Search Results (400884 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-26263 2 Ebm Technologies, Ebmtech 2 Risweb, Risweb 2025-01-23 5.3 Medium
EBM Technologies RISWEB's specific URL path is not properly controlled by permission, allowing attackers to browse specific pages and query sensitive data without login.
CVE-2024-25983 2 Fedoraproject, Moodle 2 Fedora, Moodle 2025-01-23 3.5 Low
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).
CVE-2023-6881 1 Zephyrproject 1 Zephyr 2025-01-23 7.3 High
Possible buffer overflow in is_mount_point
CVE-2023-4538 1 Comarch 1 Erp Xl 2025-01-23 6.2 Medium
The database access credentials configured during installation are stored in a special table, and are encrypted with a shared key, same among all Comarch ERP XL client installations. This could allow an attacker with access to that table to retrieve plain text passwords. This issue affects ERP XL: from 2020.2.2 through 2023.2.
CVE-2023-4539 1 Comarch 1 Erp Xl 2025-01-23 7.5 High
Use of a hard-coded password for a special database account created during Comarch ERP XL installation allows an attacker to retrieve embedded sensitive data stored in the database. The password is same among all Comarch ERP XL installations. This issue affects ERP XL: from 2020.2.2 through 2023.2.
CVE-2024-57770 1 Jfinaloa Project 1 Jfinaloa 2025-01-23 8.8 High
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component apply/save#oaContractApply.id.
CVE-2024-57769 1 Jfinaloa Project 1 Jfinaloa 2025-01-23 8.8 High
JFinalOA before v2025.01.01 was discovered to contain a SQL injection vulnerability via the component borrowmoney/listData?applyUser.
CVE-2023-31679 1 Videogo Project 1 Videogo 2025-01-23 7.5 High
Incorrect access control in Videogo v6.8.1 allows attackers to access images from other devices via modification of the Device Id parameter.
CVE-2023-31678 1 Videogo Project 1 Videogo 2025-01-23 5.3 Medium
Incorrect access control in Videogo v6.8.1 allows attackers to bind shared devices after the connection has been ended.
CVE-2023-31677 1 Luowice 1 Luowice 2025-01-23 7.5 High
Insecure permissions in luowice 3.5.18 allow attackers to view information for other alarm devices via modification of the eseeid parameter.
CVE-2023-31613 1 Openlinksw 1 Virtuoso 2025-01-23 7.5 High
An issue in the __nss_database_lookup component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2023-31612 1 Openlinksw 1 Virtuoso 2025-01-23 7.5 High
An issue in the dfe_qexp_list component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2023-31611 1 Openlinksw 1 Virtuoso 2025-01-23 7.5 High
An issue in the __libc_longjmp component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2023-31610 1 Openlinksw 1 Virtuoso 2025-01-23 7.5 High
An issue in the _IO_default_xsputn component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2023-31609 1 Openlinksw 1 Virtuoso 2025-01-23 7.5 High
An issue in the dfe_unit_col_loci component of openlink virtuoso-opensource v7.2.9 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
CVE-2023-31576 1 S9y 1 Serendipity 2025-01-23 8.8 High
An arbitrary file upload vulnerability in Serendipity 2.4-beta1 allows attackers to execute arbitrary code via a crafted HTML or Javascript file.
CVE-2023-30189 1 Posthemes 1 Posstaticblocks 2025-01-23 9.8 Critical
Prestashop posstaticblocks <= 1.0.0 is vulnerable to SQL Injection via posstaticblocks::getPosCurrentHook().
CVE-2023-29961 1 Dlink 2 Dir-605l, Dir-605l Firmware 2025-01-23 9.8 Critical
D-Link DIR-605L firmware version 1.17B01 BETA is vulnerable to stack overflow via /goform/formTcpipSetup,
CVE-2023-29927 1 Sage 1 Sage 300 2025-01-23 4.3 Medium
Versions of Sage 300 through 2022 implement role-based access controls that are only enforced client-side. Low-privileged Sage users, particularly those on a workstation setup in the "Windows Peer-to-Peer Network" or "Client Server Network" Sage 300 configurations, could recover the SQL connection strings being used by Sage 300 and interact directly with the underlying database(s) to create, update, and delete all company records, bypassing the program’s role-based access controls.
CVE-2023-28078 1 Dell 1 Smartfabric Os10 2025-01-23 9.1 Critical
Dell OS10 Networking Switches running 10.5.2.x and above contain a vulnerability with zeroMQ when VLT is configured. A remote unauthenticated attacker could potentially exploit this vulnerability leading to information disclosure and a possible Denial of Service when a huge number of requests are sent to the switch. This is a high severity vulnerability as it allows an attacker to view sensitive data. Dell recommends customers to upgrade at the earliest opportunity.