Search Results (85272 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-46998 1 Bootboxjs 1 Bootbox 2024-11-21 6.1 Medium
Cross Site Scripting vulnerability in BootBox Bootbox.js v.3.2 through 6.0 allows a remote attacker to execute arbitrary code via a crafted payload to alert(), confirm(), prompt() functions.
CVE-2023-46993 1 Totolink 2 A3300r, A3300r Firmware 2024-11-21 9.8 Critical
In TOTOLINK A3300R V17.0.0cu.557_B20221024 when dealing with setLedCfg request, there is no verification for the enable parameter, which can lead to command injection.
CVE-2023-46979 1 Totolink 2 X6000r, X6000r Firmware 2024-11-21 9.8 Critical
TOTOLINK X6000R V9.4.0cu.852_B20230719 was discovered to contain a command injection vulnerability via the enable parameter in the setLedCfg function.
CVE-2023-46977 1 Totolink 2 Lr1200gb, Lr1200gb Firmware 2024-11-21 9.8 Critical
TOTOLINK LR1200GB V9.1.0u.6619_B20230130 was discovered to contain a stack overflow via the password parameter in the function loginAuth.
CVE-2023-46976 1 Totolink 2 A3300r, A3300r Firmware 2024-11-21 9.8 Critical
TOTOLINK A3300R 17.0.0cu.557_B20221024 contains a command injection via the file_name parameter in the UploadFirmwareFile function.
CVE-2023-46974 1 Mayurik 1 Courier Management System 2024-11-21 5.4 Medium
Cross Site Scripting vulnerability in Best Courier Management System v.1.000 allows a remote attacker to execute arbitrary code via a crafted payload to the page parameter in the URL.
CVE-2023-46964 2 Hillstone, Hillstonenet 3 Next Generation Firewall Sg-6000-e3960, Sc-6000-e3960, Sc-6000-e3960 Firmware 2024-11-21 6.1 Medium
Cross Site Scripting (XSS) vulnerability in Hillstone Next Generation FireWall SG-6000-e3960 v.5.5 allows a remote attacker to execute arbitrary code via the use front-end filtering instead of back-end filtering.
CVE-2023-46943 1 Evershop 1 Evershop 2024-11-21 9.1 Critical
An issue was discovered in NPM's package @evershop/evershop before version 1.0.0-rc.8. The HMAC secret used for generating tokens is hardcoded as "secret". A weak HMAC secret poses a risk because attackers can use the predictable secret to create valid JSON Web Tokens (JWTs), allowing them access to important information and actions within the application.
CVE-2023-46935 1 Eyoucms 1 Eyoucms 2024-11-21 5.4 Medium
eyoucms v1.6.4 is vulnerable Cross Site Scripting (XSS), which can lead to stealing sensitive information of logged-in users.
CVE-2023-46931 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
GPAC 2.3-DEV-rev605-gfc9e29089-master contains a heap-buffer-overflow in ffdmx_parse_side_data /afltest/gpac/src/filters/ff_dmx.c:202:14 in gpac/MP4Box.
CVE-2023-46930 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
GPAC 2.3-DEV-rev605-gfc9e29089-master contains a SEGV in gpac/MP4Box in gf_isom_find_od_id_for_track /afltest/gpac/src/isomedia/media_odf.c:522:14.
CVE-2023-46928 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
GPAC 2.3-DEV-rev605-gfc9e29089-master contains a SEGV in gpac/MP4Box in gf_media_change_pl /afltest/gpac/src/media_tools/isom_tools.c:3293:42.
CVE-2023-46927 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
GPAC 2.3-DEV-rev605-gfc9e29089-master contains a heap-buffer-overflow in gf_isom_use_compact_size gpac/src/isomedia/isom_write.c:3403:3 in gpac/MP4Box.
CVE-2023-46925 1 Reportico 1 Reportico 2024-11-21 4.8 Medium
Reportico 7.1.21 is vulnerable to Cross Site Scripting (XSS).
CVE-2023-46918 1 Fedirtsapana 1 Simple Http Server Plus 2024-11-21 4.6 Medium
Phlox com.phlox.simpleserver.plus (aka Simple HTTP Server PLUS) 1.8.1-plus has an Android manifest file that contains an entry with the android:allowBackup attribute set to true. This could be leveraged by an attacker with physical access to the device.
CVE-2023-46911 1 Jspxcms 1 Jspxcms 2024-11-21 6.1 Medium
There is a Cross Site Scripting (XSS) vulnerability in the choose_style_tree.do interface of Jspxcms v10.2.0 backend.
CVE-2023-46866 1 Color 1 Demoiccmax 2024-11-21 6.5 Medium
In International Color Consortium DemoIccMAX 79ecb74, CIccCLUT::Interp3d in IccProfLib/IccTagLut.cpp in libSampleICC.a attempts to access array elements at out-of-bounds indexes.
CVE-2023-46858 1 Moodle 1 Moodle 2024-11-21 5.4 Medium
Moodle 4.3 allows /grade/report/grader/index.php?searchvalue= reflected XSS when logged in as a teacher. NOTE: the Moodle Security FAQ link states "Some forms of rich content [are] used by teachers to enhance their courses ... admins and teachers can post XSS-capable content, but students can not."
CVE-2023-46857 1 Squidex.io 1 Squidex 2024-11-21 5.4 Medium
Squidex before 7.9.0 allows XSS via an SVG document to the Upload Assets feature. This occurs because there is an incomplete blacklist in the SVG inspection, allowing JavaScript in the SRC attribute of an IFRAME element. An authenticated attack with assets.create permission is required for exploitation.
CVE-2023-46854 1 Proxmox 1 Proxmox-widget-toolkit 2024-11-21 5.4 Medium
Proxmox proxmox-widget-toolkit before 4.0.9, as used in multiple Proxmox products, allows XSS via the edit notes feature.