Search Results (357868 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-40934 1 Nagios 1 Nagios Xi 2024-11-21 7.2 High
A SQL injection vulnerability in Nagios XI 5.11.1 and below allows authenticated attackers with privileges to manage host escalations in the Core Configuration Manager to execute arbitrary SQL commands via the host escalation notification settings.
CVE-2023-40933 1 Nagios 1 Nagios Xi 2024-11-21 8.8 High
A SQL injection vulnerability in Nagios XI v5.11.1 and below allows authenticated attackers with announcement banner configuration privileges to execute arbitrary SQL commands via the ID parameter sent to the update_banner_message() function.
CVE-2023-40932 1 Nagios 1 Nagios Xi 2024-11-21 5.4 Medium
A Cross-site scripting (XSS) vulnerability in Nagios XI version 5.11.1 and below allows authenticated attackers with access to the custom logo component to inject arbitrary javascript or HTML via the alt-text field. This affects all pages containing the navbar including the login page which means the attacker is able to to steal plaintext credentials.
CVE-2023-40931 1 Nagios 1 Nagios Xi 2024-11-21 6.5 Medium
A SQL injection vulnerability in Nagios XI from version 5.11.0 up to and including 5.11.1 allows authenticated attackers to execute arbitrary SQL commands via the ID parameter in the POST request to /nagiosxi/admin/banner_message-ajaxhelper.php
CVE-2023-40930 1 Skyworth 1 Skyworth Os 2024-11-21 6.8 Medium
An issue in the directory /system/bin/blkid of Skyworth v3.0 allows attackers to perform a directory traversal via mounting the Udisk to /mnt/.
CVE-2023-40924 2 Contec, Solar View 3 Solarview Compact, Solarview Compact Firmware, Compact 2024-11-21 7.5 High
SolarView Compact < 6.00 is vulnerable to Directory Traversal.
CVE-2023-40922 1 Kerawen 1 Kerawen 2024-11-21 9.8 Critical
kerawen before v2.5.1 was discovered to contain a SQL injection vulnerability via the ocs_id_cart parameter at KerawenDeliveryModuleFrontController::initContent().
CVE-2023-40921 1 Common-services 1 Soliberte 2024-11-21 9.8 Critical
SQL Injection vulnerability in functions/point_list.php in Common Services soliberte before v4.3.03 allows attackers to obtain sensitive information via the lat and lng parameters.
CVE-2023-40920 1 Prixan 1 Prixanconnect 2024-11-21 9.8 Critical
Prixan prixanconnect up to v1.62 was discovered to contain a SQL injection vulnerability via the component CartsGuruCatalogModuleFrontController::importProducts().
CVE-2023-40918 1 Knowstreaming Project 1 Knowstreaming 2024-11-21 8.8 High
KnowStreaming 3.3.0 is vulnerable to Escalation of Privileges. Unauthorized users can create a new user with an admin role.
CVE-2023-40915 1 Tenda 2 Ax3, Ax3 Firmware 2024-11-21 7.5 High
Tenda AX3 v16.03.12.11 has a stack buffer overflow vulnerability detected at function form_fast_setting_wifi_set. This vulnerability allows attackers to cause a Denial of Service (DoS) via the ssid parameter.
CVE-2023-40904 1 Tenda 2 Ac10v4, Ac10v4 Firmware 2024-11-21 9.8 Critical
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at /goform/setMacFilterCfg.
CVE-2023-40902 1 Tenda 2 Ac10v4, Ac10v4 Firmware 2024-11-21 9.8 Critical
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter list and bindnum at /goform/SetIpMacBind.
CVE-2023-40901 1 Tenda 3 Ac10, Ac10v4, Ac10v4 Firmware 2024-11-21 9.8 Critical
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at url /goform/setMacFilterCfg.
CVE-2023-40877 1 Dedecms 1 Dedecms 2024-11-21 5.4 Medium
DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_edit.php via the title parameter.
CVE-2023-40876 1 Dedecms 1 Dedecms 2024-11-21 5.4 Medium
DedeCMS up to and including 5.7.110 was discovered to contain a cross-site scripting (XSS) vulnerability at /dede/freelist_add.php via the title parameter.
CVE-2023-40875 1 Dedecms 1 Dedecms 2024-11-21 5.4 Medium
DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/vote_edit.php via the votename and votenote parameters.
CVE-2023-40874 1 Dedecms 1 Dedecms 2024-11-21 5.4 Medium
DedeCMS up to and including 5.7.110 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities at /dede/vote_add.php via the votename and voteitem1 parameters.
CVE-2023-40869 1 Moosocial 1 Moosocial 2024-11-21 6.1 Medium
Cross Site Scripting vulnerability in mooSocial mooSocial Software 3.1.6 and 3.1.7 allows a remote attacker to execute arbitrary code via a crafted script to the edit_menu, copuon, and group_categorias functions.
CVE-2023-40868 1 Moosocial 1 Moosocial 2024-11-21 8.8 High
Cross Site Request Forgery vulnerability in mooSocial MooSocial Software v.Demo allows a remote attacker to execute arbitrary code via the Delete Account and Deactivate functions.