Search Results (372400 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-25010 1 Autodesk 1 Maya Usd 2025-02-06 7.8 High
A malicious actor may convince a victim to open a malicious USD file that may trigger an uninitialized variable which may result in code execution.
CVE-2023-24503 1 Electra-air 1 Smart Kit For Split Ac 2025-02-06 7.5 High
Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW.
CVE-2023-24502 1 Electra-air 2 Central Ac Unit, Central Ac Unit Firmware 2025-02-06 7.5 High
Electra Central AC unit – The unit opens an AP with an easily calculated password.
CVE-2023-24500 1 Electra-air 2 Central Ac Unit, Central Ac Unit Firmware 2025-02-06 7.5 High
Electra Central AC unit – Adjacent attacker may cause the unit to load unauthorized FW.
CVE-2023-1473 1 Metaslider 1 Slider\, Gallery\, And Carousel 2025-02-06 6.1 Medium
The Slider, Gallery, and Carousel by MetaSlider WordPress plugin 3.29.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
CVE-2023-1427 1 10web 1 Photo Gallery 2025-02-06 4.9 Medium
- The Photo Gallery by 10Web WordPress plugin before 1.8.15 did not ensure that uploaded files are kept inside its uploads folder, allowing high privilege users to put images anywhere in the filesystem via a path traversal vector.
CVE-2023-1371 1 W4 Post List Project 1 W4 Post List 2025-02-06 6.5 Medium
The W4 Post List WordPress plugin before 2.4.6 does not ensure that password protected posts can be accessed before displaying their content, which could allow any authenticated users to access them
CVE-2023-1282 1 Codedropz 1 Drag And Drop Multiple File Upload - Contact Form 7 2025-02-06 6.1 Medium
The Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard WordPress plugin before 2.11.1 and Drag and Drop Multiple File Upload PRO - Contact Form 7 with Remote Storage Integrations WordPress plugin before 5.0.6.4 do not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high-privilege users such as admins.
CVE-2023-0889 1 Metagauss 1 Themeflection Numbers 2025-02-06 6.5 Medium
Themeflection Numbers WordPress plugin before 2.0.1 does not have authorisation and CSRF check in an AJAX action, and does not ensure that the options to be updated belong to the plugin. As a result, it could allow any authenticated users, such as subscriber, to update arbitrary blog options, such as enabling registration and set the default role to administrator
CVE-2023-0277 1 Wc Fields Factory Project 1 Wc Fields Factory 2025-02-06 7.2 High
The WC Fields Factory WordPress plugin through 4.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin
CVE-2022-47522 2 Ieee, Sonicwall 59 Ieee 802.11, Soho 250, Soho 250 Firmware and 56 more 2025-02-06 7.5 High
The IEEE 802.11 specifications through 802.11ax allow physically proximate attackers to intercept (possibly cleartext) target-destined frames by spoofing a target's MAC address, sending Power Save frames to the access point, and then sending other frames to the access point (such as authentication frames or re-association frames) to remove the target's original security context. This behavior occurs because the specifications do not require an access point to purge its transmit queue before removing a client's pairwise encryption key.
CVE-2022-46640 1 Nanoleaf 1 Nanoleaf Desktop 2025-02-06 9.8 Critical
Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request.
CVE-2022-45030 1 Rconfig 1 Rconfig 2025-02-06 8.8 High
A SQL injection vulnerability in rConfig 3.9.7 exists via lib/ajaxHandlers/ajaxCompareGetCmdDates.php?command= (this may interact with secure-file-priv).
CVE-2022-43696 1 Open-xchange 1 Ox App Suite 2025-02-06 6.1 Medium
OX App Suite before 7.10.6-rev20 allows XSS via upsell ads.
CVE-2022-2525 1 Janeczku 1 Calibre-web 2025-02-06 9.8 Critical
Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20.
CVE-2021-45464 1 Kvmtool Project 1 Kvmtool 2025-02-06 8.8 High
kvmtool through 39181fc allows an out-of-bounds write, related to virtio/balloon.c and virtio/pci.c. This allows a guest OS user to execute arbitrary code on the host machine.
CVE-2021-40507 1 Openrisc 2 Or1200, Or1200 Firmware 2025-02-06 9.8 Critical
An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The overflow flag is not being updated correctly for the subtract instruction, which results in an incorrect value in the overflow flag. Any software that relies on this flag may experience corruption in execution.
CVE-2021-40506 1 Openrisc 2 Or1200, Or1200 Firmware 2025-02-06 9.8 Critical
An issue was discovered in the ALU unit of the OR1200 (aka OpenRISC 1200) processor 2011-09-10 through 2015-11-11. The overflow flag is not being updated for the msb and mac instructions, which results in an incorrect value in the overflow flag. Any software that relies on this flag may experience corruption in execution.
CVE-2021-39295 1 Openbmc-project 1 Openbmc 2025-02-06 7.5 High
In OpenBMC 2.9, crafted IPMI messages allow an attacker to cause a denial of service to the BMC via the netipmid (IPMI lan+) interface.
CVE-2023-29511 1 Xwiki 1 Xwiki 2025-02-06 9.9 Critical
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit rights on a page (e.g., it's own user page), can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cause is improper escaping of the section ids in `XWiki.AdminFieldsDisplaySheet`. This page is installed by default. The vulnerability has been patched in XWiki versions 15.0-rc-1, 14.10.1, 14.4.8, and 13.10.11.