Show filters
1,040 Total Results
Displaying 221-230 of 1,040
Sort by:
Attacker Value
Unknown
CVE-2023-40050
Disclosure Date: October 31, 2023 (last updated February 25, 2025)
Upload profile either
through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec
check command with maliciously crafted profile allows remote code execution.
0
Attacker Value
Unknown
CVE-2023-43792
Disclosure Date: October 30, 2023 (last updated February 25, 2025)
baserCMS is a website development framework. In versions 4.6.0 through 4.7.6, there is a Code Injection vulnerability in the mail form of baserCMS. As of time of publication, no known patched versions are available.
0
Attacker Value
Unknown
CVE-2020-36767
Disclosure Date: October 30, 2023 (last updated February 25, 2025)
tinyfiledialogs (aka tiny file dialogs) before 3.8.0 allows shell metacharacters in titles, messages, and other input data.
0
Attacker Value
Unknown
CVE-2023-44141
Disclosure Date: October 30, 2023 (last updated February 25, 2025)
Inkdrop prior to v5.6.0 allows a local attacker to conduct a code injection attack by having a legitimate user open a specially crafted markdown file.
0
Attacker Value
Unknown
CVE-2023-46865
Disclosure Date: October 30, 2023 (last updated February 25, 2025)
/api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an image/png IDAT chunk of a Company Logo image.
0
Attacker Value
Unknown
CVE-2021-33636
Disclosure Date: October 29, 2023 (last updated February 25, 2025)
When the isula load command is used to load malicious images, attackers can execute arbitrary code.
0
Attacker Value
Unknown
CVE-2021-33635
Disclosure Date: October 29, 2023 (last updated February 25, 2025)
When malicious images are pulled by isula pull, attackers can execute arbitrary code.
0
Attacker Value
Unknown
CVE-2023-46509
Disclosure Date: October 27, 2023 (last updated February 25, 2025)
An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.
0
Attacker Value
Unknown
CVE-2023-46818
Disclosure Date: October 27, 2023 (last updated February 25, 2025)
An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_langedit is enabled.
0
Attacker Value
Unknown
CVE-2023-46816
Disclosure Date: October 27, 2023 (last updated February 25, 2025)
An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. A Server Site Template Injection (SSTI) vulnerability has been identified in the GecControl action. By using a crafted request, custom PHP code can be injected via the GetControl action because of missing input validation. An attacker with regular user privileges can exploit this.
0