Exploit Database

151,666 exploits tracked across all sources.

Sort: Activity Stars
CVE-2023-42233 WRITEUP MEDIUM
HelpdeskAdvanced <= 11.0.33 - Cross-Site Scripting via Filter/FilterEditor Function
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Scripting (XSS) via the Filter/FilterEditor function.
CVSS 6.1
CVE-2023-42234 WRITEUP MEDIUM
HelpdeskAdvanced <= 11.0.33 - Cross-Site Request Forgery via WSCView Function
Pat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Cross Site Request Forgery (CSRF) via the WSCView function.
CVSS 5.4
CVE-2023-42235 WRITEUP LOW
Selesta Visual Access Manager < 4.42.2 - Authenticated SQL Injection via /monitor/s_normalizedtrans.php Parameters
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple parameters of /monitor/s_normalizedtrans.php.
CVSS 3.8
CVE-2023-42236 WRITEUP LOW
Selesta Visual Access Manager < 4.42.2 - Authenticated SQL Injection via GET Parameter
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in a GET parameter of /common/ajaxfunction.php.
CVSS 3.8
CVE-2023-42237 WRITEUP LOW
Selesta Visual Access Manager < 4.42.2 - Authenticated SQL Injection via vam_i_command.php GET Parameters
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple GET parameters of /vam/vam_i_command.php.
CVSS 3.8
CVE-2023-42238 WRITEUP LOW
Selesta Visual Access Manager < 4.42.2 - Authenticated SQL Injection via /vam/vam_eps.php POST Parameters
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_eps.php.
CVSS 3.8
CVE-2023-42239 WRITEUP LOW
Selesta Visual Access Manager < 4.42.2 - Authenticated SQL Injection via /vam/vam_ep.php POST Parameters
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_ep.php.
CVSS 3.8
CVE-2023-42240 WRITEUP LOW
Selesta Visual Access Manager < 4.42.2 - Authenticated SQL Injection via /monitor/s_scheduledfile.php POST Parameters
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /monitor/s_scheduledfile.php.
CVSS 3.8
CVE-2023-42241 WRITEUP LOW
Selesta Visual Access Manager < 4.42.2 - Authenticated SQL Injection via vam_anagraphic.php POST Parameters
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_anagraphic.php.
CVSS 3.8
CVE-2023-42242 WRITEUP LOW
Selesta Visual Access Manager < 4.42.2 - Authenticated SQL Injection via GET Parameter
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in a GET parameter of /monitor/s_terminal.php.
CVSS 3.8
CVE-2023-42243 WRITEUP MEDIUM
Selesta Visual Access Manager < 4.42.2 - Authenticated SQL Injection via Administrative Page
In Selesta Visual Access Manager < 4.42.2, an authenticated user can access the administrative page /common/vam_Sql.php, which allows for arbitrary SQL queries.
CVSS 5.4
CVE-2023-42244 WRITEUP HIGH
Selesta Visual Access Manager < 4.42.2 - Authenticated SQL Injection via /vam/vam_visits.php POST Parameters
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can perform SQL Injection in multiple POST parameters of /vam/vam_visits.php.
CVSS 8.8
CVE-2023-42245 WRITEUP MEDIUM
Selesta Visual Access Manager < 4.42.2 - Cross-Site Scripting via monitor/s_scheduledfile.php
Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via monitor/s_scheduledfile.php.
CVSS 6.1
CVE-2023-42246 WRITEUP MEDIUM
Selesta Visual Access Manager < 4.42.2 - Cross-Site Scripting via /vam/vam_ep.php
Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via /vam/vam_ep.php.
CVSS 6.1
CVE-2023-42247 WRITEUP MEDIUM
Selesta Visual Access Manager < 4.42.2 - Cross-Site Scripting via monitor/s_monitor_map.php
Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via monitor/s_monitor_map.php.
CVSS 6.1
CVE-2023-42248 WRITEUP MEDIUM
Selesta Visual Access Manager < 4.42.2 - Authenticated Arbitrary File Write via vam_Sql.php POST Parameters
An issue was discovered in Selesta Visual Access Manager (VAM) prior to 4.42.2. An authenticated attacker can write arbitrary files by manipulating POST parameters of the page "common/vam_Sql.php".
CVSS 6.5
CVE-2023-42249 WRITEUP MEDIUM
Selesta Visual Access Manager < 4.42.2 - Cross-Site Scripting via vam/vam_visits.php
Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via vam/vam_visits.php.
CVSS 6.1
CVE-2023-42250 WRITEUP MEDIUM
Selesta Visual Access Manager < 4.42.2 - Cross-Site Scripting via Autocomplete Endpoint
Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via /common/autocomplete.php.
CVSS 6.1
CVE-2023-42467 WRITEUP MEDIUM
QEMU < 8.0.0 - Denial of Service via Division by Zero in SCSI Disk Reset
QEMU through 8.0.0 could trigger a division by zero in scsi_disk_reset in hw/scsi/scsi-disk.c because scsi_disk_emulate_mode_select does not prevent s->qdev.blocksize from being 256. This stops QEMU and the guest immediately.
CVSS 5.5
CVE-2023-46321 WRITEUP CRITICAL
iTerm2 <3.5.0beta12 - Path Traversal
iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize paths in x-man-page URLs. They may have shell metacharacters for a /usr/bin/man command line.
CVSS 9.8
CVE-2023-46322 WRITEUP CRITICAL
iTerm2 < 3.5.0beta12 - OS Command Injection via SSH URL Hostname
iTermSessionLauncher.m in iTerm2 before 3.5.0beta12 does not sanitize ssh hostnames in URLs. The hostname's initial character may be non-alphanumeric. The hostname's other characters may be outside the set of alphanumeric characters, dash, and period.
CVSS 9.8
CVE-2023-48863 WRITEUP HIGH
SEMCMS 3.9 - SQL Injection
SEMCMS 3.9 is vulnerable to SQL Injection. Due to the lack of security checks on the input of the application, the attacker uses the existing application to inject malicious SQL commands into the background database engine for execution, and sends some attack codes as commands or query statements to the interpreter. These malicious data can deceive the interpreter, so as to execute unplanned commands or unauthorized access to data.
CVSS 7.5
CVE-2023-48864 WRITEUP HIGH
SEMCMS v4.8 - SQL Injection via languageID Parameter
SEMCMS v4.8 was discovered to contain a SQL injection vulnerability via the languageID parameter in /web_inc.php.
CVSS 7.5
CVE-2023-4875 WRITEUP LOW
Mutt >1.5.2 <2.2.12 - Memory Corruption
Null pointer dereference when composing from a specially crafted draft message in Mutt >1.5.2 <2.2.12
CVSS 2.2
CVE-2023-49963 WRITEUP HIGH
DYMO LabelWriter Print Server <2.366 - RCE
DYMO LabelWriter Print Server through 2.366 contains a backdoor hard-coded password that could allow an attacker to take control.
CVSS 8.8