Search

Search Results (381470 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-41316 1 Tolgee 1 Tolgee 2024-11-21 5.5 Medium
Tolgee is an open-source localization platform. Due to lack of validation field - Org Name, bad actor can send emails with HTML injected code to the victims. Registered users can inject HTML into unsanitized emails from the Tolgee instance to other users. This unsanitized HTML ends up in invitation emails which appear as legitimate org invitations. Bad actors may direct users to malicious website or execute javascript in the context of the users browser. This vulnerability has been addressed in version 3.29.2. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVE-2023-41314 1 Apache 1 Doris 2024-11-21 8.2 High
The api /api/snapshot and /api/get_log_file would allow unauthenticated access. It could allow a DoS attack or get arbitrary files from FE node. Please upgrade to 2.0.3 to fix these issues.
CVE-2023-41312 1 Huawei 2 Emui, Harmonyos 2024-11-21 5.3 Medium
Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause several apps to be activated automatically.
CVE-2023-41311 1 Huawei 2 Emui, Harmonyos 2024-11-21 5.3 Medium
Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause an app to be activated automatically.
CVE-2023-41310 1 Huawei 2 Emui, Harmonyos 2024-11-21 3.3 Low
Keep-alive vulnerability in the sticky broadcast mechanism. Successful exploitation of this vulnerability may cause malicious apps to run continuously in the background.
CVE-2023-41309 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
Permission control vulnerability in the MediaPlaybackController module. Successful exploitation of this vulnerability may affect availability.
CVE-2023-41308 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
Screenshot vulnerability in the input module. Successful exploitation of this vulnerability may affect confidentiality.
CVE-2023-41307 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
Memory overwriting vulnerability in the security module. Successful exploitation of this vulnerability may affect availability.
CVE-2023-41306 1 Huawei 2 Emui, Harmonyos 2024-11-21 3.7 Low
Vulnerability of mutex management in the bone voice ID trusted application (TA) module. Successful exploitation of this vulnerability may cause the bone voice ID feature to be unavailable.
CVE-2023-41305 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
Vulnerability of 5G messages being sent without being encrypted in a VPN environment in the SMS message module. Successful exploitation of this vulnerability may affect confidentiality.
CVE-2023-41304 1 Huawei 2 Emui, Harmonyos 2024-11-21 5.3 Medium
Parameter verification vulnerability in the window module.Successful exploitation of this vulnerability may cause the size of an app window to be adjusted to that of a floating window.
CVE-2023-41303 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
Command injection vulnerability in the distributed file system module. Successful exploitation of this vulnerability may cause variables in the sock structure to be modified.
CVE-2023-41302 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
Redirection permission verification vulnerability in the home screen module. Successful exploitation of this vulnerability may cause features to perform abnormally.
CVE-2023-41301 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
Vulnerability of unauthorized API access in the PMS module. Successful exploitation of this vulnerability may cause features to perform abnormally.
CVE-2023-41300 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
Vulnerability of parameters not being strictly verified in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
CVE-2023-41299 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
CVE-2023-41298 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality.
CVE-2023-41297 1 Huawei 2 Emui, Harmonyos 2024-11-21 9.8 Critical
Vulnerability of defects introduced in the design process in the HiviewTunner module. Successful exploitation of this vulnerability may cause service hijacking.
CVE-2023-41296 1 Huawei 2 Emui, Harmonyos 2024-11-21 9.1 Critical
Vulnerability of missing authorization in the kernel module. Successful exploitation of this vulnerability may affect integrity and confidentiality.
CVE-2023-41295 1 Huawei 2 Emui, Harmonyos 2024-11-21 5.3 Medium
Vulnerability of improper permission management in the displayengine module. Successful exploitation of this vulnerability may cause the screen to turn dim.