Search Results (361184 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-37064 1 Chamilo 1 Chamilo 2024-11-21 4.8 Medium
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the extra fields management section.
CVE-2023-37063 1 Chamilo 1 Chamilo 2024-11-21 4.8 Medium
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the careers & promotions management section.
CVE-2023-37062 1 Chamilo 1 Chamilo 2024-11-21 4.8 Medium
Chamilo 1.11.x up to 1.11.20 allows users with admin privilege account to insert XSS in the course categories' definition.
CVE-2023-37061 1 Chamilo 1 Chamilo 2024-11-21 4.8 Medium
Chamilo 1.11.x up to 1.11.20 allows users with an admin privilege account to insert XSS in the languages management section.
CVE-2023-37049 1 Emlog 1 Emlog 2024-11-21 6.5 Medium
emlog 2.1.9 is vulnerable to Arbitrary file deletion via admin\template.php.
CVE-2023-36995 1 Travianz Project 1 Travianz 2024-11-21 6.1 Medium
TravianZ through 8.3.4 allows XSS via the Alliance tag/name, the statistics page, the link preferences, the Admin Logs, or the COOKUSR cookie.
CVE-2023-36994 1 Travianz Project 1 Travianz 2024-11-21 9.8 Critical
In TravianZ 8.3.4 and 8.3.3, Incorrect Access Control in the installation script allows an attacker to overwrite the server configuration and inject PHP code.
CVE-2023-36993 1 Travianz Project 1 Travianz 2024-11-21 9.8 Critical
The cryptographically insecure random number generator being used in TravianZ 8.3.4 and 8.3.3 in the password reset function allows an attacker to guess the password reset.parameters and to take over accounts.
CVE-2023-36992 1 Travianz Project 1 Travianz 2024-11-21 7.2 High
PHP injection in TravianZ 8.3.4 and 8.3.3 in the config editor in the admin page allows remote attackers to execute PHP code.
CVE-2023-36984 1 Lavalite 1 Lavalite 2024-11-21 7.5 High
LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure.
CVE-2023-36983 1 Lavalite 1 Lavalite 2024-11-21 7.5 High
LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure.
CVE-2023-36980 1 Ethereum 1 Blockchain 2024-11-21 5.3 Medium
An issue in Ethereum Blockchain v0.1.1+commit.6ff4cd6 cause the balance to be zeroed out when the value of betsize+casino.balance exceeds the threshold.
CVE-2023-36970 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 5.4 Medium
A Cross-site scripting (XSS) vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web script or HTML via the File Upload function.
CVE-2023-36969 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 8.8 High
CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.
CVE-2023-36968 1 Food Ordering System Project 1 Food Ordering System 2024-11-21 7.2 High
A SQL Injection vulnerability detected in Food Ordering System v1.0 allows attackers to run commands on the database by sending crafted SQL queries to the ID parameter.
CVE-2023-36955 1 Totolink 2 Cp300\+, Cp300\+ Firmware 2024-11-21 9.8 Critical
TOTOLINK CP300+ <=V5.2cu.7594_B20200910 was discovered to contain a stack overflow via the File parameter in the function UploadCustomModule.
CVE-2023-36954 1 Totolink 2 Cp300\+, Cp300\+ Firmware 2024-11-21 9.8 Critical
TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection.
CVE-2023-36953 1 Totolink 2 Cp300\+, Cp300\+ Firmware 2024-11-21 9.8 Critical
TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection.
CVE-2023-36952 1 Totolink 2 Cp300\+, Cp300\+ Firmware 2024-11-21 9.8 Critical
TOTOLINK CP300+ V5.2cu.7594_B20200910 was discovered to contain a stack overflow via the pingIp parameter in the function setDiagnosisCfg.
CVE-2023-36950 1 Totolink 4 A7000r, A7000r Firmware, X5000r and 1 more 2024-11-21 8.8 High
TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.