CVE Vulnerability Database

Search and browse 198 known security vulnerabilities. Filter by severity, vendor, product, and year.

198 vulnerabilities found
CVE-2023-3652
6.1 medium

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital Ant E-Commerce Software allows Reflected XSS. This issue affects E-Commerce Software: before 11.

Digital-Ant Digital Ant Aug 8, 2023
CVE-2023-3651
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digital Ant E-Commerce Software allows SQL Injection. This issue affects E-Commerce Software: before 11.

Digital-Ant Digital Ant Aug 8, 2023
CVE-2023-3716
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oduyo Online Collection Software allows SQL Injection. This issue affects Online Collection Software: before 1.0.1.

Oduyo Online Collection Aug 8, 2023
CVE-2023-3717
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farmakom Remote Administration Console allows SQL Injection. This issue affects Remote Administration Console: before 1.02.

Farmakom Remote Administration Console Aug 8, 2023
CVE-2023-3898
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mAyaNet E-Commerce Software allows SQL Injection. This issue affects E-Commerce Software: before 1.1.

Mayanets E-Commerce Aug 8, 2023
CVE-2023-35067
7.5 high

Plaintext Storage of a Password vulnerability in Infodrom Software E-Invoice Approval System allows Read Sensitive Strings Within an Executable. This issue affects E-Invoice Approval System: before v.20230701.

Infodrom E-Invoice Approval System Jul 25, 2023
CVE-2023-35066
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infodrom Software E-Invoice Approval System allows SQL Injection. This issue affects E-Invoice Approval System: before v.20230701.

Infodrom E-Invoice Approval System Jul 25, 2023
CVE-2023-3046
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Biltay Technology Scienta allows SQL Injection. This issue affects Scienta: before 20230630.1953.

Biltay Scienta Jul 25, 2023
CVE-2023-2958
9.8 critical

Authorization Bypass Through User-Controlled Key vulnerability in Origin Software ATS Pro allows Authentication Abuse, Authentication Bypass.This issue affects ATS Pro: before 20230714.

Orjinyazilim Ats Pro Jul 17, 2023
CVE-2023-3376
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digital Strategy Zekiweb allows SQL Injection. This issue affects Zekiweb: before 2.

Dijital Zekiweb Jul 17, 2023
CVE-2023-2963
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Oliva Expertise Oliva Expertise EKS allows SQL Injection. This issue affects Oliva Expertise EKS: before 1.2.

Olivaekspertiz Oliva Ekspertiz Jul 17, 2023
CVE-2023-2960
6.1 medium

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliva Expertise Oliva Expertise EKS allows Cross-Site Scripting (XSS). This issue affects Oliva Expertise EKS: before 1.2.

Olivaekspertiz Oliva Ekspertiz Jul 17, 2023
CVE-2023-2959
7.5 high

Authentication Bypass by Primary Weakness vulnerability in Oliva Expertise Oliva Expertise EKS allows Collect Data as Provided by Users. This issue affects Oliva Expertise EKS: before 1.2.

Olivaekspertiz Oliva Ekspertiz Jul 17, 2023
CVE-2023-35070
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VegaGroup Web Collection allows SQL Injection. This issue affects Web Collection: before 31197.

Vegagroup Web Collection Jul 13, 2023
CVE-2023-1547
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Elra Parkmatik allows SQL Injection through SOAP Parameter Tampering, Command Line Execution through SQL Injection. This issue affects Parkmatik: before 02.01-a51.

Elra Parkmatik Jul 13, 2023
CVE-2023-3319
5.4 medium

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iDisplay PlatPlay DS allows Stored XSS. This issue affects PlatPlay DS: before 3.14.

Idisplay Platplay Ds Jul 13, 2023
CVE-2023-35069
7.5 high

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bullwark allows Path Traversal. This issue affects Bullwark: before BLW-2016E-960H.

Biges Bullwark Momentum Series Jul 13, 2023
CVE-2023-2957
9.8 critical

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Lisa Software Florist Site allows SQL Injection.This issue affects Florist Site: before 3.0.

Lisayazilim Florist Site Jul 13, 2023
CVE-2023-33162
5.5 medium

Microsoft Excel Information Disclosure Vulnerability

Microsoft 365 Apps Jul 11, 2023
CVE-2023-33161
7.8 high

Microsoft Excel Remote Code Execution Vulnerability

Microsoft 365 Apps Jul 11, 2023
CVE-2023-33158
7.8 high

Microsoft Excel Remote Code Execution Vulnerability

Microsoft 365 Apps Jul 11, 2023
CVE-2023-33153
6.8 medium

Microsoft Outlook Remote Code Execution Vulnerability

Microsoft 365 Apps Jul 11, 2023
CVE-2023-33152
7.0 high

Microsoft ActiveX Remote Code Execution Vulnerability

Microsoft 365 Apps Jul 11, 2023
CVE-2023-33151
6.5 medium

Microsoft Outlook Spoofing Vulnerability

Microsoft 365 Apps Jul 11, 2023