Search Results (374375 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-37650 1 Agentejo 1 Cockpit 2024-11-21 8.8 High
A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows attackers to execute arbitrary Administrator commands.
CVE-2023-37649 1 Agentejo 1 Cockpit 2024-11-21 7.5 High
Incorrect access control in the component /models/Content of Cockpit CMS v2.5.2 allows unauthorized attackers to access sensitive data.
CVE-2023-37647 1 Sem-cms 1 Semcms 2024-11-21 9.8 Critical
SEMCMS v1.5 was discovered to contain a SQL injection vulnerability via the id parameter at /Ant_Suxin.php.
CVE-2023-37646 1 Bitberry 1 File Opener 2024-11-21 7.8 High
An issue in the CAB file extraction function of Bitberry File Opener v23.0 allows attackers to execute a directory traversal.
CVE-2023-37645 1 Eyoucms 1 Eyoucms 2024-11-21 5.3 Medium
eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.
CVE-2023-37636 1 Webkul 1 Uvdesk 2024-11-21 5.4 Medium
A stored cross-site scripting (XSS) vulnerability in UVDesk Community Skeleton v1.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Message field when creating a ticket.
CVE-2023-37635 1 Uvdesk 1 Community-skeleton 2024-11-21 9.8 Critical
UVDesk Community Skeleton v1.1.1 allows unauthenticated attackers to perform brute force attacks on the login page to gain access to the application.
CVE-2023-37630 1 Simple Online Piggery Management System Project 1 Simple Online Piggery Management System 2024-11-21 6.1 Medium
Online Piggery Management System 1.0 is vulnerable to Cross Site Scripting (XSS). An unauthenticated user can POST JavaScript code to "manage-breed.php" resulting in Persistent XSS.
CVE-2023-37629 1 Simple Online Piggery Management System Project 1 Simple Online Piggery Management System 2024-11-21 9.8 Critical
Online Piggery Management System 1.0 is vulnerable to File Upload. An unauthenticated user can upload a php file by sending a POST request to "add-pig.php."
CVE-2023-37628 1 Simple Online Piggery Management System Project 1 Simple Online Piggery Management System 2024-11-21 9.8 Critical
Online Piggery Management System 1.0 is vulnerable to SQL Injection.
CVE-2023-37627 1 Code-projects 1 Online Restaurant Management System 2024-11-21 9.8 Critical
Code-projects Online Restaurant Management System 1.0 is vulnerable to SQL Injection. Through SQL injection, an attacker can bypass the admin panel and view order records, add items, delete items etc.
CVE-2023-37625 1 Netbox 1 Netbox 2024-11-21 5.4 Medium
A stored cross-site scripting (XSS) vulnerability in Netbox v3.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Link templates.
CVE-2023-37624 1 Netdisco 1 Netdisco 2024-11-21 6.1 Medium
Netdisco before v2.063000 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.
CVE-2023-37623 1 Netdisco 1 Netdisco 2024-11-21 4.8 Medium
Netdisco before v2.063000 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /Web/TypeAhead.pm.
CVE-2023-37613 1 Assemblysoftware 1 Trialworks 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability in Assembly Software Trialworks v11.4 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the asset src parameter.
CVE-2023-37611 1 Neos 1 Neos Cms 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) vulnerability in Neos CMS 8.3.3 allows a remote authenticated attacker to execute arbitrary code via a crafted SVG file to the neos/management/media component.
CVE-2023-37605 1 Baramundi 1 Enterprise Mobility Management 2024-11-21 5.5 Medium
Weak Exception Handling vulnerability in baramundi software GmbH EMM Agent 23.1.50 and before allows an attacker to cause a denial of service via a crafted request to the password parameter.
CVE-2023-37602 1 Alkacon 1 Opencms 2024-11-21 6.1 Medium
An arbitrary file upload vulnerability in the component /workplace#!explorer of Alkacon OpenCMS v15.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.
CVE-2023-37601 1 Mobisystems 1 Office Suite 2024-11-21 7.5 High
Office Suite Premium v10.9.1.42602 was discovered to contain a local file inclusion (LFI) vulnerability via the component /etc/hosts.
CVE-2023-37600 1 Mobisystems 1 Office Suite 2024-11-21 6.1 Medium
Office Suite Premium Version v10.9.1.42602 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /api?path=profile.