Vulnerabilites CVE
Base de donnees CVE enrichie avec CISA KEV et NVD
| CVE ID | CVSS | Severite | KEV | Observations |
|---|---|---|---|---|
| CVE-2023-36678 Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP-buy WP Content Copy Protection & No Right Click plugin <= 3.5.5 versions. | 5.9 | MEDIUM | — | 0 |
| CVE-2023-36686 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CartFlows Pro plugin <= 1.11.11 versions. | 7.1 | HIGH | — | 0 |
| CVE-2023-36689 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFactory WPFactory Helper plugin <= 1.5.2 versions. | 7.1 | HIGH | — | 0 |
| CVE-2023-37874 Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Dimitar Ivanov HTTP Headers plugin <= 1.18.11 versions. | 5.9 | MEDIUM | — | 0 |
| CVE-2023-4172 A vulnerability, which was classified as problematic, has been found in Chengdu Flash Flood Disaster Monitoring and Warning System 2.0. This issue affects some unknown processing of the file \Service\... | 4.3 | MEDIUM | — | 0 |
| CVE-2023-32600 Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Rank Math SEO plugin <= 1.0.119 versions. | 6.5 | MEDIUM | — | 0 |
| CVE-2023-4173 A vulnerability, which was classified as problematic, was found in mooSocial mooStore 3.1.6. Affected is an unknown function of the file /search/index. The manipulation of the argument q leads to cros... | 3.5 | LOW | — | 0 |
| CVE-2023-4174 A vulnerability has been found in mooSocial mooStore 3.1.6 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting. Th... | 3.5 | LOW | — | 0 |
| CVE-2023-4190 Insufficient Session Expiration in GitHub repository admidio/admidio prior to 4.2.11. | 6.5 | MEDIUM | — | 0 |
| CVE-2023-6450 An incorrect permissions vulnerability was reported in the Lenovo App Store app that could allow an attacker to use system resources, resulting in a denial of service. | 5.5 | MEDIUM | — | 0 |
| CVE-2023-4175 A vulnerability was found in mooSocial mooTravel 3.1.8 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. The attack m... | 3.5 | LOW | — | 0 |
| CVE-2023-4176 A vulnerability was found in SourceCodester Hospital Management System 1.0. It has been classified as critical. This affects an unknown part of the file appointmentapproval.php. The manipulation of th... | 6.3 | MEDIUM | — | 0 |
| CVE-2023-4177 A vulnerability was found in EmpowerID up to 7.205.0.0. It has been rated as problematic. This issue affects some unknown processing of the component Multi-Factor Authentication Code Handler. The mani... | 2.6 | LOW | — | 0 |
| CVE-2023-37581 Insufficient input validation and sanitation in Weblog Category name, Website About and File Upload features in all versions of Apache Roller on all platforms allows an authenticated user to perform a... | 5.4 | MEDIUM | — | 0 |
| CVE-2023-4179 A vulnerability classified as critical has been found in SourceCodester Free Hospital Management System for Small Practices 1.0. Affected is an unknown function of the file /vm/doctor/doctors.php?acti... | 6.3 | MEDIUM | — | 0 |
| CVE-2024-22245 Arbitrary Authentication Relay and Session Hijack vulnerabilities in the deprecated VMware Enhanced Authentication Plug-in (EAP) could allow a malicious actor that could trick a target domain user wit... | 9.6 | CRITICAL | — | 0 |
| CVE-2023-4180 A vulnerability classified as critical was found in SourceCodester Free Hospital Management System for Small Practices 1.0. Affected by this vulnerability is an unknown functionality of the file /vm/l... | 7.3 | HIGH | — | 0 |
| CVE-2023-4181 A vulnerability, which was classified as critical, has been found in SourceCodester Free Hospital Management System for Small Practices 1.0. Affected by this issue is some unknown functionality of the... | 5.4 | MEDIUM | — | 0 |
| CVE-2023-4182 A vulnerability, which was classified as critical, was found in SourceCodester Inventory Management System 1.0. This affects an unknown part of the file edit_sell.php. The manipulation of the argument... | 7.3 | HIGH | — | 0 |
| CVE-2023-4183 A vulnerability has been found in SourceCodester Inventory Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file edit_update.php of the component Pas... | 4.3 | MEDIUM | — | 0 |
| CVE-2023-4184 A vulnerability was found in SourceCodester Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file sell_return.php. The manipulation of the ... | 7.3 | HIGH | — | 0 |
| CVE-2022-38795 In Gitea through 1.17.1, repo cloning can occur in the migration function. | 6.5 | MEDIUM | — | 0 |
