Search Results (370450 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-49276 1 Uptime.kuma 1 Uptime Kuma 2024-11-21 6.3 Medium
Uptime Kuma is an open source self-hosted monitoring tool. In affected versions the Google Analytics element in vulnerable to Attribute Injection leading to Cross-Site-Scripting (XSS). Since the custom status interface can set an independent Google Analytics ID and the template has not been sanitized, there is an attribute injection vulnerability here, which can lead to XSS attacks. This vulnerability has been addressed in commit `f28dccf4e` which is included in release version 1.23.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVE-2023-49274 1 Umbraco 1 Umbraco Cms 2024-11-21 3.7 Low
Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.4, a user enumeration attack is possible when SMTP is not set up correctly, but reset password is enabled. Versions 8.18.10, 10.8.1, and 12.3.4 contain a patch for this issue.
CVE-2023-49273 1 Umbraco 1 Umbraco Cms 2024-11-21 5.4 Medium
Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.8.1, and 12.3.4, users with low privileges (Editor, etc.) are able to access some unintended endpoints. Versions 8.18.10, 10.8.1, and 12.3.4 contain a patch for this issue.
CVE-2023-49261 1 Hongdian 2 H8951-4g-esp, H8951-4g-esp Firmware 2024-11-21 7.5 High
The "tokenKey" value used in user authorization is visible in the HTML source of the login page.
CVE-2023-49248 1 Huawei 2 Emui, Harmonyos 2024-11-21 5.5 Medium
Vulnerability of unauthorized file access in the Settings app. Successful exploitation of this vulnerability may cause unauthorized file access.
CVE-2023-49247 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
Permission verification vulnerability in distributed scenarios. Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2023-49245 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
Unauthorized access vulnerability in the Huawei Share module. Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2023-49244 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
Permission management vulnerability in the multi-user module. Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2023-49243 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
Vulnerability of unauthorized access to email attachments in the email module. Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2023-49242 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
Free broadcast vulnerability in the running management module. Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2023-49241 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
API permission control vulnerability in the network management module. Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2023-49240 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
Unauthorized access vulnerability in the launcher module. Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2023-49230 1 Peplink 2 Balance Two, Balance Two Firmware 2024-11-21 8.8 High
An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in captive portals allows attackers to modify the portals' configurations without prior authentication.
CVE-2023-49229 1 Peplink 2 Balance Two, Balance Two Firmware 2024-11-21 4.3 Medium
An issue was discovered in Peplink Balance Two before 8.4.0. A missing authorization check in the administration web service allows read-only, unprivileged users to obtain sensitive information about the device configuration.
CVE-2023-49226 1 Peplink 2 Balance Two, Balance Two Firmware 2024-11-21 7.2 High
An issue was discovered in Peplink Balance Two before 8.4.0. Command injection in the traceroute feature of the administration console allows users with admin privileges to execute arbitrary commands as root.
CVE-2023-49216 1 Usedesk 1 Usedesk 2024-11-21 5.4 Medium
Usedesk before 1.7.57 allows profile stored XSS.
CVE-2023-49214 1 Usedesk 1 Usedesk 2024-11-21 9.8 Critical
Usedesk before 1.7.57 allows chat template injection.
CVE-2023-49213 1 Ironmansoftware 1 Powershell Universal 2024-11-21 8.8 High
The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to execute arbitrary commands via crafted HTTP requests if a param block is used, due to invalid sanitization of input strings. The fixed versions are 3.10.2, 4.1.10, and 4.2.1.
CVE-2023-49210 1 Node-openssl Project 1 Node-openssl 2024-11-21 9.8 Critical
The openssl (aka node-openssl) NPM package through 2.0.0 was characterized as "a nonsense wrapper with no real purpose" by its author, and accepts an opts argument that contains a verb field (used for command execution). NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVE-2023-49198 1 Apache 1 Seatunnel 2024-11-21 7.5 High
Mysql security vulnerability in Apache SeaTunnel. Attackers can read files on the MySQL server by modifying the information in the MySQL URL allowLoadLocalInfile=true&allowUrlInLocalInfile=true&allowLoadLocalInfileInPath=/&maxAllowedPacket=655360 This issue affects Apache SeaTunnel: 1.0.0. Users are recommended to upgrade to version [1.0.1], which fixes the issue.