Show filters
94,105 Total Results
Displaying 351-360 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Very High

CVE-2023-26258

Disclosure Date: July 03, 2023 (last updated February 25, 2025)
Arcserve UDP through 9.0.6034 allows authentication bypass. The method getVersionInfo at WebServiceImpl/services/FlashServiceImpl leaks the AuthUUID token. This token can be used at /WebServiceImpl/services/VirtualStandbyServiceImpl to obtain a valid session. This session can be used to execute any task as administrator.
Attacker Value
Very High

CVE-2023-2068

Disclosure Date: June 27, 2023 (last updated October 08, 2023)
The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is available to unauthenticated users.
Attacker Value
Very High

CVE-2023-30258

Disclosure Date: June 23, 2023 (last updated February 25, 2025)
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.
Attacker Value
Very Low

CVE-2023-2991

Disclosure Date: June 22, 2023 (last updated February 25, 2025)
Fortra Globalscape EFT's administration server suffers from an information disclosure vulnerability where the serial number of the harddrive that Globalscape is installed on can be remotely determined via a "trial extension request" message
Attacker Value
Very Low

CVE-2023-2990

Disclosure Date: June 22, 2023 (last updated February 25, 2025)
Fortra Globalscape EFT versions before 8.1.0.16 suffer from a denial of service vulnerability, where a compressed message that decompresses to itself can cause infinite recursion and crash the service
Attacker Value
Very High

CVE-2023-35885

Disclosure Date: June 20, 2023 (last updated February 25, 2025)
CloudPanel 2 before 2.3.1 has insecure file-manager cookie authentication.
Attacker Value
High

CVE-2023-33145

Disclosure Date: June 14, 2023 (last updated January 11, 2025)
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
Attacker Value
Moderate

CVE-2023-33140

Disclosure Date: June 14, 2023 (last updated March 01, 2025)
Microsoft OneNote Spoofing Vulnerability
2
Attacker Value
High

CVE-2023-33131

Disclosure Date: June 14, 2023 (last updated March 01, 2025)
Microsoft Outlook Remote Code Execution Vulnerability
2
Attacker Value
Very High

CVE-2023-29357

Disclosure Date: June 14, 2023 (last updated February 25, 2025)
Microsoft SharePoint Server Elevation of Privilege Vulnerability