Export limit exceeded: 98004 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.

Search

Search Results (98004 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-39452 1 Socomec 2 Modulys Gp, Modulys Gp Firmware 2024-11-21 7.5 High
The web application that owns the device clearly stores the credentials within the user management section. Obtaining this information can be done remotely due to the incorrect management of the sessions in the web application.
CVE-2023-39448 1 Ss-proj 1 Shirasagi 2024-11-21 8.8 High
Path traversal vulnerability in SHIRASAGI prior to v1.18.0 allows a remote authenticated attacker to alter or create arbitrary files on the server, resulting in arbitrary code execution.
CVE-2023-39446 1 Socomec 2 Modulys Gp, Modulys Gp Firmware 2024-11-21 8.9 High
Thanks to the weaknesses that the web application has at the user management level, an attacker could obtain the information from the headers that is necessary to create specially designed URLs and originate malicious actions when a legitimate user is logged into the web application.
CVE-2023-39445 2 Elecom, Logitec 15 Wrc-1467ghbk-a, Wrc-1467ghbk-a Firmware, Wrc-1467ghbk-s and 12 more 2024-11-21 8.8 High
Hidden functionality vulnerability in LAN-WH300N/RE all versions provided by LOGITEC CORPORATION allows an unauthenticated attacker to execute arbitrary code by sending a specially crafted file to the product's certain management console.
CVE-2023-39438 1 Sap 1 Contributor License Agreement Assistant 2024-11-21 8.1 High
A missing authorization check allows an arbitrary authenticated user to perform certain operations through the API of CLA-assistant by executing specific additional steps. This allows an arbitrary authenticated user to read CLA information including information of the persons who signed them as well as custom fields the CLA requester had configured. In addition, an arbitrary authenticated user can update or delete the CLA-configuration for repositories or organizations using CLA-assistant. The stored access tokens for GitHub are not affected, as these are redacted from the API-responses.
CVE-2023-39437 1 Sap 1 Business One 2024-11-21 7.6 High
SAP business One allows - version 10.0, allows an attacker to insert malicious code into the content of a web page or application and gets it delivered to the client, resulting to Cross-site scripting. This could lead to harmful action affecting the Confidentiality, Integrity and Availability of the application.
CVE-2023-39425 1 Intel 1 Driver \& Support Assistant 2024-11-21 8.8 High
Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2023-39423 1 Resortdata 1 Internet Reservation Module Next Generation 2024-11-21 8.6 High
The RDPData.dll file exposes the /irmdata/api/common endpoint that handles session IDs,  among other features. By using a UNION SQL operator, an attacker can leak the sessions table, obtain the currently valid sessions and impersonate a currently logged-in user.
CVE-2023-39421 1 Resortdata 1 Internet Reservation Module Next Generation 2024-11-21 7.7 High
The RDPWin.dll component as used in the IRM Next Generation booking engine includes a set of hardcoded API keys for third-party services such as Twilio and Vonage. These keys allow unrestricted interaction with these services.
CVE-2023-39419 2 Seimens, Siemens 2 Solid Edge, Solid Edge 2024-11-21 7.8 High
A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 7). The affected applications contain an out of bounds write past the end of an allocated structure while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.
CVE-2023-39416 2 North Grid Corporation, Northgrid 4 Proself Enterprise Standard Edition, Proself Gateway Edition, Proself Mail Sanitize Edition and 1 more 2024-11-21 7.2 High
Proself Enterprise/Standard Edition Ver5.61 and earlier, Proself Gateway Edition Ver1.62 and earlier, and Proself Mail Sanitize Edition Ver1.07 and earlier allow a remote authenticated attacker with an administrative privilege to execute arbitrary OS commands.
CVE-2023-39415 1 Northgrid 4 Proself, Proself Enterprise Standard Edition, Proself Gateway Edition and 1 more 2024-11-21 7.5 High
Improper authentication vulnerability in Proself Enterprise/Standard Edition Ver5.61 and earlier, Proself Gateway Edition Ver1.62 and earlier, and Proself Mail Sanitize Edition Ver1.07 and earlier allow a remote unauthenticated attacker to log in to the product's Control Panel and perform an unintended operation.
CVE-2023-39409 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
CVE-2023-39408 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
DoS vulnerability in the PMS module. Successful exploitation of this vulnerability may cause the system to restart.
CVE-2023-39406 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
Permission control vulnerability in the XLayout component. Successful exploitation of this vulnerability may cause apps to forcibly restart.
CVE-2023-39404 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
Vulnerability of input parameter verification in certain APIs in the window management module. Successful exploitation of this vulnerability may cause the device to restart.
CVE-2023-39397 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
Input parameter verification vulnerability in the communication system. Successful exploitation of this vulnerability may affect availability.
CVE-2023-39396 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
Deserialization vulnerability in the input module. Successful exploitation of this vulnerability may affect availability.
CVE-2023-39395 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
Mismatch vulnerability in the serialization process in the communication system. Successful exploitation of this vulnerability may affect availability.
CVE-2023-39394 1 Huawei 2 Emui, Harmonyos 2024-11-21 7.5 High
Vulnerability of API privilege escalation in the wifienhance module. Successful exploitation of this vulnerability may cause the arp list to be modified.