Export limit exceeded: 35281 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (35281 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-41326 | 1 Glpi-project | 1 Glpi | 2024-11-21 | 8.1 High |
| GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. A logged user from any profile can hijack the Kanban feature to alter any user field, and end-up with stealing its account. Users are advised to upgrade to version 10.0.10. There are no known workarounds for this vulnerability. | ||||
| CVE-2023-41324 | 1 Glpi-project | 1 Glpi | 2024-11-21 | 8.1 High |
| GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. An API user that have read access on users resource can steal accounts of other users. Users are advised to upgrade to version 10.0.10. There are no known workarounds for this vulnerability. | ||||
| CVE-2023-41323 | 1 Glpi-project | 1 Glpi | 2024-11-21 | 5.3 Medium |
| GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. An unauthenticated user can enumerate users logins. Users are advised to upgrade to version 10.0.10. There are no known workarounds for this vulnerability. | ||||
| CVE-2023-41322 | 1 Glpi-project | 1 Glpi | 2024-11-21 | 4.9 Medium |
| GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. A user with write access to another user can make requests to change the latter's password and then take control of their account. Users are advised to upgrade to version 10.0.10. There are no known work around for this vulnerability. | ||||
| CVE-2023-41321 | 1 Glpi-project | 1 Glpi | 2024-11-21 | 4.9 Medium |
| GLPI stands for Gestionnaire Libre de Parc Informatique is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. An API user can enumerate sensitive fields values on resources on which he has read access. Users are advised to upgrade to version 10.0.10. There are no known workarounds for this vulnerability. | ||||
| CVE-2023-41312 | 1 Huawei | 2 Emui, Harmonyos | 2024-11-21 | 5.3 Medium |
| Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause several apps to be activated automatically. | ||||
| CVE-2023-41311 | 1 Huawei | 2 Emui, Harmonyos | 2024-11-21 | 5.3 Medium |
| Permission control vulnerability in the audio module. Successful exploitation of this vulnerability may cause an app to be activated automatically. | ||||
| CVE-2023-41309 | 1 Huawei | 2 Emui, Harmonyos | 2024-11-21 | 7.5 High |
| Permission control vulnerability in the MediaPlaybackController module. Successful exploitation of this vulnerability may affect availability. | ||||
| CVE-2023-41308 | 1 Huawei | 2 Emui, Harmonyos | 2024-11-21 | 7.5 High |
| Screenshot vulnerability in the input module. Successful exploitation of this vulnerability may affect confidentiality. | ||||
| CVE-2023-41302 | 1 Huawei | 2 Emui, Harmonyos | 2024-11-21 | 7.5 High |
| Redirection permission verification vulnerability in the home screen module. Successful exploitation of this vulnerability may cause features to perform abnormally. | ||||
| CVE-2023-41301 | 1 Huawei | 2 Emui, Harmonyos | 2024-11-21 | 7.5 High |
| Vulnerability of unauthorized API access in the PMS module. Successful exploitation of this vulnerability may cause features to perform abnormally. | ||||
| CVE-2023-41300 | 1 Huawei | 2 Emui, Harmonyos | 2024-11-21 | 7.5 High |
| Vulnerability of parameters not being strictly verified in the PMS module. Successful exploitation of this vulnerability may cause the system to restart. | ||||
| CVE-2023-41298 | 1 Huawei | 2 Emui, Harmonyos | 2024-11-21 | 7.5 High |
| Vulnerability of permission control in the window module. Successful exploitation of this vulnerability may affect confidentiality. | ||||
| CVE-2023-41297 | 1 Huawei | 2 Emui, Harmonyos | 2024-11-21 | 9.8 Critical |
| Vulnerability of defects introduced in the design process in the HiviewTunner module. Successful exploitation of this vulnerability may cause service hijacking. | ||||
| CVE-2023-41294 | 1 Huawei | 1 Harmonyos | 2024-11-21 | 9.8 Critical |
| The DP module has a service hijacking vulnerability.Successful exploitation of this vulnerability may affect some Super Device services. | ||||
| CVE-2023-41293 | 1 Huawei | 2 Emui, Harmonyos | 2024-11-21 | 7.5 High |
| Data security classification vulnerability in the DDMP module. Successful exploitation of this vulnerability may affect confidentiality. | ||||
| CVE-2023-41146 | 1 Autodesk | 1 Customer Portal | 2024-11-21 | 4.3 Medium |
| Autodesk Customer Support Portal allows cases created by users under an account to see cases created by other users on the same account. | ||||
| CVE-2023-41145 | 1 Autodesk | 1 Customer Portal | 2024-11-21 | 5.3 Medium |
| Autodesk users who no longer have an active license for an account can still access cases for that account. | ||||
| CVE-2023-41138 | 1 Appsanywhere | 1 Appsanywhere Client | 2024-11-21 | 7.5 High |
| The AppsAnywhere macOS client-privileged helper can be tricked into executing arbitrary commands with elevated permissions by a local user process. | ||||
| CVE-2023-41121 | 1 Arraynetworks | 3 Ag, Arrayos Ag, Vxag | 2024-11-21 | 7.5 High |
| Array AG OS before 9.4.0.499 allows denial of service: remote attackers can cause system service processes to crash through abnormal HTTP operations. | ||||