Search Results (357798 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-4929 1 Oretnom23 1 Simple Online Bidding System 2024-12-09 4.3 Medium
A vulnerability classified as problematic has been found in SourceCodester Simple Online Bidding System 1.0. This affects an unknown part of the file /simple-online-bidding-system/admin/ajax.php?action=save_user. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-264465 was assigned to this vulnerability.
CVE-2024-4928 1 Oretnom23 1 Simple Online Bidding System 2024-12-09 6.3 Medium
A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /simple-online-bidding-system/admin/ajax.php?action=delete_category. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-264464.
CVE-2024-4927 1 Oretnom23 1 Simple Online Bidding System 2024-12-09 7.3 High
A vulnerability was found in SourceCodester Simple Online Bidding System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /simple-online-bidding-system/admin/ajax.php?action=save_product. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264463.
CVE-2024-2077 1 Oretnom23 1 Simple Online Bidding System 2024-12-09 6.3 Medium
A vulnerability classified as critical has been found in SourceCodester Simple Online Bidding System 1.0. This affects an unknown part of the file index.php. The manipulation of the argument category_id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-255393 was assigned to this vulnerability.
CVE-2023-34563 1 Netgear 2 R6250, R6250 Firmware 2024-12-09 9.8 Critical
netgear R6250 Firmware Version 1.0.4.48 is vulnerable to Buffer Overflow after authentication.
CVE-2023-34541 1 Langchain 1 Langchain 2024-12-09 9.8 Critical
Langchain 0.0.171 is vulnerable to Arbitrary code execution in load_prompt.
CVE-2023-33495 1 Craftcms 1 Craft Cms 2024-12-09 6.1 Medium
Craft CMS through 4.4.9 is vulnerable to HTML Injection.
CVE-2020-21489 1 Feehi 1 Feehicms 2024-12-09 9.8 Critical
File Upload vulnerability in Feehicms v.2.0.8 allows a remote attacker to execute arbitrary code via the /admin/index.php?r=admin-user%2Fupdate-self component.
CVE-2020-21486 1 Phpok 1 Phpok 2024-12-09 7.5 High
SQL injection vulnerability in PHPOK v.5.4. allows a remote attacker to obtain sensitive information via the _userlist function in framerwork/phpok_call.php file.
CVE-2020-21485 1 Alluxio 1 Alluxio 2024-12-09 6.1 Medium
Cross Site Scripting vulnerability in Alluxio v.1.8.1 allows a remote attacker to executea arbitrary code via the path parameter in the browse board component.
CVE-2020-21325 1 Wuzhicms 1 Wuzhicms 2024-12-09 8.8 High
An issue in WUZHI CMS v.4.1.0 allows a remote attacker to execute arbitrary code via the set_chache method of the function\common.func.php file.
CVE-2020-21268 1 Easycorp 1 Zentao 2024-12-09 6.1 Medium
Cross Site Scripting vulnerability in EasySoft ZenTao v.11.6.4 allows a remote attacker to execute arbitrary code via the lastComment parameter.
CVE-2023-42959 1 Apple 1 Macos 2024-12-09 7.0 High
A race condition was addressed with improved state handling. This issue is fixed in macOS Sonoma 14. An app may be able to execute arbitrary code with kernel privileges.
CVE-2023-42918 1 Apple 1 Macos 2024-12-09 8.6 High
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14. A sandboxed process may be able to circumvent sandbox restrictions.
CVE-2023-2805 1 Supportcandy 1 Supportcandy 2024-12-09 7.2 High
The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the agents[] parameter in the set_add_agent_leaves AJAX function before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
CVE-2023-34596 1 Aeotech 2 Zw130-a, Zw130-a Firmware 2024-12-09 6.5 Medium
A vulnerability in Aeotec WallMote Switch firmware v2.3 allows attackers to cause a Denial of Service (DoS) via a crafted Z-Wave message.
CVE-2023-2812 1 Ultimate Dashboard Project 1 Ultimate Dashboard 2024-12-09 4.8 Medium
The Ultimate Dashboard WordPress plugin before 3.7.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVE-2023-34461 1 Pybb Project 1 Pybb 2024-12-09 4.6 Medium
PyBB is an open source bulletin board. A manual code review of the PyBB bulletin board server has revealed that a vulnerability could have been exploited in which users could submit any type of HTML tag, and have said tag run. For example, a malicious `<a>` that looks like ```<a href=javascript:alert (1)>xss</a>``` could have been used to run code through JavaScript on the client side. The problem has been patched as of commit `5defd92`, and users are advised to upgrade. Attackers do need posting privilege in order to exploit this vulnerability. This vulnerability is present within the 0.1.0 release, and users are advised to upgrade to 0.1.1. Users unable to upgrade may be able to work around the attack by either; Removing the ability to create posts, removing the `|safe` tag from the Jinja2 template titled "post.html" in templates or by adding manual validation of links in the post creation section.
CVE-2023-29158 1 Subnet 1 Powersystem Center 2024-12-09 6.1 Medium
SUBNET PowerSYSTEM Center versions 2020 U10 and prior are vulnerable to replay attacks which may result in a denial-of-service condition or a loss of data integrity.
CVE-2023-32659 1 Subnet 1 Powersystem Center 2024-12-09 6.5 Medium
SUBNET PowerSYSTEM Center versions 2020 U10 and prior contain a cross-site scripting vulnerability that may allow an attacker to inject malicious code into report header graphic files that could propagate out of the system and reach users who are subscribed to email notifications.