Search Results (357848 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-41613 2 Ezviz, Microsoft 2 Ezviz Studio, Windows 2024-11-21 7.8 High
EzViz Studio v2.2.0 is vulnerable to DLL hijacking.
CVE-2023-41609 1 Couchcms 1 Couchcms 2024-11-21 6.1 Medium
An open redirect vulnerability in the sanitize_url() parameter of CouchCMS v2.3 allows attackers to redirect a victim user to an arbitrary web site via a crafted URL.
CVE-2023-41601 1 Cszcms 1 Csz Cms 2024-11-21 6.1 Medium
Multiple cross-site scripting (XSS) vulnerabilities in install/index.php of CSZ CMS v1.3.0 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Database Username or Database Host parameters.
CVE-2023-41599 1 Jfinalcms Project 1 Jfinalcms 2024-11-21 5.3 Medium
An issue in the component /common/DownController.java of JFinalCMS v5.0.0 allows attackers to execute a directory traversal.
CVE-2023-41597 1 Eyoucms 1 Eyoucms 2024-11-21 6.1 Medium
EyouCms v1.6.2 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the component /admin/twitter.php?active_t.
CVE-2023-41595 1 Vaxilu 1 X-ui 2024-11-21 7.5 High
An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password.
CVE-2023-41594 1 Phpgurukul 1 Dairy Farm Shop Management System 2024-11-21 7.5 High
Dairy Farm Shop Management System Using PHP and MySQL v1.1 was discovered to contain multiple SQL injection vulnerabilities in the Login function via the Username and Password parameters.
CVE-2023-41593 1 Phpgurukul 1 Dairy Farm Shop Management System 2024-11-21 5.4 Medium
Multiple cross-site scripting (XSS) vulnerabilities in Dairy Farm Shop Management System Using PHP and MySQL v1.1 allow attackers to execute arbitrary web scripts and HTML via a crafted payload injected into the Category and Category Field parameters.
CVE-2023-41592 1 Froala 1 Froala Editor 2024-11-21 5.4 Medium
Froala Editor v4.0.1 to v4.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability.
CVE-2023-41588 1 Appfire 1 Time To Sla 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability in Time to SLA plugin v10.13.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the durationFormat parameter.
CVE-2023-41580 1 Phpipam 1 Phpipam 2024-11-21 7.5 High
Phpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability via the dname parameter at /users/ad-search-result.php. This vulnerability allows attackers to enumerate arbitrary fields in the LDAP server and access sensitive data via a crafted POST request.
CVE-2023-41578 1 Jeecg 1 Jeecg Boot 2024-11-21 7.5 High
Jeecg boot up to v3.5.3 was discovered to contain an arbitrary file read vulnerability via the interface /testConnection.
CVE-2023-41575 1 Phpgurukul 1 Blood Bank \& Donor Management System 2024-11-21 5.4 Medium
Multiple stored cross-site scripting (XSS) vulnerabilities in /bbdms/sign-up.php of Blood Bank & Donor Management v2.2 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Full Name, Message, or Address parameters.
CVE-2023-41570 1 Mikrotik 1 Routeros 2024-11-21 5.3 Medium
MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API.
CVE-2023-41564 1 Agentejo 1 Cockpit 2024-11-21 6.1 Medium
An arbitrary file upload vulnerability in the Upload Asset function of Cockpit CMS v2.6.3 allows attackers to execute arbitrary code via uploading a crafted .shtml file.
CVE-2023-41563 1 Tenda 4 Ac5, Ac5 Firmware, Ac9 and 1 more 2024-11-21 9.8 Critical
Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter mac at url /goform/GetParentControlInfo.
CVE-2023-41562 1 Tenda 6 Ac5, Ac5 Firmware, Ac7 and 3 more 2024-11-21 9.8 Critical
Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter time at url /goform/PowerSaveSet.
CVE-2023-41561 1 Tenda 4 Ac5, Ac5 Firmware, Ac9 and 1 more 2024-11-21 9.8 Critical
Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter startIp and endIp at url /goform/SetPptpServerCfg.
CVE-2023-41560 1 Tenda 2 Ac9, Ac9 Firmware 2024-11-21 9.8 Critical
Tenda AC9 V3.0 V15.03.06.42_multi was discovered to contain a stack overflow via parameter firewallEn at url /goform/SetFirewallCfg.
CVE-2023-41559 1 Tenda 6 Ac5, Ac5 Firmware, Ac7 and 3 more 2024-11-21 9.8 Critical
Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_multi, and Tenda AC5 V1.0RTL_V15.03.06.28 were discovered to contain a stack overflow via parameter page at url /goform/NatStaticSetting.