| CVE-2023-4185 A vulnerability was found in SourceCodester Online Hospital Management System 1.0. It has been classified as critical. Affected is an unknown function of the file patientlogin.php. The manipulation of... | 6.3 | MEDIUM | — | 0 |
| CVE-2023-4186 A vulnerability was found in SourceCodester Pharmacy Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file manage_website.php.... | 6.3 | MEDIUM | — | 0 |
| CVE-2023-4195 PHP Remote File Inclusion in GitHub repository cockpit-hq/cockpit prior to 2.6.3. | 8.8 | HIGH | — | 0 |
| CVE-2023-4196 Cross-site Scripting (XSS) - Stored in GitHub repository cockpit-hq/cockpit prior to 2.6.3. | 5.4 | MEDIUM | — | 0 |
| CVE-2023-4191 A vulnerability, which was classified as critical, has been found in SourceCodester Resort Reservation System 1.0. Affected by this issue is some unknown functionality of the file index.php. The manip... | 6.3 | MEDIUM | — | 0 |
| CVE-2022-48579 UnRAR before 6.2.3 allows extraction of files outside of the destination folder via symlink chains. | 7.5 | HIGH | — | 0 |
| CVE-2023-4192 A vulnerability, which was classified as critical, was found in SourceCodester Resort Reservation System 1.0. This affects an unknown part of the file manage_user.php. The manipulation of the argument... | 6.3 | MEDIUM | — | 0 |
| CVE-2023-4193 A vulnerability has been found in SourceCodester Resort Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file view_fee.php. The manipulation of the arg... | 6.3 | MEDIUM | — | 0 |
| CVE-2022-47350 In camera driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed | 4.4 | MEDIUM | — | 0 |
| CVE-2022-47351 In camera driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed | 4.4 | MEDIUM | — | 0 |
| CVE-2023-20796 In power, there is a possible memory corruption due to an incorrect bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for... | 4.4 | MEDIUM | — | 0 |
| CVE-2023-33906 In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges | 5.5 | MEDIUM | — | 0 |
| CVE-2023-33907 In Contacts Service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges | 5.5 | MEDIUM | — | 0 |
| CVE-2023-33908 In ims service, there is a possible missing permission check. This could lead to local information disclosure with no additional execution privileges | 5.5 | MEDIUM | — | 0 |
| CVE-2023-33909 In Contacts service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges | 5.5 | MEDIUM | — | 0 |
| CVE-2023-33910 In Contacts Service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges | 5.5 | MEDIUM | — | 0 |
| CVE-2023-33911 In vowifi service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges | 5.5 | MEDIUM | — | 0 |
| CVE-2023-33912 In Contacts service, there is a possible missing permission check.This could lead to local information disclosure with no additional execution privileges | 5.5 | MEDIUM | — | 0 |
| CVE-2023-33913 In DRM/oemcrypto, there is a possible out of bounds write due to an incorrect calculation of buffer size.This could lead to remote escalation of privilege with System execution privileges needed | 7.2 | HIGH | — | 0 |
| CVE-2023-20813 In wlan service, there is a possible out of bounds read due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is n... | 4.4 | MEDIUM | — | 0 |
| CVE-2023-20780 In keyinstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is no... | 4.4 | MEDIUM | — | 0 |
| CVE-2023-20781 In keyinstall, there is a possible memory corruption due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed f... | 4.4 | MEDIUM | — | 0 |
| CVE-2023-20782 In keyinstall, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is no... | 4.4 | MEDIUM | — | 0 |
| CVE-2023-20783 In keyinstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not ... | 6.7 | MEDIUM | — | 0 |
| CVE-2024-22250 Session Hijack vulnerability in Deprecated VMware Enhanced Authentication Plug-in could allow a malicious actor with unprivileged local access to a windows operating system can hijack a privileged EAP... | 7.8 | HIGH | — | 0 |
| CVE-2023-20784 In keyinstall, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not ... | 6.7 | MEDIUM | — | 0 |
| CVE-2023-20785 In audio, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not neede... | 6.4 | MEDIUM | — | 0 |
| CVE-2023-20786 In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed ... | 6.7 | MEDIUM | — | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.