Export limit exceeded: 98281 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (98281 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-4154 2 Redhat, Samba 3 Enterprise Linux, Storage, Samba 2024-11-21 7.5 High
A design flaw was found in Samba's DirSync control implementation, which exposes passwords and secrets in Active Directory to privileged users and Read-Only Domain Controllers (RODCs). This flaw allows RODCs and users possessing the GET_CHANGES right to access all attributes, including sensitive secrets and passwords. Even in a default setup, RODC DC accounts, which should only replicate some passwords, can gain access to all domain secrets, including the vital krbtgt, effectively eliminating the RODC / DC distinction. Furthermore, the vulnerability fails to account for error conditions (fail open), like out-of-memory situations, potentially granting access to secret attributes, even under low-privileged attacker influence.
CVE-2023-4152 1 Frauscher 1 Frauscher Diagnostic System 101 2024-11-21 7.5 High
Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a path traversal vulnerability of the web interface by a crafted URL without authentication. This enables an remote attacker to read all files on the filesystem of the FDS101 device.
CVE-2023-4126 1 Answer 1 Answer 2024-11-21 8.8 High
Insufficient Session Expiration in GitHub repository answerdev/answer prior to v1.1.0.
CVE-2023-4125 1 Answer 1 Answer 2024-11-21 8.8 High
Weak Password Requirements in GitHub repository answerdev/answer prior to v1.1.0.
CVE-2023-4103 1 Qsige 1 Qsige 2024-11-21 8.8 High
QSige statistics are affected by a remote SQLi vulnerability. It has been identified that the web application does not correctly filter input parameters, allowing SQL injections, DoS or information disclosure. As a prerequisite, it is necessary to log into the application.
CVE-2023-4102 1 Qsige 1 Qsige 2024-11-21 8.8 High
QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary to log into the application.
CVE-2023-4101 1 Qsige 1 Qsige 2024-11-21 8.8 High
The QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary to log into the application.
CVE-2023-4099 1 Qsige 1 Qsige 2024-11-21 7.6 High
The QSige Monitor application does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary to log into the application.
CVE-2023-4098 1 Qsige 1 Qsige 2024-11-21 8.8 High
It has been identified that the web application does not correctly filter input parameters, allowing SQL injections, DoS or information disclosure. As a prerequisite, it is necessary to log into the application.
CVE-2023-4097 1 Qsige 1 Qsige 2024-11-21 8.8 High
The file upload functionality is not implemented correctly and allows uploading of any type of file. As a prerequisite, it is necessary for the attacker to log into the application with a valid username.
CVE-2023-4096 1 Fujitsu 1 Arconte Aurea 2024-11-21 8.6 High
Weak password recovery mechanism vulnerability in Fujitsu Arconte Áurea version 1.5.0.0, which exploitation could allow an attacker to perform a brute force attack on the emailed PIN number in order to change the password of a legitimate user.
CVE-2023-4092 1 Fujitsu 1 Arconte Aurea 2024-11-21 8.8 High
SQL injection vulnerability in Arconte Áurea, in its 1.5.0.0 version. The exploitation of this vulnerability could allow an attacker to read sensitive data from the database, modify data (insert/update/delete), perform database administration operations and, in some cases, execute commands on the operating system.
CVE-2023-4033 2 Lfprojects, Mlflow 2 Mlflow, Mlflow 2024-11-21 7.8 High
OS Command Injection in GitHub repository mlflow/mlflow prior to 2.6.0.
CVE-2023-4030 1 Lenovo 9 Thinkpad, Thinkpad P14s Gen 2, Thinkpad P14s Gen 2 Firmware and 6 more 2024-11-21 8.4 High
A vulnerability was reported in BIOS for ThinkPad P14s Gen 2, P15s Gen 2, T14 Gen 2, and T15 Gen 2 that could cause the system to recover to insecure settings if the BIOS becomes corrupt.
CVE-2023-4003 1 Oneidentity 1 Password Manager 2024-11-21 7.6 High
One Identity Password Manager version 5.9.7.1 - An unauthenticated attacker with physical access to a workstation may upgrade privileges to SYSTEM through an unspecified method. CWE-250: Execution with Unnecessary Privileges.
CVE-2023-49981 2 Oretnom23, Sourcecodester 2 School Fees Management System, School Fees Management System 2024-11-21 7.5 High
A directory listing vulnerability in School Fees Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization.
CVE-2023-49980 2 Mayurik, Sourcecodester 2 Best Student Result Management System, Best Student Result Management System 2024-11-21 7.5 High
A directory listing vulnerability in Best Student Result Management System v1.0 allows attackers to list directories and sensitive files within the application without requiring authorization.
CVE-2023-49979 2 Mayurik, Sourcecodester 2 Best Student Management System, Customer Support System 2024-11-21 7.5 High
A directory listing vulnerability in Customer Support System v1 allows attackers to list directories and sensitive files within the application without requiring authorization.
CVE-2023-49978 1 Oretnom23 1 Customer Support System 2024-11-21 8.8 High
Incorrect access control in Customer Support System v1 allows non-administrator users to access administrative pages and execute actions reserved for administrators.
CVE-2023-49967 1 Typecho 1 Typecho 2024-11-21 7.5 High
Typecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xmlrpc.