Search Results (357816 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-43301 1 Linecorp 1 Line 2024-11-21 8.2 High
An issue in DARTS SHOP MAXIM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
CVE-2023-43300 1 Linecorp 1 Line 2024-11-21 8.2 High
An issue in urban_project mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
CVE-2023-43299 1 Linecorp 1 Line 2024-11-21 5.3 Medium
An issue in DA BUTCHERS mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
CVE-2023-43297 1 Linecorp 1 Line 2024-11-21 5.4 Medium
An issue in animal-art-lab v13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.
CVE-2023-43295 1 Clickstudios 1 Passwordstate 2024-11-21 3.5 Low
Cross Site Request Forgery vulnerability in Click Studios (SA) Pty Ltd Passwordstate v.Build 9785 and before allows a local attacker to execute arbitrary code via a crafted request.
CVE-2023-43291 1 Emlog 1 Emlog 2024-11-21 9.8 Critical
Deserialization of Untrusted Data in emlog pro v.2.1.15 and earlier allows a remote attacker to execute arbitrary code via the cache.php component.
CVE-2023-43284 1 Dlink 2 Dir-846, Dir-846 Firmware 2024-11-21 8.8 High
D-Link Wireless MU-MIMO Gigabit AC1200 Router DIR-846 100A53DBR-Retail devices allow an authenticated remote attacker to execute arbitrary code via an unspecified manipulation of the QoS POST parameter.
CVE-2023-43281 1 Nothings 1 Stb Image.h 2024-11-21 6.5 Medium
Double Free vulnerability in Nothings Stb Image.h v.2.28 allows a remote attacker to cause a denial of service via a crafted file to the stbi_load_gif_main function.
CVE-2023-43278 1 Seacms 1 Seacms 2024-11-21 8.8 High
A Cross-Site Request Forgery (CSRF) in admin_manager.php of Seacms up to v12.8 allows attackers to arbitrarily add an admin account.
CVE-2023-43275 1 Dedecms 1 Dedecms 2024-11-21 8.8 High
Cross-Site Request Forgery (CSRF) vulnerability in DedeCMS v5.7 in 110 backend management interface via /catalog_add.php, allows attackers to create crafted web pages due to a lack of verification of the token value of the submitted form.
CVE-2023-43274 1 Phpjabbers 1 Php Shopping Cart 2024-11-21 7.5 High
Phpjabbers PHP Shopping Cart 4.2 is vulnerable to SQL Injection via the id parameter.
CVE-2023-43271 1 70mai 2 A500s, A500s Firmware 2024-11-21 9.1 Critical
Incorrect access control in 70mai a500s v1.2.119 allows attackers to directly access and delete the video files of the driving recorder through ftp and other protocols.
CVE-2023-43270 1 Dst-admin Project 1 Dst-admin 2024-11-21 9.8 Critical
dst-admin v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the userId parameter at /home/playerOperate.
CVE-2023-43269 1 Pigcms 1 Pigcms 2024-11-21 9.8 Critical
pigcms up to 7.0 was discovered to contain an arbitrary file upload vulnerability.
CVE-2023-43268 1 Deyue Remote Vehicle Management System Project 1 Deyue Remote Vehicle Management System 2024-11-21 8.8 High
Deyue Remote Vehicle Management System v1.1 was discovered to contain a deserialization vulnerability.
CVE-2023-43267 1 Emlog 1 Emlog 2024-11-21 5.4 Medium
A cross-site scripting (XSS) vulnerability in the publish article function of emlog pro v2.1.14 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title field.
CVE-2023-43263 1 Froala 1 Froala Editor 2024-11-21 6.1 Medium
A Cross-site scripting (XSS) vulnerability in Froala Editor v.4.1.1 allows attackers to execute arbitrary code via the Markdown component.
CVE-2023-43260 1 Milesight 15 Ur32, Ur32 Firmware, Ur32l and 12 more 2024-11-21 6.1 Medium
Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the admin panel.
CVE-2023-43256 1 Gladysassistant 1 Gladys Assistant 2024-11-21 6.5 Medium
A path traversal in Gladys Assistant v4.26.1 and below allows authenticated attackers to extract sensitive files in the host machine by exploiting a non-sanitized user input.
CVE-2023-43252 1 Xnview 1 Nconvert 2024-11-21 7.8 High
XNSoft Nconvert 7.136 is vulnerable to Buffer Overflow via a crafted image file.