Show filters
1,040 Total Results
Displaying 221-230 of 1,040
Sort by:
Attacker Value
Unknown

CVE-2023-40050

Disclosure Date: October 31, 2023 (last updated February 25, 2025)
Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution.
Attacker Value
Unknown

CVE-2023-43792

Disclosure Date: October 30, 2023 (last updated February 25, 2025)
baserCMS is a website development framework. In versions 4.6.0 through 4.7.6, there is a Code Injection vulnerability in the mail form of baserCMS. As of time of publication, no known patched versions are available.
Attacker Value
Unknown

CVE-2020-36767

Disclosure Date: October 30, 2023 (last updated February 25, 2025)
tinyfiledialogs (aka tiny file dialogs) before 3.8.0 allows shell metacharacters in titles, messages, and other input data.
Attacker Value
Unknown

CVE-2023-44141

Disclosure Date: October 30, 2023 (last updated February 25, 2025)
Inkdrop prior to v5.6.0 allows a local attacker to conduct a code injection attack by having a legitimate user open a specially crafted markdown file.
Attacker Value
Unknown

CVE-2023-46865

Disclosure Date: October 30, 2023 (last updated February 25, 2025)
/api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an image/png IDAT chunk of a Company Logo image.
Attacker Value
Unknown

CVE-2021-33636

Disclosure Date: October 29, 2023 (last updated February 25, 2025)
When the isula load command is used to load malicious images, attackers can execute arbitrary code.
Attacker Value
Unknown

CVE-2021-33635

Disclosure Date: October 29, 2023 (last updated February 25, 2025)
When malicious images are pulled by isula pull, attackers can execute arbitrary code.
Attacker Value
Unknown

CVE-2023-46509

Disclosure Date: October 27, 2023 (last updated February 25, 2025)
An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.
Attacker Value
Unknown

CVE-2023-46818

Disclosure Date: October 27, 2023 (last updated February 25, 2025)
An issue was discovered in ISPConfig before 3.2.11p1. PHP code injection can be achieved in the language file editor by an admin if admin_allow_langedit is enabled.
Attacker Value
Unknown

CVE-2023-46816

Disclosure Date: October 27, 2023 (last updated February 25, 2025)
An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. A Server Site Template Injection (SSTI) vulnerability has been identified in the GecControl action. By using a crafted request, custom PHP code can be injected via the GetControl action because of missing input validation. An attacker with regular user privileges can exploit this.