820 1 Shizutetsu 1 Shizutetsu Store 2024-11-21 7.5 High
An issue found in Shizutetsu Store v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp function.
CVE-2023-31818 1 Marukyu 1 Marukyu Line 2024-11-21 7.5 High
An issue found in Marukyu Line v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp function.
CVE-2023-31808 1 Technicolor 2 Tg670, Tg670 Firmware 2024-11-21 7.2 High
Technicolor TG670 10.5.N.9 devices contain multiple accounts with hard-coded passwords. One account has administrative privileges, allowing for unrestricted access over the WAN interface if Remote Administration is enabled.