Search Results (97876 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-37243 2 Atera, Microsoft 2 Agent Package Availability, Windows 2024-11-21 7.8 High
The C:\Windows\Temp\Agent.Package.Availability\Agent.Package.Availability.exe file is automatically launched as SYSTEM when the system reboots. Since the C:\Windows\Temp\Agent.Package.Availability folder inherits permissions from C:\Windows\Temp and Agent.Package.Availability.exe is susceptible to DLL hijacking, standard users can write a malicious DLL to it and elevate their privileges.
CVE-2023-37241 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
Input verification vulnerability in the WMS API. Successful exploitation of this vulnerability may cause the device to restart.
CVE-2023-37239 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
Format string vulnerability in the distributed file system. Attackers who bypass the selinux permission can exploit this vulnerability to crash the program.
CVE-2023-37221 1 7-twenty 1 Bot 2024-11-21 8.8 High
7Twenty BOT - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
CVE-2023-37220 1 Synel 43 Bioentry-w2, Bioentry-w2 Firmware, Bioentry P2 and 40 more 2024-11-21 7.2 High
Synel Terminals - CWE-494: Download of Code Without Integrity Check
CVE-2023-37219 1 Tadirantele 1 Aeonix 2024-11-21 7.3 High
Tadiran Telecom Composit - CWE-1236: Improper Neutralization of Formula Elements in a CSV File
CVE-2023-37218 1 Tadirantele 1 Aeonix 2024-11-21 7.5 High
Tadiran Telecom Aeonix - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2023-37216 1 Anasystem 2 Sensmini M4, Sensmini M4 Firmware 2024-11-21 7.5 High
AnaSystem SensMini M4 – Using the configuration tool, an authenticated user can cause Denial of Service for the device
CVE-2023-37213 1 Synel 3 Synergy\/a, Synergy\/a Firmware, Synergy Fingerprint Terminals 2024-11-21 8.8 High
Synel SYnergy Fingerprint Terminals - CWE-78: 'OS Command Injection'
CVE-2023-37208 3 Debian, Mozilla, Redhat 9 Debian Linux, Firefox, Firefox Esr and 6 more 2024-11-21 7.8 High
When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
CVE-2023-37197 1 Schneider-electric 1 Struxureware Data Center Expert 2024-11-21 8.8 High
A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, change, or delete content, or perform unauthorized actions when tampering with the mass configuration settings of endpoints on DCE.
CVE-2023-37196 1 Schneider-electric 1 Struxureware Data Center Expert 2024-11-21 8.8 High
A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, change, or delete content, or perform unauthorized actions when tampering with the alert settings of endpoints on DCE.
CVE-2023-37192 1 Bitcoin 1 Bitcoin Core 2024-11-21 7.5 High
Memory management and protection issues in Bitcoin Core v22 allows attackers to modify the stored sending address within the app's memory, potentially allowing them to redirect Bitcoin transactions to wallets of their own choosing.
CVE-2023-36992 1 Travianz Project 1 Travianz 2024-11-21 7.2 High
PHP injection in TravianZ 8.3.4 and 8.3.3 in the config editor in the admin page allows remote attackers to execute PHP code.
CVE-2023-36984 1 Lavalite 1 Lavalite 2024-11-21 7.5 High
LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure.
CVE-2023-36983 1 Lavalite 1 Lavalite 2024-11-21 7.5 High
LavaLite CMS v 9.0.0 is vulnerable to Sensitive Data Exposure.
CVE-2023-36969 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 8.8 High
CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.
CVE-2023-36968 1 Food Ordering System Project 1 Food Ordering System 2024-11-21 7.2 High
A SQL Injection vulnerability detected in Food Ordering System v1.0 allows attackers to run commands on the database by sending crafted SQL queries to the ID parameter.
CVE-2023-36950 1 Totolink 4 A7000r, A7000r Firmware, X5000r and 1 more 2024-11-21 8.8 High
TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.
CVE-2023-36947 1 Totolink 4 A7000r, A7000r Firmware, X5000r and 1 more 2024-11-21 8.8 High
TOTOLINK X5000R V9.1.0u.6118_B20201102 and TOTOLINK A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow via the File parameter in the function UploadCustomModule.