CVE Vulnerability Database

Search and browse 41 known security vulnerabilities. Filter by severity, vendor, product, and year.

41 vulnerabilities found
CVE-2023-4672
6.1 medium

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Talent Software ECOP allows Reflected XSS. This issue affects ECOP: before 32255.

Talentyazilim Ecop Dec 28, 2023
CVE-2023-51384
5.5 medium

In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.

Openbsd Openssh Dec 18, 2023
CVE-2023-36009
5.5 medium

Microsoft Word Information Disclosure Vulnerability

Microsoft 365 Apps Dec 12, 2023
CVE-2023-4406
6.1 medium

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in KC Group E-Commerce Software allows Reflected XSS. This issue affects E-Commerce Software: through 20231123.  NOTE: The vendor was contacted early about this disclosure but did not respond in any

Kc Group E-Commerce Software Project Kc Group E-Commerce Software Nov 23, 2023
CVE-2023-6011
5.4 medium

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in DECE Software Geodi allows Stored XSS. This issue affects Geodi: before 8.0.0.27396.

Dece Geodi Nov 22, 2023
CVE-2023-4663
6.1 medium

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Saphira Saphira Connect allows Reflected XSS. This issue affects Saphira Connect: before 9.

Adobe Connect Sep 15, 2023
CVE-2023-4676
6.1 medium

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Yordam MedasPro allows Reflected XSS. This issue affects MedasPro: before 28.

Yordam Medaspro Sep 14, 2023
CVE-2023-3653
5.4 medium

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital Ant E-Commerce Software allows Stored XSS. This issue affects E-Commerce Software: before 11.

Digital-Ant Digital Ant Aug 8, 2023
CVE-2023-3652
6.1 medium

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Digital Ant E-Commerce Software allows Reflected XSS. This issue affects E-Commerce Software: before 11.

Digital-Ant Digital Ant Aug 8, 2023
CVE-2023-2960
6.1 medium

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliva Expertise Oliva Expertise EKS allows Cross-Site Scripting (XSS). This issue affects Oliva Expertise EKS: before 1.2.

Olivaekspertiz Oliva Ekspertiz Jul 17, 2023
CVE-2023-3319
5.4 medium

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iDisplay PlatPlay DS allows Stored XSS. This issue affects PlatPlay DS: before 3.14.

Idisplay Platplay Ds Jul 13, 2023
CVE-2023-33162
5.5 medium

Microsoft Excel Information Disclosure Vulnerability

Microsoft 365 Apps Jul 11, 2023
CVE-2023-33153
6.8 medium

Microsoft Outlook Remote Code Execution Vulnerability

Microsoft 365 Apps Jul 11, 2023
CVE-2023-33151
6.5 medium

Microsoft Outlook Spoofing Vulnerability

Microsoft 365 Apps Jul 11, 2023
CVE-2023-35699
5.3 medium

Cleartext Storage on Disk in the SICK ICR890-4 could allow an unauthenticated attacker with local access to the device to disclose sensitive information by accessing a SD card.

Sick Icr890-4 Firmware Jul 10, 2023
CVE-2023-35698
5.3 medium

Observable Response Discrepancy in the SICK ICR890-4 could allow a remote attacker to identify valid usernames for the FTP server from the response given during a failed login attempt.

Sick Icr890-4 Firmware Jul 10, 2023
CVE-2023-35697
5.3 medium

Improper Restriction of Excessive Authentication Attempts in the SICK ICR890-4 could allow a remote attacker to brute-force user credentials.

Sick Icr890-4 Firmware Jul 10, 2023
CVE-2023-2853
6.1 medium

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Softmed SelfPatron allows Reflected XSS.This issue affects SelfPatron : before 2.0.

Softmedyazilim Selfpatron Jul 10, 2023
CVE-2023-2886
4.3 medium

Missing Origin Validation in WebSockets vulnerability in CBOT Chatbot allows Content Spoofing Via Application API Manipulation.This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.

Cbot Cbot Core May 25, 2023
CVE-2023-31409
5.3 medium

Uncontrolled Resource Consumption in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an remote attacker to influence the availability of the webserver by invocing a Slowloris style attack via HTTP requests.

Sick Ftmg-Esd20Axx Firmware May 15, 2023
CVE-2023-31408
5.3 medium

Cleartext Storage of Sensitive Information in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to potentially steal user credentials that are stored in the user’s browsers local storage via cross-site-scripting attacks.

Sick Ftmg-Esd20Axx Firmware May 15, 2023
CVE-2023-23450
6.2 medium

Use of Password Hash Instead of Password for Authentication in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows an unprivileged remote attacker to use a password hash instead of an actual password to login to a valid user account via the

Sick Ftmg-Esd20Axx Firmware May 15, 2023
CVE-2023-23449
5.3 medium

Observable Response Discrepancy in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames by analyzing challenge responses from the server via the REST interface.

Sick Ftmg-Esd20Axx Firmware May 15, 2023
CVE-2023-23448
5.3 medium

Inclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 1122524, 1122526 allows a remote attacker to gain information about valid usernames via analysis of source code.

Sick Ftmg-Esd20Axx Firmware May 15, 2023