Show filters
118,611 Total Results
Displaying 241-250 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
High

CVE-2023-35636

Disclosure Date: December 12, 2023 (last updated February 25, 2025)
Microsoft Outlook Information Disclosure Vulnerability
Attacker Value
Very High

CVE-2023-6448

Disclosure Date: December 05, 2023 (last updated February 25, 2025)
Unitronics VisiLogic before version 9.9.00, used in Vision and Samba PLCs and HMIs, uses a default administrative password. An unauthenticated attacker with network access can take administrative control of a vulnerable system.
Attacker Value
Unknown

CVE-2021-35975

Disclosure Date: November 30, 2023 (last updated February 25, 2025)
Absolute path traversal vulnerability in the Systematica SMTP Adapter component (up to v2.0.1.101) in Systematica Radius (up to v.3.9.256.777) allows remote attackers to read arbitrary files via a full pathname in GET parameter "file" in URL. Also: affected components in same product - HTTP Adapter (up to v.1.8.0.15), MSSQL MessageBus Proxy (up to v.1.1.06), Financial Calculator (up to v.1.3.05), FIX Adapter (up to v.2.4.0.25)
Attacker Value
Low

CVE-2023-6209

Disclosure Date: November 21, 2023 (last updated February 25, 2025)
Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host. This could contribute to security problems in web sites. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
Attacker Value
High

CVE-2023-5360

Disclosure Date: October 31, 2023 (last updated February 25, 2025)
The Royal Elementor Addons and Templates WordPress plugin before 1.3.79 does not properly validate uploaded files, which could allow unauthenticated users to upload arbitrary files, such as PHP and achieve RCE.
Attacker Value
Moderate

CVE-2023-46748

Disclosure Date: October 26, 2023 (last updated February 25, 2025)
An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Attacker Value
Very High

CVE-2023-5009

Disclosure Date: September 19, 2023 (last updated February 25, 2025)
An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.2.7, all versions starting from 16.3 before 16.3.4. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies. This was a bypass of [CVE-2023-3932](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3932) showing additional impact.
Attacker Value
High

CVE-2023-34960

Disclosure Date: August 01, 2023 (last updated February 25, 2025)
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.
Attacker Value
Moderate

CVE-2023-29298

Disclosure Date: July 12, 2023 (last updated February 25, 2025)
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.
Attacker Value
Low

CVE-2023-24488

Disclosure Date: July 10, 2023 (last updated February 25, 2025)
Cross site scripting vulnerability in Citrix ADC and Citrix Gateway  in allows and attacker to perform cross site scripting