Show filters
71,179 Total Results
Displaying 331-340 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Moderate

CVE-2022-43939

Disclosure Date: April 03, 2023 (last updated October 08, 2023)
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.2, including 8.3.x contain security restrictions using non-canonical URLs which can be circumvented. 
Attacker Value
High

CVE-2023-28879

Disclosure Date: March 31, 2023 (last updated October 08, 2023)
In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is filled to one byte less than full, and one then tries to write an escaped character, two bytes are written.
Attacker Value
High

CVE-2023-24892

Disclosure Date: March 14, 2023 (last updated January 11, 2025)
Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability
Attacker Value
Unknown

CVE-2023-24880

Disclosure Date: March 14, 2023 (last updated January 11, 2025)
Windows SmartScreen Security Feature Bypass Vulnerability
Attacker Value
High

CVE-2023-23398

Disclosure Date: March 14, 2023 (last updated May 29, 2024)
Microsoft Excel Spoofing Vulnerability
Attacker Value
Moderate

CVE-2023-23396

Disclosure Date: March 14, 2023 (last updated May 29, 2024)
Microsoft Excel Denial of Service Vulnerability
Attacker Value
High

CVE-2023-26035

Disclosure Date: February 25, 2023 (last updated October 08, 2023)
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are vulnerable to Unauthenticated Remote Code Execution via Missing Authorization. There are no permissions check on the snapshot action, which expects an id to fetch an existing monitor but can be passed an object to create a new one instead. TriggerOn ends up calling shell_exec using the supplied Id. This issue is fixed in This issue is fixed in versions 1.36.33 and 1.37.33.
Attacker Value
Very High

CVE-2023-23333

Disclosure Date: February 06, 2023 (last updated October 08, 2023)
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php.
Attacker Value
High

CVE-2023-25135

Disclosure Date: February 03, 2023 (last updated October 08, 2023)
vBulletin before 5.6.9 PL1 allows an unauthenticated remote attacker to execute arbitrary code via a crafted HTTP request that triggers deserialization. This occurs because verify_serialized checks that a value is serialized by calling unserialize and then checking for errors. The fixed versions are 5.6.7 PL1, 5.6.8 PL1, and 5.6.9 PL1.
Attacker Value
Very Low

CVE-2023-20073

Disclosure Date: February 02, 2023 (last updated October 08, 2023)
A vulnerability in the web-based management interface of Cisco RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to upload arbitrary files to an affected device. This vulnerability is due to insufficient authorization enforcement mechanisms in the context of file uploads. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device. A successful exploit could allow the attacker to upload arbitrary files to the affected device.