Search Results (381932 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-47390 1 Juanfont 1 Headscale 2024-11-21 7.5 High
Headscale through 0.22.3 writes bearer tokens to info-level logs.
CVE-2023-47384 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
MP4Box GPAC v2.3-DEV-rev617-g671976fcc-master was discovered to contain a memory leak in the function gf_isom_add_chapter at /isomedia/isom_write.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
CVE-2023-47380 1 Admidio 1 Admidio 2024-11-21 6.1 Medium
Admidio v4.2.12 and below is vulnerable to Cross Site Scripting (XSS).
CVE-2023-47379 1 Microweber 1 Microweber 2024-11-21 5.4 Medium
Microweber CMS version 2.0.1 is vulnerable to stored Cross Site Scripting (XSS) via the profile picture file upload functionality.
CVE-2023-47373 1 Linecorp 1 Line 2024-11-21 6.5 Medium
The leakage of channel access token in DRAGON FAMILY Line 13.6.1 allows remote attackers to send malicious notifications to victims.
CVE-2023-47372 1 Linecorp 1 Line 2024-11-21 6.5 Medium
The leakage of channel access token in UPDATESALON C-LOUNGE Line 13.6.1 allows remote attackers to send malicious notifications to victims.
CVE-2023-47370 1 Linecorp 1 Line 2024-11-21 6.5 Medium
The leakage of channel access token in bluetrick Line 13.6.1 allows remote attackers to send malicious notifications to victims.
CVE-2023-47369 1 Linecorp 1 Line 2024-11-21 6.5 Medium
The leakage of channel access token in best_training_member Line 13.6.1 allows remote attackers to send malicious notifications.
CVE-2023-47368 1 Linecorp 1 Line 2024-11-21 6.5 Medium
The leakage of channel access token in taketorinoyu Line 13.6.1 allows remote attackers to send malicious notifications to victims.
CVE-2023-47367 1 Linecorp 1 Line 2024-11-21 6.5 Medium
The leakage of channel access token in platinum clinic Line 13.6.1 allows remote attackers to send malicious notifications to victims.
CVE-2023-47366 1 Linecorp 1 Line 2024-11-21 6.5 Medium
The leakage of channel access token in craft_members Line 13.6.1 allows remote attackers to send malicious notifications to victims.
CVE-2023-47365 1 Linecorp 1 Line 2024-11-21 6.5 Medium
The leakage of channel access token in Lil.OFF-PRICE STORE Line 13.6.1 allows remote attackers to send malicious notifications to victims.
CVE-2023-47363 1 Linecorp 1 Line 2024-11-21 6.5 Medium
The leakage of channel access token in F.B.P members Line 13.6.1 allows remote attackers to send malicious notifications to victims.
CVE-2023-47347 1 Free5gc 1 Free5gc 2024-11-21 7.5 High
Buffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP messages whose Sequence Number is mutated to overflow bytes.
CVE-2023-47346 1 Free5gc 3 Free5gc, Smf, Upf 2024-11-21 7.5 High
Buffer Overflow vulnerability in free5gc 3.3.0, UPF 1.2.0, and SMF 1.2.0 allows attackers to cause a denial of service via crafted PFCP messages.
CVE-2023-47345 1 Free5gc 1 Free5gc 2024-11-21 7.5 High
Buffer Overflow vulnerability in free5gc 3.3.0 allows attackers to cause a denial of service via crafted PFCP message with malformed PFCP Heartbeat message whose Recovery Time Stamp IE length is mutated to zero.
CVE-2023-47326 1 Silverpeas 1 Silverpeas 2024-11-21 8.8 High
Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) via the Domain SQL Create function.
CVE-2023-47324 1 Silverpeas 1 Silverpeas 2024-11-21 5.4 Medium
Silverpeas Core 6.3.1 is vulnerable to Cross Site Scripting (XSS) via the message/notification feature.
CVE-2023-47323 1 Silverpeas 1 Silverpeas 2024-11-21 7.5 High
The notification/messaging feature of Silverpeas Core 6.3.1 does not enforce access control on the ID parameter. This allows an attacker to read all messages sent between other users; including those sent only to administrators.
CVE-2023-47322 1 Silverpeas 1 Silverpeas 2024-11-21 8.8 High
The "userModify" feature of Silverpeas Core 6.3.1 is vulnerable to Cross Site Request Forgery (CSRF) leading to privilege escalation. If an administrator goes to a malicious URL while being authenticated to the Silverpeas application, the CSRF with execute making the attacker an administrator user in the application.