Show filters
780 Total Results
Displaying 151-160 of 780
Sort by:
Attacker Value
Unknown
CVE-2023-31414
Disclosure Date: May 04, 2023 (last updated February 24, 2025)
Kibana versions 8.0.0 through 8.7.0 contain an arbitrary code execution flaw. An attacker with write access to Kibana yaml or env configuration could add a specific payload that will attempt to execute JavaScript code. This could lead to the attacker executing arbitrary commands on the host system with permissions of the Kibana process.
0
Attacker Value
Unknown
CVE-2023-1178
Disclosure Date: May 03, 2023 (last updated February 24, 2025)
An issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. File integrity may be compromised when source code or installation packages are pulled from a tag or from a release containing a ref to another commit.
0
Attacker Value
Unknown
CVE-2023-26546
Disclosure Date: May 02, 2023 (last updated February 24, 2025)
European Chemicals Agency IUCLID before 6.27.6 allows remote authenticated users to execute arbitrary code via Server Side Template Injection (SSTI) with a crafted template file. The attacker must have template manager permission.
0
Attacker Value
Unknown
CVE-2023-26782
Disclosure Date: April 28, 2023 (last updated February 24, 2025)
An issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interface ->System Configuration->Cache Configuration->Cache security characters.
0
Attacker Value
Unknown
CVE-2023-2360
Disclosure Date: April 28, 2023 (last updated February 24, 2025)
Sensitive information disclosure due to CORS misconfiguration. The following products are affected: Acronis Cyber Infrastructure (ACI) before build 5.2.0-135.
0
Attacker Value
Unknown
CVE-2023-30349
Disclosure Date: April 27, 2023 (last updated February 24, 2025)
JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function.
0
Attacker Value
Unknown
CVE-2023-30404
Disclosure Date: April 26, 2023 (last updated February 24, 2025)
Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability via the sysCmd parameter in the formSysCmd function. This vulnerability is exploited via a crafted HTTP request.
0
Attacker Value
Unknown
CVE-2023-2259
Disclosure Date: April 24, 2023 (last updated February 24, 2025)
Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.
0
Attacker Value
Unknown
CVE-2023-29566
Disclosure Date: April 24, 2023 (last updated February 24, 2025)
huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.
0
Attacker Value
Unknown
CVE-2023-26060
Disclosure Date: April 24, 2023 (last updated February 24, 2025)
An issue was discovered in Nokia NetAct before 22 FP2211. On the Working Set Manager page, users can create a Working Set with a name that has a client-side template injection payload. Input validation is missing during creation of the working set. For an external attacker, it is very difficult to exploit this, because a few dynamically created parameters such as Jsession-id, a CSRF token, and an Nxsrf token would be needed. The attack can realistically only be performed by an internal user.
0