CVE Vulnerabilities
CVE vulnerability database enriched with CISA KEV and NVD data
| CVE ID | CVSS | Severity | KEV | Sightings |
|---|---|---|---|---|
| CVE-2023-2775 A vulnerability was found in code-projects Bus Dispatch and Information System 1.0. It has been classified as critical. This affects an unknown part of the file adminHome.php. The manipulation of the ... | 6.3 | MEDIUM | — | 0 |
| CVE-2023-2776 A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to unrestricted upload. The attac... | 6.3 | MEDIUM | — | 0 |
| CVE-2023-2780 Path Traversal: '\..\filename' in GitHub repository mlflow/mlflow prior to 2.3.1. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-20003 A vulnerability in the social login configuration option for the guest users of Cisco Business Wireless Access Points (APs) could allow an unauthenticated, adjacent attacker to bypass social login aut... | 4.7 | MEDIUM | — | 0 |
| CVE-2023-20077 Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of ... | 4.9 | MEDIUM | — | 0 |
| CVE-2023-20087 Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to download arbitrary files from the filesystem of ... | 4.9 | MEDIUM | — | 0 |
| CVE-2023-20106 Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabil... | 5.4 | MEDIUM | — | 0 |
| CVE-2023-20110 A vulnerability in the web-based management interface of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an authenticated, remote attacker to conduct SQL injection attacks on an affecte... | 6.5 | MEDIUM | — | 0 |
| CVE-2023-20156 Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or... | 8.6 | HIGH | — | 0 |
| CVE-2023-20157 Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or... | 8.6 | HIGH | — | 0 |
| CVE-2023-20158 Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or... | 8.6 | HIGH | — | 0 |
| CVE-2023-20159 Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or... | 8.6 | HIGH | — | 0 |
| CVE-2023-20160 Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or... | 8.6 | HIGH | — | 0 |
| CVE-2023-20161 Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or... | 8.6 | HIGH | — | 0 |
| CVE-2023-20162 Multiple vulnerabilities in the web-based user interface of certain Cisco Small Business Series Switches could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or... | 8.6 | HIGH | — | 0 |
| CVE-2023-20163 Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to... | 6.5 | MEDIUM | — | 0 |
| CVE-2023-34736 Guantang Equipment Management System version 4.12 is vulnerable to Arbitrary File Upload. | 7.2 | HIGH | — | 0 |
| CVE-2023-20164 Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to... | 6.5 | MEDIUM | — | 0 |
| CVE-2023-20166 Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform path traversal attacks on the underlying operating system to either elevate privileges... | 6.0 | MEDIUM | — | 0 |
| CVE-2023-20167 Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform path traversal attacks on the underlying operating system to either elevate privileges... | 6.0 | MEDIUM | — | 0 |
| CVE-2023-20171 Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabil... | 5.4 | MEDIUM | — | 0 |
| CVE-2023-20172 Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabil... | 5.4 | MEDIUM | — | 0 |
| CVE-2023-2864 A vulnerability was found in SourceCodester Online Jewelry Store 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file customer.php of the component POST ... | 3.5 | LOW | — | 0 |
| CVE-2023-2865 A vulnerability was found in SourceCodester Theme Park Ticketing System 1.0. It has been classified as critical. This affects an unknown part of the file print_ticket.php of the component GET Paramete... | 6.3 | MEDIUM | — | 0 |
| CVE-2023-2750 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cityboss E-municipality allows SQL Injection.This issue affects E-municipality: before 6.05. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-2065 Authorization Bypass Through User-Controlled Key vulnerability in Armoli Technology Cargo Tracking System allows Authentication Abuse, Authentication Bypass.This issue affects Cargo Tracking System: b... | 8.8 | HIGH | — | 0 |
| CVE-2023-2045 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ipekyolu Software Auto Damage Tracking Software allows SQL Injection.This issue affects Auto Damag... | 9.8 | CRITICAL | — | 0 |
