Search Results (378393 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-27161 1 Jellyfin 1 Jellyfin 2025-02-28 7.5 High
Jellyfin up to v10.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /Repositories. This vulnerability allows attackers to access network resources and sensitive information via a crafted POST request.
CVE-2023-27119 1 Webassembly 1 Wabt 2025-02-28 5.5 Medium
WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::Decompiler::WrapChild.
CVE-2023-25134 1 Mcafee 1 Total Protection 2025-02-28 6.7 Medium
McAfee Total Protection prior to 16.0.50 may allow an adversary (with full administrative access) to modify a McAfee specific Component Object Model (COM) in the Windows Registry. This can result in the loading of a malicious payload.
CVE-2023-24709 1 Paradox 2 Ipr512, Ipr512 Firmware 2025-02-28 7.5 High
An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and login.xml parameters.
CVE-2023-26109 1 Node-bluetooth-serial-port Project 1 Node-bluetooth-serial-port 2025-02-28 7.3 High
All versions of the package node-bluetooth-serial-port are vulnerable to Buffer Overflow via the findSerialPortChannel method due to improper user input length validation.
CVE-2023-26110 1 Node-bluetooth Project 1 Node-bluetooth 2025-02-28 7.3 High
All versions of the package node-bluetooth are vulnerable to Buffer Overflow via the findSerialPortChannel method due to improper user input length validation.
CVE-2023-1084 1 Gitlab 1 Gitlab 2025-02-28 2.7 Low
An issue has been discovered in GitLab CE/EE affecting all versions before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A malicious project Maintainer may create a Project Access Token with Owner level privileges using a crafted request.
CVE-2023-1072 1 Gitlab 1 Gitlab 2025-02-28 4.3 Medium
An issue has been discovered in GitLab affecting all versions starting from 9.0 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible to trigger a resource depletion attack due to improper filtering for number of requests to read commits details.
CVE-2023-0483 1 Gitlab 1 Gitlab 2025-02-28 5.5 Medium
An issue has been discovered in GitLab affecting all versions starting from 12.1 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. It was possible for a project maintainer to extract a Datadog integration API key by modifying the site.
CVE-2023-0223 1 Gitlab 1 Gitlab 2025-02-28 5.3 Medium
An issue has been discovered in GitLab affecting all versions starting from 15.5 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. Non-project members could retrieve release descriptions via the API, even if the release visibility is restricted to project members only in the project settings.
CVE-2023-0050 1 Gitlab 1 Gitlab 2025-02-28 8.7 High
An issue has been discovered in GitLab affecting all versions starting from 13.7 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A specially crafted Kroki diagram could lead to a stored XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims.
CVE-2022-4462 1 Gitlab 1 Gitlab 2025-02-28 5 Medium
An issue has been discovered in GitLab affecting all versions starting from 12.8 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. This vulnerability could allow a user to unmask the Discord Webhook URL through viewing the raw API response.
CVE-2023-36887 1 Microsoft 1 Edge Chromium 2025-02-28 7.8 High
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2023-33157 1 Microsoft 1 Sharepoint Server 2025-02-28 8.8 High
Microsoft SharePoint Remote Code Execution Vulnerability
CVE-2023-33131 1 Microsoft 4 Office, Office Long Term Servicing Channel, Outlook and 1 more 2025-02-28 8.8 High
Microsoft Outlook Remote Code Execution Vulnerability
CVE-2023-24923 1 Microsoft 1 Onedrive 2025-02-28 5.5 Medium
Microsoft OneDrive for Android Information Disclosure Vulnerability
CVE-2023-24882 1 Microsoft 1 Onedrive 2025-02-28 5.5 Medium
Microsoft OneDrive for Android Information Disclosure Vulnerability
CVE-2023-24879 1 Microsoft 1 Dynamics 365 2025-02-28 5.4 Medium
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-24860 1 Microsoft 1 Malware Protection Engine 2025-02-28 7.5 High
Microsoft Defender Denial of Service Vulnerability
CVE-2023-20947 1 Google 1 Android 2025-02-28 7.8 High
In getGroupState of GrantPermissionsViewModel.kt, there is a possible way to keep a one-time permission granted due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12 Android-12L Android-13Android ID: A-237405974