Show filters
40,662 Total Results
Displaying 91-100 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
High

CVE-2023-4220

Disclosure Date: November 28, 2023 (last updated December 05, 2023)
Unrestricted file upload in big file upload functionality in `/main/inc/lib/javascript/bigupload/inc/bigUpload.php` in Chamilo LMS <= v1.11.24 allows unauthenticated attackers to perform stored cross-site scripting attacks and obtain remote code execution via uploading of web shell.
Attacker Value
Unknown

CVE-2021-34506

Disclosure Date: July 01, 2023 (last updated October 08, 2023)
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Attacker Value
Unknown

CVE-2021-34475

Disclosure Date: July 01, 2023 (last updated October 08, 2023)
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Attacker Value
High

CVE-2023-33137

Disclosure Date: June 14, 2023 (last updated January 04, 2025)
Microsoft Excel Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2023-3079

Disclosure Date: June 05, 2023 (last updated June 29, 2024)
Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Attacker Value
High

CVE-2023-28311

Disclosure Date: April 11, 2023 (last updated January 04, 2025)
Microsoft Word Remote Code Execution Vulnerability
Attacker Value
High

CVE-2022-44268

Disclosure Date: February 06, 2023 (last updated October 08, 2023)
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulting image could have embedded the content of an arbitrary. file (if the magick binary has permissions to read it).
Attacker Value
Very High

CVE-2023-0129

Disclosure Date: January 10, 2023 (last updated October 08, 2023)
Heap buffer overflow in Network Service in Google Chrome prior to 109.0.5414.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page and specific interactions. (Chromium security severity: High)
Attacker Value
High

CVE-2022-46689

Disclosure Date: December 15, 2022 (last updated October 08, 2023)
A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.
Attacker Value
High

CVE-2022-1494

Disclosure Date: July 26, 2022 (last updated October 07, 2023)
Insufficient data validation in Trusted Types in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass trusted types policy via a crafted HTML page.