| CVE-2023-2064 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Minova Technology eTrace allows SQL Injection.This issue affects eTrace: before 23.05.20. | 9.8 | CRITICAL | — | 0 |
| CVE-2022-45364 Cross-Site Request Forgery (CSRF) vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload – Contact Form 7 plugin <= 1.3.6.5 versions. | 5.4 | MEDIUM | — | 0 |
| CVE-2022-46794 Cross-Site Request Forgery (CSRF) vulnerability in weightbasedshipping.Com WooCommerce Weight Based Shipping plugin <= 5.4.1 versions. | 4.3 | MEDIUM | — | 0 |
| CVE-2022-46816 Cross-Site Request Forgery (CSRF) vulnerability in Booking Ultra Pro Appointments Booking Calendar Plugin plugin <= 1.1.4 versions. | 4.3 | MEDIUM | — | 0 |
| CVE-2022-47152 Cross-Site Request Forgery (CSRF) vulnerability in Etison, LLC ClickFunnels plugin <= 3.1.1 versions. | 5.4 | MEDIUM | — | 0 |
| CVE-2022-47180 Cross-Site Request Forgery (CSRF) vulnerability in Kopa Theme Kopa Framework plugin <= 1.3.5 versions. | 4.3 | MEDIUM | — | 0 |
| CVE-2021-25748 A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the `spec.rules[].http.paths[].path` f... | 7.6 | HIGH | — | 0 |
| CVE-2021-25749 Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true. | 7.8 | HIGH | — | 0 |
| CVE-2023-33793 A stored cross-site scripting (XSS) vulnerability in the Create Power Panels (/dcim/power-panels/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted pay... | 5.4 | MEDIUM | — | 0 |
| CVE-2022-47446 Cross-Site Request Forgery (CSRF) vulnerability in Viadat Creations Store Locator for WordPress with Google Maps – LotsOfLocales plugin <= 3.98.7 versions. | 5.4 | MEDIUM | — | 0 |
| CVE-2022-47447 Cross-Site Request Forgery (CSRF) vulnerability in Mathieu Chartier WordPress WP-Advanced-Search plugin <= 3.3.8 versions. | 4.3 | MEDIUM | — | 0 |
| CVE-2022-47448 Cross-Site Request Forgery (CSRF) vulnerability in dev.Xiligroup.Com - MS plugin <= 1.12.03 versions. | 5.4 | MEDIUM | — | 0 |
| CVE-2023-1174 This vulnerability exposes a network port in minikube running on macOS with Docker driver that could enable unexpected remote access to the minikube container. | 9.8 | CRITICAL | — | 0 |
| CVE-2023-1944 This vulnerability enables ssh access to minikube container using a default password. | 8.4 | HIGH | — | 0 |
| CVE-2023-25028 Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in chuyencode CC Custom Taxonomy plugin <= 1.0.1 versions. | 5.9 | MEDIUM | — | 0 |
| CVE-2023-33950 Pattern Redirects in Liferay Portal 7.4.3.48 through 7.4.3.76, and Liferay DXP 7.4 update 48 through 76 allows regular expressions that are vulnerable to ReDoS attacks to be used as patterns, which al... | 6.5 | MEDIUM | — | 0 |
| CVE-2023-2870 A vulnerability was found in EnTech Monitor Asset Manager 2.9. It has been declared as problematic. Affected by this vulnerability is the function 0x80002014 of the component IoControlCode Handler. Th... | 3.3 | LOW | — | 0 |
| CVE-2023-2871 A vulnerability was found in FabulaTech USB for Remote Desktop 6.1.0.0. It has been rated as problematic. Affected by this issue is the function 0x220448/0x220420/0x22040c/0x220408 of the component Io... | 3.3 | LOW | — | 0 |
| CVE-2023-2872 A vulnerability classified as problematic has been found in FlexiHub 5.5.14691.0. This affects the function 0x220088 in the library fusbhub.sys of the component IoControlCode Handler. The manipulation... | 5.5 | MEDIUM | — | 0 |
| CVE-2023-2873 A vulnerability classified as critical was found in Twister Antivirus 8. This vulnerability affects the function 0x804f2143/0x804f217f/0x804f214b/0x80800043 in the library filppd.sys of the component ... | 5.3 | MEDIUM | — | 0 |
| CVE-2023-33794 A stored cross-site scripting (XSS) vulnerability in the Create Tenants (/tenancy/tenants/) function of Netbox v3.5.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in... | 5.4 | MEDIUM | — | 0 |
| CVE-2023-2874 A vulnerability, which was classified as problematic, has been found in Twister Antivirus 8. This issue affects the function 0x804f2158/0x804f2154/0x804f2150/0x804f215c/0x804f2160/0x80800040/0x804f214... | 5.5 | MEDIUM | — | 0 |
| CVE-2023-2875 A vulnerability, which was classified as problematic, was found in eScan Antivirus 22.0.1400.2443. Affected is the function 0x22E008u in the library PROCOBSRVESX.SYS of the component IoControlCode Han... | 5.5 | MEDIUM | — | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.