Export limit exceeded: 390756 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 390756 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Export limit exceeded: 98041 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (98041 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2023-41749 | 2 Acronis, Microsoft | 3 Agent, Cyber Protect, Windows | 2024-11-21 | 7.5 High |
| Sensitive information disclosure due to excessive collection of system information. The following products are affected: Acronis Agent (Windows) before build 32047, Acronis Cyber Protect 15 (Windows) before build 35979. | ||||
| CVE-2023-41744 | 2 Acronis, Apple | 3 Agent, Cyber Protect, Macos | 2024-11-21 | 7.8 High |
| Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Agent (macOS) before build 30600, Acronis Cyber Protect 15 (macOS) before build 35979. | ||||
| CVE-2023-41742 | 4 Acronis, Apple, Linux and 1 more | 5 Agent, Cyber Protect, Macos and 2 more | 2024-11-21 | 7.5 High |
| Excessive attack surface due to binding to an unrestricted IP address. The following products are affected: Acronis Agent (Linux, macOS, Windows) before build 30430, Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979. | ||||
| CVE-2023-41738 | 1 Synology | 1 Router Manager | 2024-11-21 | 7.2 High |
| Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Directory Domain Functionality in Synology Router Manager (SRM) before 1.3.1-9346-6 allows remote authenticated users to execute arbitrary commands via unspecified vectors. | ||||
| CVE-2023-41726 | 1 Ivanti | 1 Avalanche | 2024-11-21 | 7.8 High |
| Ivanti Avalanche Incorrect Default Permissions allows Local Privilege Escalation Vulnerability | ||||
| CVE-2023-41725 | 1 Ivanti | 1 Avalanche | 2024-11-21 | 7.8 High |
| Ivanti Avalanche EnterpriseServer Service Unrestricted File Upload Local Privilege Escalation Vulnerability | ||||
| CVE-2023-41720 | 1 Ivanti | 1 Connect Secure | 2024-11-21 | 7.8 High |
| A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker with a foothold on an Ivanti Connect Secure (ICS) appliance can escalate their privileges by exploiting a vulnerable installed application. This vulnerability allows the attacker to gain elevated execution privileges on the affected system. | ||||
| CVE-2023-41719 | 1 Ivanti | 1 Connect Secure | 2024-11-21 | 7.2 High |
| A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker impersonating an administrator may craft a specific web request which may lead to remote code execution. | ||||
| CVE-2023-41713 | 1 Sonicwall | 61 Nsa2700, Nsa3700, Nsa4700 and 58 more | 2024-11-21 | 7.5 High |
| SonicOS Use of Hard-coded Password vulnerability in the 'dynHandleBuyToolbar' demo function. | ||||
| CVE-2023-41692 | 1 Hennessey | 1 Attorney | 2024-11-21 | 7.1 High |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Hennessey Digital Attorney theme <= 3 theme. | ||||
| CVE-2023-41691 | 1 Pensopay | 1 Woocommerce Pensopay | 2024-11-21 | 7.1 High |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Pensopay WooCommerce PensoPay plugin <= 6.3.1 versions. | ||||
| CVE-2023-41658 | 1 I13websolution | 1 Web Solution Photo Gallery Slideshow \& Masonry Tiled Gallery | 2024-11-21 | 7.1 High |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Photo Gallery Slideshow & Masonry Tiled Gallery plugin <= 1.0.13 versions. | ||||
| CVE-2023-41653 | 1 Bearthemes | 1 Sermon\'e - Sermons Online | 2024-11-21 | 7.1 High |
| Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Beplus Sermon'e – Sermons Online plugin <= 1.0.0 versions. | ||||
| CVE-2023-41640 | 1 Grupposcai | 1 Realgimm | 2024-11-21 | 8.8 High |
| An improper error handling vulnerability in the component ErroreNonGestito.aspx of GruppoSCAI RealGimm 1.1.37p38 allows attackers to obtain sensitive technical information via a crafted SQL query. | ||||
| CVE-2023-41638 | 1 Grupposcai | 1 Realgimm | 2024-11-21 | 8.8 High |
| An arbitrary file upload vulnerability in the Gestione Documentale module of GruppoSCAI RealGimm 1.1.37p38 allows attackers to execute arbitrary code via uploading a crafted file. | ||||
| CVE-2023-41631 | 1 Esst | 1 Esst Monitoring | 2024-11-21 | 8.8 High |
| eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the file upload function. | ||||
| CVE-2023-41629 | 1 Esst | 1 Esst Monitoring | 2024-11-21 | 7.5 High |
| A lack of input sanitizing in the file download feature of eSST Monitoring v2.147.1 allows attackers to execute a path traversal. | ||||
| CVE-2023-41628 | 1 O-ran-sc | 1 E2 | 2024-11-21 | 7.5 High |
| An issue in O-RAN Software Community E2 G-Release allows attackers to cause a Denial of Service (DoS) by incorrectly initiating the messaging procedure between the E2Node and E2Term components. | ||||
| CVE-2023-41627 | 1 O-ran-sc | 1 Ric Message Router | 2024-11-21 | 7.5 High |
| O-RAN Software Community ric-plt-lib-rmr v4.9.0 does not validate the source of the routing tables it receives, potentially allowing attackers to send forged routing tables to the device. | ||||
| CVE-2023-41623 | 1 Emlog | 1 Emlog | 2024-11-21 | 7.2 High |
| Emlog version pro2.1.14 was discovered to contain a SQL injection vulnerability via the uid parameter at /admin/media.php. | ||||