Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.2
CVE-2023-49328
On a Wolters Kluwer B.POINT 23.70.00 server running Linux on premises, during the authentication phase, a validated system user can achieve remote co…
B.point
Mitigation only
CRITICAL 9.8
CVE-2023-7100
A vulnerability, which was classified as critical, was found in PHPGurukul Restaurant Table Booking System 1.0. Affected is an unknown function of th…
Restaurant Table Booking System
No fix yet
CRITICAL 9.8
CVE-2023-7096
A flaw has been found in code-projects Faculty Management System 1.0. The affected element is an unknown function of the file /admin/php/crud.php. Th…
Faculty Management System
No fix yet
CRITICAL 9.8
CVE-2023-7039EPSS 14%
A vulnerability classified as critical has been found in Byzoro S210 up to 20231210. Affected is an unknown function of the file /importexport.php. T…
Smart S210 Firmware
after 2023-12-10
CRITICAL 9.8
CVE-2023-35895
IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when passing an unchecked argument to a cert…
Informix Jdbc
Mitigation only
CRITICAL 9.8
CVE-2023-46726
GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.11, on PHP 7.4 only, the LDAP server co…
Glpi
10.0.11+
CRITICAL 9.8
CVE-2023-43364
main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution.
Searchor
2.4.2+
CRITICAL 9.8
CVE-2023-46456EPSS 25%
In GL.iNET GL-AR300M routers with firmware 3.216 it is possible to inject arbitrary shell commands through the OpenVPN client file upload functionali…
Gl Ar300m Firmware
Mitigation only
HIGH 8.8
CVE-2023-49964EPSS 35%
An issue was discovered in Hyland Alfresco Community Edition through 7.2.0. By inserting malicious content in the folder.get.html.ftl file, an attack…
Alfresco Content Services
after 7.2.0
CRITICAL 9.8
CVE-2023-6648
A vulnerability, which was classified as critical, was found in PHPGurukul Nipah Virus Testing Management System 1.0. This affects an unknown part of…
Nipah Virus Testing Management System
No fix yet
HIGH 8.8
CVE-2023-48841
Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
Appointment Scheduler
No fix yet
HIGH 8.8
CVE-2023-48830
Shuttle Booking Software 2.0 is vulnerable to CSV Injection in the Languages section via an export.
Shuttle Booking Software
No fix yet
HIGH 8.8
CVE-2023-48835
Car Rental Script v3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
Car Rental Script
No fix yet
HIGH 8.8
CVE-2023-48826
Time Slots Booking Calendar 4.0 is vulnerable to CSV Injection via the unique ID field of the Reservations List.
Time Slots Booking Calendar
No fix yet
MEDIUM 5.3
CVE-2023-48205
Jorani Leave Management System 1.0.2 allows a remote attacker to spoof a Host header associated with password reset emails.
Leave Management System
No fix yet
CRITICAL 9.8
CVE-2023-6458
Mattermost webapp fails to validate route parameters in/<TEAM_NAME>/channels/<CHANNEL_NAME> allowing an attacker to perform a client-side path traver…
Mattermost Server
7.8.14 / 8.1.5+
HIGH 8.8
CVE-2023-22522EPSS 13%
This Template Injection vulnerability allows an authenticated attacker, including one with anonymous access, to inject unsafe user input into a Confl…
Confluence Data Center
7.19.17 / 8.4.5+
MEDIUM 5.4
CVE-2023-35075
Mattermost fails to use innerText / textContent when setting the channel name in the webapp during autocomplete, allowing an attacker to inject HTML…
Mattermost
after 8.1.3
CRITICAL 9.8
CVE-2023-49214
Usedesk before 1.7.57 allows chat template injection.
Usedesk
1.7.57+
CRITICAL 9.8
CVE-2023-5340
The Five Star Restaurant Menu and Food Ordering WordPress plugin before 2.4.11 unserializes user input via an AJAX action available to unauthenticate…
Five Star Restaurant Menu
2.4.11+
CRITICAL 9.8
CVE-2022-46337
A cleverly devised username might bypass LDAP authentication checks. In
LDAP-authenticated Derby installations, this could let an attacker fill
up …
Derby
10.14.3.0 / 10.15.2.1+
MEDIUM 6.5
CVE-2023-6174
SSH dissector crash in Wireshark 4.0.0 to 4.0.10 allows denial of service via packet injection or crafted capture file
Wireshark
after 4.0.10
HIGH 7.8
CVE-2023-48199
HTML Injection vulnerability in the 'manageApiKeys' component in Grocy <= 4.0.3 allows attackers to inject arbitrary HTML content without script exec…
Grocy
No fix yet
CRITICAL 9.1
CVE-2023-44373
Affected devices do not properly sanitize an input field. This could allow an authenticated remote attacker with administrative privileges to inject…
6gk5205 3bb00 2ab2 Firmware
4.5+
MEDIUM 6.1
CVE-2023-47119
Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` an…
Discourse
3.1.3 / 3.2.0+
CRITICAL 9.8
CVE-2017-20187
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Magnesium-PHP up to 0.3.0. It has been classified as problematic. Affected is the functi…
Magnesium Php
after 0.3.0
MEDIUM 6.1
CVE-2023-4767
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attack…
Manageengine Desktop Central
Mitigation only
HIGH 8.8
CVE-2023-4197EPSS 33%
Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing a…
Dolibarr Erp\/crm
after 18.0.1
MEDIUM 6.1
CVE-2023-4393
HTML and SMTP injections on the registration page of LiquidFiles versions 3.7.13 and below, allow an attacker to perform more advanced phishing attac…
Liquidfiles
3.7.14+
HIGH 7.8
CVE-2023-46468
An issue in juzawebCMS v.3.4 and before allows a remote attacker to execute arbitrary code via a crafted file to the custom plugin function.
Juzaweb Cms
after 3.4