Search Results (357862 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-41552 1 Tenda 4 Ac7, Ac7 Firmware, Ac9 and 1 more 2024-11-21 9.8 Critical
Tenda AC7 V1.0 V15.03.06.44 and Tenda AC9 V3.0 V15.03.06.42_multi were discovered to contain a stack overflow via parameter ssid at url /goform/fast_setting_wifi_set.
CVE-2023-41544 1 Jeecg 1 Jeecg Boot 2024-11-21 9.8 Critical
SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport/loadTableData component.
CVE-2023-41543 1 Jeecg 1 Jeecg Boot 2024-11-21 9.8 Critical
SQL injection vulnerability in jeecg-boot v3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the component /sys/replicate/check.
CVE-2023-41542 1 Jeecg 1 Jeecg Boot 2024-11-21 9.8 Critical
SQL injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to escalate privileges and obtain sensitive information via the jmreport/qurestSql component.
CVE-2023-41539 1 Phpjabbers 1 Business Directory Script 2024-11-21 7.5 High
phpjabbers Business Directory Script 3.2 is vulnerable to SQL Injection via the column parameter.
CVE-2023-41538 1 Phpjabbers 1 Php Forum Script 2024-11-21 6.1 Medium
phpjabbers PHP Forum Script 3.0 is vulnerable to Cross Site Scripting (XSS) via the keyword parameter.
CVE-2023-41508 1 Superstorefinder 1 Super Store Finder 2024-11-21 9.8 Critical
A hard coded password in Super Store Finder v3.6 allows attackers to access the administration panel.
CVE-2023-41507 1 Superstorefinder 1 Super Store Finder 2024-11-21 9.8 Critical
Super Store Finder v3.6 was discovered to contain multiple SQL injection vulnerabilities in the store locator component via the products, distance, lat, and lng parameters.
CVE-2023-41484 1 Cimg 1 Cimg 2024-11-21 8.1 High
An issue in cimg.eu Cimg Library v2.9.3 allows an attacker to obtain sensitive information via a crafted JPEG file.
CVE-2023-41453 1 Phpkobo 1 Ajaxnewsticker 2024-11-21 6.1 Medium
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the cmd parameter in the index.php component.
CVE-2023-41452 1 Phpkobo 1 Ajaxnewsticker 2024-11-21 8.8 High
Cross Site Request Forgery vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the txt parameter in the index.php component.
CVE-2023-41451 1 Phpkobo 1 Ajaxnewsticker 2024-11-21 6.1 Medium
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the txt parameter in the index.php component.
CVE-2023-41450 1 Phpkobo 1 Ajaxnewsticker 2024-11-21 8.8 High
An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter.
CVE-2023-41449 1 Phpkobo 1 Ajaxnewsticker 2024-11-21 9.8 Critical
An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter.
CVE-2023-41448 1 Phpkobo 1 Ajaxnewsticker 2024-11-21 6.1 Medium
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the ID parameter in the index.php component.
CVE-2023-41447 1 Phpkobo 1 Ajaxnewsticker 2024-11-21 6.1 Medium
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the subcmd parameter in the index.php component.
CVE-2023-41446 1 Phpkobo 1 Ajaxnewsticker 2024-11-21 6.1 Medium
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted script to the title parameter in the index.php component.
CVE-2023-41445 1 Phpkobo 1 Ajaxnewsticker 2024-11-21 6.1 Medium
Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the index.php component.
CVE-2023-41444 2 Binalyze, Microsoft 2 Irec, Windows 2024-11-21 7.8 High
An issue in Binalyze IREC.sys v.3.11.0 and before allows a local attacker to execute arbitrary code and escalate privileges via the fun_1400084d0 function in IREC.sys driver.
CVE-2023-41443 1 Xxyopen 1 Novel-plus 2024-11-21 7.2 High
SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /sys/menu/list.