Search Results (35283 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-47126 1 Typo3 1 Typo3 2024-11-21 3.7 Low
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions the login screen of the standalone install tool discloses the full path of the transient data directory (e.g. /var/www/html/var/transient/). This applies to composer-based scenarios only - “classic” non-composer installations are not affected. This issue has been addressed in version 12.4.8. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVE-2023-47110 1 Prestashop 1 Customer Reassurance Block 2024-11-21 9.1 Critical
blockreassurance adds an information block aimed at offering helpful information to reassure customers that their store is trustworthy. An ajax function in module blockreassurance allows modifying any value in the configuration table. This vulnerability has been patched in version 5.1.4.
CVE-2023-47109 1 Prestashop 1 Customer Reassurance Block 2024-11-21 5.5 Medium
PrestaShop blockreassurance adds an information block aimed at offering helpful information to reassure customers that the store is trustworthy. When adding a block in blockreassurance module, a BO user can modify the http request and give the path of any file in the project instead of an image. When deleting the block from the BO, the file will be deleted. It is possible to make the website completely unavailable by removing index.php for example. This issue has been patched in version 5.1.4.
CVE-2023-47101 1 Securepoint 1 Openvpn-client 2024-11-21 7.8 High
The installer (aka openvpn-client-installer) in Securepoint SSL VPN Client before 2.0.40 allows local privilege escalation during installation or repair.
CVE-2023-47093 1 Stormshield 1 Stormshield Network Security 2024-11-21 6.5 Medium
An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.21, 4.4.0 through 4.6.8, and 4.7.0. Sending a crafted ICMP packet may lead to a crash of the ASQ engine.
CVE-2023-46980 1 Mayurik 1 Best Courier Management System 2024-11-21 9.8 Critical
An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to the userID parameter.
CVE-2023-46958 1 Lmxcms 1 Lmxcms 2024-11-21 9.8 Critical
An issue in lmxcms v.1.41 allows a remote attacker to execute arbitrary code via a crafted script to the admin.php file.
CVE-2023-46944 1 Gitkraken 1 Gitlens 2024-11-21 7.8 High
An issue in GitKraken GitLens before v.14.0.0 allows an attacker to execute arbitrary code via a crafted file to the Visual Studio Codes workspace trust component.
CVE-2023-46930 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
GPAC 2.3-DEV-rev605-gfc9e29089-master contains a SEGV in gpac/MP4Box in gf_isom_find_od_id_for_track /afltest/gpac/src/isomedia/media_odf.c:522:14.
CVE-2023-46928 1 Gpac 1 Gpac 2024-11-21 5.5 Medium
GPAC 2.3-DEV-rev605-gfc9e29089-master contains a SEGV in gpac/MP4Box in gf_media_change_pl /afltest/gpac/src/media_tools/isom_tools.c:3293:42.
CVE-2023-46916 1 Maximawatches 2 Maxima Max Pro Power, Maxima Max Pro Power Firmware 2024-11-21 4.3 Medium
Maxima Max Pro Power 1.0 486A devices allow BLE traffic replay. An attacker can use GATT characteristic handle 0x0012 to perform potentially disruptive actions such as starting a Heart Rate monitor.
CVE-2023-46771 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
Security vulnerability in the face unlock module. Successful exploitation of this vulnerability may affect service confidentiality.
CVE-2023-46764 1 Huawei 2 Emui, Harmonyos 2024-11-21 5.3 Medium
Unauthorized startup vulnerability of background apps. Successful exploitation of this vulnerability may cause background apps to start maliciously.
CVE-2023-46763 1 Huawei 2 Emui, Harmonyos 2024-11-21 5.3 Medium
Vulnerability of background app permission management in the framework module. Successful exploitation of this vulnerability may cause background apps to start maliciously.
CVE-2023-46757 1 Huawei 1 Harmonyos 2024-11-21 7.5 High
The remote PIN module has a vulnerability that causes incorrect information storage locations.Successful exploitation of this vulnerability may affect confidentiality.
CVE-2023-46755 1 Huawei 2 Emui, Harmonyos 2024-11-21 5.3 Medium
Vulnerability of input parameters being not strictly verified in the input. Successful exploitation of this vulnerability may cause the launcher to restart.
CVE-2023-46723 1 Pajip 1 Lte-pic32-writer 2024-11-21 8.9 High
lte-pic32-writer is a writer for PIC32 devices. In versions 0.0.1 and prior, those who use `sendto.txt` are vulnerable to attackers who known the IMEI reading the sendto.txt. The sendto.txt file can contain the SNS(such as slack and zulip) URL and API key. As of time of publication, a patch is not yet available. As workarounds, avoid using `sendto.txt` or use `.htaccess` to block access to `sendto.txt`.
CVE-2023-46666 1 Elastic 1 Elastic Sharepoint Online Python Connector 2024-11-21 5.3 Medium
An issue was discovered when using Document Level Security and the SPO "Limited Access" functionality in Elastic Sharepoint Online Python Connector. If a user is assigned limited access permissions to an item on a Sharepoint site then that user would have read permissions to all content on the Sharepoint site through Elasticsearch.
CVE-2023-46510 1 Zioncom 2 A7000r, A7000r Firmware 2024-11-21 9.8 Critical
An issue in ZIONCOM (Hong Kong) Technology Limited A7000R v.4.1cu.4154 allows an attacker to execute arbitrary code via the cig-bin/cstecgi.cgi to the settings/setPasswordCfg function.
CVE-2023-46509 1 Contec 2 Solarview Compact, Solarview Compact Firmware 2024-11-21 9.8 Critical
An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.