Search Results (357868 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-33592 1 Oretnom23 1 Lost And Found Information System 2024-11-27 9.8 Critical
Lost and Found Information System v1.0 was discovered to contain a SQL injection vulnerability via the component /php-lfis/admin/?page=system_info/contact_information.
CVE-2023-33661 1 Churchcrm 1 Churchcrm 2024-11-27 6.1 Medium
Multiple cross-site scripting (XSS) vulnerabilities were discovered in Church CRM v4.5.3 in GroupReports.php via GroupRole, ReportModel, and OnlyCart parameters.
CVE-2023-34647 1 Phpgurukul 1 Hostel Management System 2024-11-27 6.1 Medium
PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-34833 1 Thinkadmin 1 Thinkadmin 2024-11-27 6.1 Medium
An arbitrary file upload vulnerability in the component /api/upload.php of ThinkAdmin v6 allows attackers to execute arbitrary code via a crafted file.
CVE-2023-34650 1 Small Crm Project 1 Small Crm 2024-11-27 6.1 Medium
PHPgurukl Small CRM v.1.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-34651 1 Hospital Management System Project 1 Hospital Management System 2024-11-27 6.1 Medium
PHPgurukl Hospital Management System v.1.0 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-34652 1 Phpgurukul 1 Hostel Management System 2024-11-27 6.1 Medium
PHPgurukl Hostel Management System v.1.0 is vulnerable to Cross Site Scripting (XSS) via Add New Course.
CVE-2023-23163 1 Phpgurukul 1 Art Gallery Management System 2024-11-27 9.8 Critical
Art Gallery Management System Project v1.0 was discovered to contain a SQL injection vulnerability via the editid parameter.
CVE-2022-48328 1 Misp 1 Misp 2024-11-27 9.8 Critical
app/Controller/Component/IndexFilterComponent.php in MISP before 2.4.167 mishandles ordered_url_params and additional_delimiters.
CVE-2023-34738 1 Chemex 1 Chemex 2024-11-27 9.8 Critical
Chemex through 3.7.1 is vulnerable to arbitrary file upload.
CVE-2022-46395 1 Arm 4 Avalon Gpu Kernel Driver, Bifrost Gpu Kernel Driver, Midgard Gpu Kernel Driver and 1 more 2024-11-27 8.8 High
An issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access to already freed memory. This affects Midgard r0p0 through r32p0, Bifrost r0p0 through r41p0 before r42p0, Valhall r19p0 through r41p0 before r42p0, and Avalon r41p0 before r42p0.
CVE-2023-24734 1 Sigb 1 Pmb 2024-11-27 9.8 Critical
An arbitrary file upload vulnerability in the camera_upload.php component of PMB v7.4.6 allows attackers to execute arbitrary code via a crafted image file.
CVE-2023-25304 1 Prismlauncher 1 Prism Launcher 2024-11-27 7.8 High
An issue in Prism Launcher up to v6.1 allows attackers to perform a directory traversal via importing a crafted .mrpack file.
CVE-2023-34843 1 Traggo 1 Traggo 2024-11-27 7.5 High
Traggo Server 0.3.0 is vulnerable to directory traversal via a crafted GET request.
CVE-2022-27665 1 Progress 1 Ws Ftp Server 2024-11-27 6.1 Medium
Reflected XSS (via AngularJS sandbox escape expressions) exists in Progress Ipswitch WS_FTP Server 8.6.0. This can lead to execution of malicious code and commands on the client due to improper handling of user-provided input. By inputting malicious payloads in the subdirectory searchbar or Add folder filename boxes, it is possible to execute client-side commands. For example, there is Client-Side Template Injection via subFolderPath to the ThinClient/WtmApiService.asmx/GetFileSubTree URI.
CVE-2023-32623 1 2inc 1 Snow Monkey Forms 2024-11-27 9.1 Critical
Directory traversal vulnerability in Snow Monkey Forms v5.1.1 and earlier allows a remote unauthenticated attacker to delete arbitrary files on the server.
CVE-2023-26134 1 Git-commit-info Project 1 Git-commit-info 2024-11-27 9.8 Critical
Versions of the package git-commit-info before 2.0.2 are vulnerable to Command Injection such that the package-exported method gitCommitInfo () fails to sanitize its parameter commit, which later flows into a sensitive command execution API. As a result, attackers may inject malicious commands once they control the hash content.
CVE-2023-36475 1 Parseplatform 1 Parse-server 2024-11-27 9.8 Critical
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 5.5.2 and 6.2.1, an attacker can use a prototype pollution sink to trigger a remote code execution through the MongoDB BSON parser. A patch is available in versions 5.5.2 and 6.2.1.
CVE-2020-26708 1 Requests-xml Project 1 Requests-xml 2024-11-27 7.5 High
requests-xml v0.2.3 was discovered to contain an XML External Entity Injection (XXE) vulnerability which allows attackers to execute arbitrary code via a crafted XML file.
CVE-2023-28473 1 Concretecms 1 Concrete Cms 2024-11-27 3.3 Low
Concrete CMS (previously concrete5) versions 8.5.12 and below, and 9.0 through 9.1.3 is vulnerable to possible Auth bypass in the jobs section.