Search Results (374385 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-37759 1 Trendylogics 1 Crypto Currency Tracker 2024-11-21 9.8 Critical
Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticated attackers to register as an Admin account via a crafted POST request.
CVE-2023-37758 2 D-link, Dlink 3 Dir-815, Dir-815, Dir-815 Firmware 2024-11-21 7.5 High
D-LINK DIR-815 v1.01 was discovered to contain a buffer overflow via the component /web/captcha.cgi.
CVE-2023-37756 1 I-doit 1 I-doit 2024-11-21 9.8 Critical
I-doit pro 25 and below and I-doit open 25 and below employ weak password requirements for Administrator account creation. Attackers are able to easily guess users' passwords via a bruteforce attack.
CVE-2023-37755 1 I-doit 1 I-doit 2024-11-21 9.8 Critical
i-doit pro 25 and below and I-doit open 25 and below are configured with insecure default administrator credentials, and there is no warning or prompt to ask users to change the default password and account name. Unauthenticated attackers can exploit this vulnerability to obtain Administrator privileges, resulting in them being able to perform arbitrary system operations or cause a Denial of Service (DoS).
CVE-2023-37754 1 Powerjob 1 Powerjob 2024-11-21 9.8 Critical
PowerJob v4.3.3 was discovered to contain a remote command execution (RCE) vulnerability via the instanceId parameter at /instance/detail.
CVE-2023-37748 1 Miniupnp Project 1 Ngiflib 2024-11-21 5.5 Medium
ngiflib commit 5e7292 was discovered to contain an infinite loop via the function DecodeGifImg at ngiflib.c.
CVE-2023-37746 1 Phpgurukul 1 Maid Hiring Management System 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability in Maid Hiring Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title parameter of the /admin/contactus.php component.
CVE-2023-37745 1 Phpgurukul 1 Maid Hiring Management System 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability in Maid Hiring Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Page Description of the /admin/aboutus.php component.
CVE-2023-37744 1 Phpgurukul 1 Maid Hiring Management System 2024-11-21 6.1 Medium
Maid Hiring Management System v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/search-booking-request.php.
CVE-2023-37743 1 Phpgurukul 1 Teacher Subject Allocation System 2024-11-21 6.1 Medium
A cross-site scripting (XSS) vulnerability in Teacher Subject Allocation System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Search text box.
CVE-2023-37742 1 Webboss 1 Webboss.io Cms 2024-11-21 6.1 Medium
WebBoss.io CMS before v3.7.0.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability.
CVE-2023-37739 1 I-doit 1 I-doit 2024-11-21 6.5 Medium
i-doit Pro v25 and below was discovered to be vulnerable to path traversal.
CVE-2023-37734 1 Ezsoftmagic 1 Mp3 Audio Converter 2024-11-21 9.8 Critical
EZ softmagic MP3 Audio Converter 2.7.3.700 was discovered to contain a buffer overflow.
CVE-2023-37733 1 Tduckcloud 1 Tduck-platform 2024-11-21 6.1 Medium
An arbitrary file upload vulnerability in tduck-platform v4.0 allows attackers to execute arbitrary code via a crafted HTML file.
CVE-2023-37732 1 Yasm Project 1 Yasm 2024-11-21 5.5 Medium
Yasm v1.3.0.78 was found prone to NULL Pointer Dereference in /libyasm/intnum.c and /elf/elf.c, which allows the attacker to cause a denial of service via a crafted file.
CVE-2023-37723 1 Tenda 10 4g300, 4g300 Firmware, F1202 and 7 more 2024-11-21 9.8 Critical
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromqossetting.
CVE-2023-37722 1 Tenda 6 4g300, 4g300 Firmware, F1202 and 3 more 2024-11-21 9.8 Critical
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromSafeUrlFilter.
CVE-2023-37721 1 Tenda 10 4g300, 4g300 Firmware, F1202 and 7 more 2024-11-21 9.8 Critical
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromSafeMacFilter.
CVE-2023-37719 1 Tenda 8 F1202, F1202 Firmware, Fh1202 and 5 more 2024-11-21 9.8 Critical
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromP2pListFilter.
CVE-2023-37718 1 Tenda 6 4g300, 4g300 Firmware, F1202 and 3 more 2024-11-21 9.8 Critical
Tenda F1202 V1.0BR_V1.2.0.20(408), FH1202_V1.2.0.19_EN were discovered to contain a stack overflow in the page parameter in the function fromSafeClientFilter.