Search Results (357827 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-42494 1 Busbaer 1 Eisbaer Scada 2024-11-21 7.5 High
EisBaer Scada - CWE-749: Exposed Dangerous Method or Function
CVE-2023-42493 1 Busbaer 1 Eisbaer Scada 2024-11-21 7.1 High
EisBaer Scada - CWE-256: Plaintext Storage of a Password
CVE-2023-42492 1 Busbaer 1 Eisbaer Scada 2024-11-21 7.1 High
EisBaer Scada - CWE-321: Use of Hard-coded Cryptographic Key
CVE-2023-42491 1 Busbaer 1 Eisbaer Scada 2024-11-21 8.8 High
EisBaer Scada - CWE-285: Improper Authorization
CVE-2023-42490 1 Busbaer 1 Eisbaer Scada 2024-11-21 7.5 High
EisBaer Scada - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CVE-2023-42489 1 Busbaer 1 Eisbaer Scada 2024-11-21 7.5 High
EisBaer Scada - CWE-732: Incorrect Permission Assignment for Critical Resource
CVE-2023-42488 1 Busbaer 1 Eisbaer Scada 2024-11-21 7.5 High
EisBaer Scada - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-42487 1 Soundminer 1 Soundminer 2024-11-21 7.5 High
Soundminer – CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-42486 1 Fortect 1 Fortect 2024-11-21 6.3 Medium
Fortect - CWE-428: Unquoted Search Path or Element, may be used by local user to elevate privileges.
CVE-2023-42483 1 Samsung 14 Exynos 1080, Exynos 1080 Firmware, Exynos 1280 and 11 more 2024-11-21 6.3 Medium
A TOCTOU race condition in Samsung Mobile Processor Exynos 9820, Exynos 980, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, and Exynos 1380 can cause unexpected termination of a system.
CVE-2023-42482 1 Samsung 2 Exynos 2200, Exynos 2200 Firmware 2024-11-21 4.7 Medium
Samsung Mobile Processor Exynos 2200 allows a GPU Use After Free.
CVE-2023-42481 1 Sap 1 Commerce Cloud 2024-11-21 8.1 High
In SAP Commerce Cloud - versions HY_COM 1905, HY_COM 2005, HY_COM2105, HY_COM 2011, HY_COM 2205, COM_CLOUD 2211, a locked B2B user can misuse the forgotten password functionality to un-block his user account again and re-gain access if SAP Commerce Cloud - Composable Storefront is used as storefront, due to weak access controls in place. This leads to a considerable impact on confidentiality and integrity.
CVE-2023-42480 1 Sap 1 Netweaver Application Server Java 2024-11-21 5.3 Medium
The unauthenticated attacker in NetWeaver AS Java Logon application - version 7.50, can brute force the login functionality to identify the legitimate user ids. This will have an impact on confidentiality but there is no other impact on integrity or availability.
CVE-2023-42478 1 Sap 1 Business Objects Business Intelligence Platform 2024-11-21 7.5 High
SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to upload agnostic documents in the system which when opened by any other user could lead to high impact on integrity of the application.
CVE-2023-42477 1 Sap 1 Netweaver Application Server Java 2024-11-21 6.5 Medium
SAP NetWeaver AS Java (GRMG Heartbeat application) - version 7.50, allows an attacker to send a crafted request from a vulnerable web application, causing limited impact on confidentiality and integrity of the application.
CVE-2023-42476 1 Sap 1 Businessobjects Web Intelligence 2024-11-21 6.8 Medium
SAP Business Objects Web Intelligence - version 420, allows an authenticated attacker to inject JavaScript code into Web Intelligence documents which is then executed in the victim’s browser each time the vulnerable page is visited. Successful exploitation can lead to exposure of the data that the user has access to. In the worst case, attacker could access data from reporting databases.
CVE-2023-42475 1 Sap 1 S\/4hana 2024-11-21 4.3 Medium
The Statutory Reporting application has a vulnerable file storage location, potentially enabling low privileged attacker to read server files with minimal impact on confidentiality.
CVE-2023-42474 1 Sap 1 Businessobjects Web Intelligence 2024-11-21 6.8 Medium
SAP BusinessObjects Web Intelligence - version 420, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to a user that would possibly allow an attacker to retrieve the sensitive information.
CVE-2023-42472 1 Sap 1 Businessobjects Business Intelligence Platform 2024-11-21 8.7 High
Due to insufficient file type validation, SAP BusinessObjects Business Intelligence Platform (Web Intelligence HTML interface) - version 420, allows a report creator to upload files from local system into the report over the network. When uploading the image file, an authenticated attacker could intercept the request, modify the content type and the extension to read and modify sensitive data causing a high impact on confidentiality and integrity of the application.
CVE-2023-42471 1 Wave-ai 1 Wave 2024-11-21 9.8 Critical
The wave.ai.browser application through 1.0.35 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. It contains a manifest entry that exports the wave.ai.browser.ui.splash.SplashScreen activity. This activity uses a WebView component to display web content and doesn't adequately validate or sanitize the URI or any extra data passed in the intent by a third party application (with no permissions).