Search Results (369657 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-42426 1 Froala 1 Froala Editor 2024-11-21 6.1 Medium
Cross-site scripting (XSS) vulnerability in Froala Froala Editor v.4.1.1 allows remote attackers to execute arbitrary code via the 'Insert link' parameter in the 'Insert Image' component.
CVE-2023-42425 1 Turing 2 Edge\+ Evc5fd, Edge\+ Evc5fd Firmware 2024-11-21 9.8 Critical
An issue in Turing Video Turing Edge+ EVC5FD v.1.38.6 allows remote attacker to execute arbitrary code and obtain sensitive information via the cloud connection components.
CVE-2023-42406 1 Dlink 2 Dar-7000, Dar-7000 Firmware 2024-11-21 9.8 Critical
SQL injection vulnerability in D-Link Online behavior audit gateway DAR-7000 V31R02B1413C allows a remote attacker to obtain sensitive information and execute arbitrary code via the editrole.php component.
CVE-2023-42405 1 Fit2cloud 1 Rackshift 2024-11-21 9.8 Critical
SQL injection vulnerability in FIT2CLOUD RackShift v1.7.1 allows attackers to execute arbitrary code via the `sort` parameter to taskService.list(), bareMetalService.list(), and switchService.list().
CVE-2023-42399 1 Xdsoft 1 Joditeditor 2024-11-21 6.1 Medium
Cross Site Scripting vulnerability in xdsoft.net Jodit Editor v.4.0.0-beta.86 allows a remote attacker to obtain sensitive information via the rich text editor component.
CVE-2023-42398 1 Zzcms 1 Zzcms 2024-11-21 9.8 Critical
An issue in zzCMS v.2023 allows a remote attacker to execute arbitrary code and obtain sensitive information via the ueditor component in controller.php.
CVE-2023-42387 1 Tdsql Chitu Project 1 Tdsql Chitu 2024-11-21 7.5 High
An issue in TDSQL Chitu management platform v.10.3.19.5.0 allows a remote attacker to obtain sensitive information via get_db_info function in install.php.
CVE-2023-42371 1 Summernote 1 Rich Text Editor 2024-11-21 5.4 Medium
Cross Site Scripting vulnerability in Summernote Rich Text Editor v.0.8.18 and before allows a remote attacker to execute arbitrary code via a crafted script to the insert link function in the editor component.
CVE-2023-42363 1 Busybox 1 Busybox 2024-11-21 5.5 Medium
A use-after-free vulnerability was discovered in xasprintf function in xfuncs_printf.c:344 in BusyBox v.1.36.1.
CVE-2023-42362 1 Teller 1 Teller 2024-11-21 5.4 Medium
An arbitrary file upload vulnerability in Teller Web App v.4.4.0 allows a remote attacker to execute arbitrary commands and obtain sensitive information via uploading a crafted file.
CVE-2023-42361 1 Midori-global 1 Better Pdf Exporter 2024-11-21 7.8 High
Local File Inclusion vulnerability in Midori-global Better PDF Exporter for Jira Server and Jira Data Center v.10.3.0 and before allows an attacker to view arbitrary files and cause other impacts via use of crafted image during PDF export.
CVE-2023-42359 1 Exam Form Submission In Php With Source Code Project 1 Exam Form Submission In Php With Source Code 2024-11-21 9.8 Critical
SQL injection vulnerability in Exam Form Submission in PHP with Source Code v.1.0 allows a remote attacker to escalate privileges via the val-username parameter in /index.php.
CVE-2023-42336 1 Netis-systems 2 Wf2409e, Wf2409e Firmware 2024-11-21 9.8 Critical
An issue in NETIS SYSTEMS WF2409Ev4 v.1.0.1.705 allows a remote attacker to execute arbitrary code and obtain sensitive information via the password parameter in the /etc/shadow.sample component.
CVE-2023-42335 1 Fl3xx 2 Crew, Dispatch 2024-11-21 8.8 High
Unrestricted File Upload vulnerability in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to execute arbitrary code via the add attachment function in the New Expense component.
CVE-2023-42334 1 Fl3xx 2 Crew, Dispatch 2024-11-21 6.5 Medium
An Indirect Object Reference (IDOR) in Fl3xx Dispatch 2.10.37 and fl3xx Crew 2.10.37 allows a remote attacker to escalate privileges via the user parameter.
CVE-2023-42331 1 Elitecms 1 Elite Cms 2024-11-21 8.8 High
A file upload vulnerability in EliteCMS v1.01 allows a remote attacker to execute arbitrary code via the manage_uploads.php component.
CVE-2023-42328 1 Peppermint 1 Peppermint 2024-11-21 8.8 High
An issue in PeppermintLabs Peppermint v.0.2.4 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the hardcoded session cookie.
CVE-2023-42327 1 Netgate 1 Pfsense 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page.
CVE-2023-42326 1 Netgate 2 Pfsense, Pfsense Plus 2024-11-21 8.8 High
An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components.
CVE-2023-42323 1 Mnbvcxz131421 1 Douhaocms 2024-11-21 8.8 High
Cross Site Request Forgery (CSRF) vulnerability in DouHaocms v.3.3 allows a remote attacker to execute arbitrary code via the adminAction.class.php file.