Search Results (94564 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-41658 1 I13websolution 1 Web Solution Photo Gallery Slideshow \& Masonry Tiled Gallery 2024-11-21 7.1 High
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Photo Gallery Slideshow & Masonry Tiled Gallery plugin <= 1.0.13 versions.
CVE-2023-41653 1 Bearthemes 1 Sermon\'e - Sermons Online 2024-11-21 7.1 High
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Beplus Sermon'e – Sermons Online plugin <= 1.0.0 versions.
CVE-2023-41640 1 Grupposcai 1 Realgimm 2024-11-21 8.8 High
An improper error handling vulnerability in the component ErroreNonGestito.aspx of GruppoSCAI RealGimm 1.1.37p38 allows attackers to obtain sensitive technical information via a crafted SQL query.
CVE-2023-41638 1 Grupposcai 1 Realgimm 2024-11-21 8.8 High
An arbitrary file upload vulnerability in the Gestione Documentale module of GruppoSCAI RealGimm 1.1.37p38 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2023-41631 1 Esst 1 Esst Monitoring 2024-11-21 8.8 High
eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the file upload function.
CVE-2023-41629 1 Esst 1 Esst Monitoring 2024-11-21 7.5 High
A lack of input sanitizing in the file download feature of eSST Monitoring v2.147.1 allows attackers to execute a path traversal.
CVE-2023-41628 1 O-ran-sc 1 E2 2024-11-21 7.5 High
An issue in O-RAN Software Community E2 G-Release allows attackers to cause a Denial of Service (DoS) by incorrectly initiating the messaging procedure between the E2Node and E2Term components.
CVE-2023-41627 1 O-ran-sc 1 Ric Message Router 2024-11-21 7.5 High
O-RAN Software Community ric-plt-lib-rmr v4.9.0 does not validate the source of the routing tables it receives, potentially allowing attackers to send forged routing tables to the device.
CVE-2023-41623 1 Emlog 1 Emlog 2024-11-21 7.2 High
Emlog version pro2.1.14 was discovered to contain a SQL injection vulnerability via the uid parameter at /admin/media.php.
CVE-2023-41613 2 Ezviz, Microsoft 2 Ezviz Studio, Windows 2024-11-21 7.8 High
EzViz Studio v2.2.0 is vulnerable to DLL hijacking.
CVE-2023-41595 1 Vaxilu 1 X-ui 2024-11-21 7.5 High
An issue in xui-xray v1.8.3 allows attackers to obtain sensitive information via default password.
CVE-2023-41594 1 Phpgurukul 1 Dairy Farm Shop Management System 2024-11-21 7.5 High
Dairy Farm Shop Management System Using PHP and MySQL v1.1 was discovered to contain multiple SQL injection vulnerabilities in the Login function via the Username and Password parameters.
CVE-2023-41580 1 Phpipam 1 Phpipam 2024-11-21 7.5 High
Phpipam before v1.5.2 was discovered to contain a LDAP injection vulnerability via the dname parameter at /users/ad-search-result.php. This vulnerability allows attackers to enumerate arbitrary fields in the LDAP server and access sensitive data via a crafted POST request.
CVE-2023-41578 1 Jeecg 1 Jeecg Boot 2024-11-21 7.5 High
Jeecg boot up to v3.5.3 was discovered to contain an arbitrary file read vulnerability via the interface /testConnection.
CVE-2023-41539 1 Phpjabbers 1 Business Directory Script 2024-11-21 7.5 High
phpjabbers Business Directory Script 3.2 is vulnerable to SQL Injection via the column parameter.
CVE-2023-41484 1 Cimg 1 Cimg 2024-11-21 8.1 High
An issue in cimg.eu Cimg Library v2.9.3 allows an attacker to obtain sensitive information via a crafted JPEG file.
CVE-2023-41452 1 Phpkobo 1 Ajaxnewsticker 2024-11-21 8.8 High
Cross Site Request Forgery vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the txt parameter in the index.php component.
CVE-2023-41450 1 Phpkobo 1 Ajaxnewsticker 2024-11-21 8.8 High
An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter.
CVE-2023-41444 2 Binalyze, Microsoft 2 Irec, Windows 2024-11-21 7.8 High
An issue in Binalyze IREC.sys v.3.11.0 and before allows a local attacker to execute arbitrary code and escalate privileges via the fun_1400084d0 function in IREC.sys driver.
CVE-2023-41443 1 Xxyopen 1 Novel-plus 2024-11-21 7.2 High
SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /sys/menu/list.