Search Results (30614 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-34865 2 Linux, Ujcms 2 Linux Kernel, Ujcms 2025-01-03 9.8 Critical
Directory traversal vulnerability in ujcms 6.0.2 allows attackers to move files via the rename feature.
CVE-2022-36331 1 Westerndigital 24 My Cloud, My Cloud Dl2100, My Cloud Dl2100 Firmware and 21 more 2025-01-03 10 Critical
Western Digital My Cloud, My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices were vulnerable to an impersonation attack that could allow an unauthenticated attacker to gain access to user data. This issue affects My Cloud OS 5 devices: before 5.25.132; My Cloud Home and My Cloud Home Duo: before 8.13.1-102; SanDisk ibi: before 8.13.1-102.
CVE-2023-38429 1 Linux 1 Linux Kernel 2025-01-03 9.8 Critical
An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/connection.c in ksmbd has an off-by-one error in memory allocation (because of ksmbd_smb2_check_message) that may lead to out-of-bounds access.
CVE-2017-18017 9 Arista, Canonical, Debian and 6 more 33 Eos, Ubuntu Linux, Debian Linux and 30 more 2025-01-03 9.8 Critical
The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other impact by leveraging the presence of xt_TCPMSS in an iptables action.
CVE-2023-34944 1 Chamilo 1 Chamilo Lms 2025-01-03 9.8 Critical
An arbitrary file upload vulnerability in the /fileUpload.lib.php component of Chamilo 1.11.* up to v1.11.18 allows attackers to execute arbitrary code via uploading a crafted SVG file.
CVE-2023-3224 1 Nuxt 1 Nuxt 2025-01-03 9.8 Critical
Code Injection in GitHub repository nuxt/nuxt prior to 3.5.3.
CVE-2023-29129 1 Mendix 1 Saml 2025-01-03 9.1 Critical
A vulnerability has been identified in Mendix SAML (Mendix 7 compatible) (All versions >= V1.17.3 < V1.18.0), Mendix SAML (Mendix 7 compatible) (All versions >= V1.16.4 < V1.17.3), Mendix SAML (Mendix 8 compatible) (All versions >= V2.3.0 < V2.4.0), Mendix SAML (Mendix 8 compatible) (All versions >= V2.2.0 < V2.3.0), Mendix SAML (Mendix 9 latest compatible, New Track) (All versions >= V3.3.1 < V3.6.1), Mendix SAML (Mendix 9 latest compatible, New Track) (All versions >= V3.1.9 < V3.3.1), Mendix SAML (Mendix 9 latest compatible, Upgrade Track) (All versions >= V3.3.0 < V3.6.0), Mendix SAML (Mendix 9 latest compatible, Upgrade Track) (All versions >= V3.1.8 < V3.3.0), Mendix SAML (Mendix 9.12/9.18 compatible, New Track) (All versions >= V3.3.1 < V3.3.15), Mendix SAML (Mendix 9.12/9.18 compatible, Upgrade Track) (All versions >= V3.3.0 < V3.3.14), Mendix SAML (Mendix 9.6 compatible, New Track) (All versions >= V3.1.9 < V3.2.7), Mendix SAML (Mendix 9.6 compatible, Upgrade Track) (All versions >= V3.1.8 < V3.2.6). The affected versions of the module insufficiently verify the SAML assertions. This could allow unauthenticated remote attackers to bypass authentication and get access to the application. This CVE entry describes the incomplete fix for CVE-2023-25957 in a specific non default configuration.
CVE-2022-37968 1 Microsoft 3 Azure Arc-enabled Kubernetes, Azure Stack Edge, Edge 2025-01-02 10 Critical
Microsoft has identified a vulnerability affecting the cluster connect feature of Azure Arc-enabled Kubernetes clusters. This vulnerability could allow an unauthenticated user to elevate their privileges and potentially gain administrative control over the Kubernetes cluster. Additionally, because Azure Stack Edge allows customers to deploy Kubernetes workloads on their devices via Azure Arc, Azure Stack Edge devices are also vulnerable to this vulnerability.
CVE-2023-34754 2 Apple, Bloofox 2 Macos, Bloofoxcms 2025-01-02 9.8 Critical
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the pid parameter at admin/index.php?mode=settings&page=plugins&action=edit.
CVE-2023-34753 2 Apple, Bloofox 2 Macos, Bloofoxcms 2025-01-02 9.8 Critical
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the tid parameter at admin/index.php?mode=settings&page=tmpl&action=edit.
CVE-2023-34752 2 Apple, Bloofox 2 Macos, Bloofoxcms 2025-01-02 9.8 Critical
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the lid parameter at admin/index.php?mode=settings&page=lang&action=edit.
CVE-2023-34751 2 Apple, Bloofox 2 Macos, Bloofoxcms 2025-01-02 9.8 Critical
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the gid parameter at admin/index.php?mode=user&page=groups&action=edit.
CVE-2023-34750 2 Apple, Bloofox 2 Macos, Bloofoxcms 2025-01-02 9.8 Critical
bloofox v0.5.2.1 was discovered to contain a SQL injection vulnerability via the cid parameter at admin/index.php?mode=settings&page=projects&action=edit.
CVE-2022-35744 1 Microsoft 23 Windows 10 1507, Windows 10 1607, Windows 10 1809 and 20 more 2025-01-02 9.8 Critical
Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
CVE-2022-33649 1 Microsoft 1 Edge Chromium 2025-01-02 9.6 Critical
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
CVE-2022-30133 1 Microsoft 20 Windows 10, Windows 10 1507, Windows 10 1607 and 17 more 2025-01-02 9.8 Critical
Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
CVE-2022-30136 1 Microsoft 4 Windows Server 2012, Windows Server 2012 R2, Windows Server 2016 and 1 more 2025-01-02 9.8 Critical
Windows Network File System Remote Code Execution Vulnerability
CVE-2022-29130 1 Microsoft 23 Windows 10, Windows 10 1507, Windows 10 1607 and 20 more 2025-01-02 9.8 Critical
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
CVE-2022-26937 1 Microsoft 10 Windows Server, Windows Server 2008, Windows Server 2008 R2 and 7 more 2025-01-02 9.8 Critical
Windows Network File System Remote Code Execution Vulnerability
CVE-2022-22012 1 Microsoft 22 Windows 10, Windows 10 1507, Windows 10 1607 and 19 more 2025-01-02 9.8 Critical
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability