Search Results (85173 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-37223 1 Archerirm 1 Archer 2024-11-21 5.4 Medium
Cross Site Scripting (XSS) vulnerability in Archer Platform before v.6.13 and fixed in v.6.12.0.6 and v.6.13.0 allows a remote authenticated attacker to execute arbitrary code via a crafted malicious script.
CVE-2023-37222 1 Farsight 1 Provide Server 2024-11-21 4.8 Medium
Farsight Tech Nordic AB ProVide version 14.5 - Multiple XSS vulnerabilities (CWE-79) can be exploited by a user with administrator privilege.
CVE-2023-37221 1 7-twenty 1 Bot 2024-11-21 8.8 High
7Twenty BOT - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
CVE-2023-37215 1 Jbl 2 Jbl Bar 5.1 Surround, Jbl Bar 5.1 Surround Firmware 2024-11-21 6.2 Medium
JBL soundbar multibeam 5.1 - CWE-798: Use of Hard-coded Credentials
CVE-2023-37214 1 Heights-t 2 Ero1xs-pro, Ero1xs-pro Firmware 2024-11-21 9.8 Critical
Heights Telecom ERO1xS-Pro Dual-Band FW version BZ_ERO1XP.025.
CVE-2023-37213 1 Synel 3 Synergy\/a, Synergy\/a Firmware, Synergy Fingerprint Terminals 2024-11-21 8.8 High
Synel SYnergy Fingerprint Terminals - CWE-78: 'OS Command Injection'
CVE-2023-37191 1 Issabel 1 Pbx 2024-11-21 4.8 Medium
A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Group and Description parameters.
CVE-2023-37190 1 Issabel 1 Pbx 2024-11-21 4.8 Medium
A stored cross-site scripting (XSS) vulnerability in Issabel issabel-pbx v.4.0.0-6 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Virtual Fax Name and Caller ID Name parameters under the New Virtual Fax feature.
CVE-2023-37189 1 Issabel 1 Pbx 2024-11-21 4.8 Medium
A stored cross site scripting (XSS) vulnerability in index.php?menu=billing_rates of Issabel PBX version 4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the Name or Prefix fields under the Create New Rate module.
CVE-2023-37174 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
GPAC v2.3-DEV-rev381-g817a848f6-master was discovered to contain a segmentation violation in the dump_isom_scene function at /mp4box/filedump.c.
CVE-2023-37173 1 Totolink 3 A3000ru, A3300r, A3300r Firmware 2024-11-21 9.8 Critical
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the command parameter in the setTracerouteCfg function.
CVE-2023-37172 1 Totolink 3 A3000ru, A3300r, A3300r Firmware 2024-11-21 9.8 Critical
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg function.
CVE-2023-37171 1 Totolink 2 A3300r, A3300r Firmware 2024-11-21 9.8 Critical
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the admuser parameter in the setPasswordCfg function.
CVE-2023-37170 1 Totolink 2 A3300r, A3300r Firmware 2024-11-21 9.8 Critical
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the lang parameter in the setLanguageCfg function.
CVE-2023-37164 1 Diafan 1 Diafan.cms 2024-11-21 6.1 Medium
Diafan CMS v6.0 was discovered to contain a reflected cross-site scripting via the cat_id parameter at /shop/?module=shop&action=search.
CVE-2023-37153 1 Kodcloud 1 Kodexplorer 2024-11-21 6.1 Medium
KodExplorer 4.51 contains a Cross-Site Scripting (XSS) vulnerability in the Description box of the Light App creation feature. An attacker can exploit this vulnerability by injecting XSS syntax into the Description field.
CVE-2023-37150 1 Online Pizza Ordering System Project 1 Online Pizza Ordering System 2024-11-21 6.1 Medium
Sourcecodester Online Pizza Ordering System v1.0 has a Cross-site scripting (XSS) vulnerability in "/admin/index.php?page=categories" Category item.
CVE-2023-37149 1 Totolink 2 Lr350, Lr350 Firmware 2024-11-21 9.8 Critical
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadSetting function.
CVE-2023-37148 1 Totolink 2 Lr350, Lr350 Firmware 2024-11-21 9.8 Critical
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the ussd parameter in the setUssd function.
CVE-2023-37146 1 Totolink 2 Lr350, Lr350 Firmware 2024-11-21 9.8 Critical
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.