Search Results (370169 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-47440 1 Gladysassistant 1 Gladys Assistant 2024-11-21 6.5 Medium
Gladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be incomplete, allowing authenticated attackers to extract sensitive files in the host machine.
CVE-2023-47437 1 Pachno 1 Pachno 2024-11-21 5.4 Medium
A vulnerability has been identified in Pachno 1.0.6 allowing an authenticated attacker to execute a cross-site scripting (XSS) attack. The vulnerability exists due to inadequate input validation in the Project Description and comments, which enables an attacker to inject malicious java script.
CVE-2023-47418 1 Zoneland 1 O2oa 2024-11-21 9.8 Critical
Remote Code Execution (RCE) vulnerability in o2oa version 8.1.2 and before, allows attackers to create a new interface in the service management function to execute JavaScript.
CVE-2023-47417 1 Paulrouget 1 Dzslides 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) vulnerability in the component /shells/embedder.html of DZSlides after v2011.07.25 allows attackers to execute arbitrary code via a crafted payload.
CVE-2023-47397 1 Webidsupport 1 Webid 2024-11-21 9.8 Critical
WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.
CVE-2023-47393 1 Mercedes-benz 1 Mercedes Me 2024-11-21 5.3 Medium
An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the maintenance orders of other users and access sensitive user information via unspecified vectors.
CVE-2023-47392 1 Mercedes-benz 1 Mercedes Me 2024-11-21 5.3 Medium
An access control issue in Mercedes me IOS APP v1.34.0 and below allows attackers to view the carts of other users via sending a crafted add order request.
CVE-2023-47390 1 Juanfont 1 Headscale 2024-11-21 7.5 High
Headscale through 0.22.3 writes bearer tokens to info-level logs.
CVE-2023-47384 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
MP4Box GPAC v2.3-DEV-rev617-g671976fcc-master was discovered to contain a memory leak in the function gf_isom_add_chapter at /isomedia/isom_write.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
CVE-2023-47380 1 Admidio 1 Admidio 2024-11-21 6.1 Medium
Admidio v4.2.12 and below is vulnerable to Cross Site Scripting (XSS).
CVE-2023-47379 1 Microweber 1 Microweber 2024-11-21 5.4 Medium
Microweber CMS version 2.0.1 is vulnerable to stored Cross Site Scripting (XSS) via the profile picture file upload functionality.
CVE-2023-47373 1 Linecorp 1 Line 2024-11-21 6.5 Medium
The leakage of channel access token in DRAGON FAMILY Line 13.6.1 allows remote attackers to send malicious notifications to victims.
CVE-2023-47372 1 Linecorp 1 Line 2024-11-21 6.5 Medium
The leakage of channel access token in UPDATESALON C-LOUNGE Line 13.6.1 allows remote attackers to send malicious notifications to victims.
CVE-2023-47370 1 Linecorp 1 Line 2024-11-21 6.5 Medium
The leakage of channel access token in bluetrick Line 13.6.1 allows remote attackers to send malicious notifications to victims.
CVE-2023-47369 1 Linecorp 1 Line 2024-11-21 6.5 Medium
The leakage of channel access token in best_training_member Line 13.6.1 allows remote attackers to send malicious notifications.
CVE-2023-47368 1 Linecorp 1 Line 2024-11-21 6.5 Medium
The leakage of channel access token in taketorinoyu Line 13.6.1 allows remote attackers to send malicious notifications to victims.
CVE-2023-47367 1 Linecorp 1 Line 2024-11-21 6.5 Medium
The leakage of channel access token in platinum clinic Line 13.6.1 allows remote attackers to send malicious notifications to victims.
CVE-2023-47366 1 Linecorp 1 Line 2024-11-21 6.5 Medium
The leakage of channel access token in craft_members Line 13.6.1 allows remote attackers to send malicious notifications to victims.
CVE-2023-47365 1 Linecorp 1 Line 2024-11-21 6.5 Medium
The leakage of channel access token in Lil.OFF-PRICE STORE Line 13.6.1 allows remote attackers to send malicious notifications to victims.
CVE-2023-47363 1 Linecorp 1 Line 2024-11-21 6.5 Medium
The leakage of channel access token in F.B.P members Line 13.6.1 allows remote attackers to send malicious notifications to victims.