Show filters
48 Total Results
Displaying 11-20 of 48
Sort by:
Attacker Value
Unknown
CVE-2023-33411
Disclosure Date: December 07, 2023 (last updated December 13, 2023)
A web server in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions up to 3.17.02, allows remote unauthenticated users to perform directory traversal, potentially disclosing sensitive information.
0
Attacker Value
Unknown
CVE-2023-4975
Disclosure Date: October 20, 2023 (last updated October 27, 2023)
The Website Builder by SeedProd plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.15.13.1. This is due to missing or incorrect nonce validation on functionality in the builder.php file. This makes it possible for unauthenticated attackers to change the stripe connect token via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2023-34853
Disclosure Date: August 22, 2023 (last updated October 08, 2023)
Buffer Overflow vulnerability in Supermicro motherboard X12DPG-QR 1.4b allows local attackers to hijack control flow via manipulation of SmcSecurityEraseSetupVar variable.
0
Attacker Value
Unknown
CVE-2023-35861
Disclosure Date: July 31, 2023 (last updated October 08, 2023)
A shell-injection vulnerability in email notifications on Supermicro motherboards (such as H12DST-B before 03.10.35) allows remote attackers to inject execute arbitrary commands as root on the BMC.
0
Attacker Value
Unknown
CVE-2021-39421
Disclosure Date: July 24, 2023 (last updated October 08, 2023)
A cross-site scripting (XSS) vulnerability in SeedDMS v6.0.15 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
0
Attacker Value
Unknown
CVE-2021-39425
Disclosure Date: July 20, 2023 (last updated October 08, 2023)
SeedDMS v6.0.15 was discovered to contain an open redirect vulnerability. An attacker may exploit this vulnerability to redirect users to arbitrary web URLs by tricking the victim users to click on crafted links.
0
Attacker Value
Unknown
CVE-2023-35779
Disclosure Date: June 19, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Seed Webs Seed Fonts plugin <= 2.3.1 versions.
0
Attacker Value
Unknown
CVE-2021-33223
Disclosure Date: June 07, 2023 (last updated October 08, 2023)
An issue discovered in SeedDMS 6.0.15 allows an attacker to escalate privileges via the userid and role parameters in the out.UsrMgr.php file.
0
Attacker Value
Unknown
CVE-2017-20164
Disclosure Date: January 07, 2023 (last updated October 25, 2023)
A vulnerability was found in Symbiote Seed up to 6.0.2. It has been classified as critical. Affected is the function onBeforeSecurityLogin of the file code/extensions/SecurityLoginExtension.php of the component Login. The manipulation of the argument URL leads to open redirect. It is possible to launch the attack remotely. Upgrading to version 6.0.3 is able to address this issue. The patch is identified as b065ebd82da53009d273aa7e989191f701485244. It is recommended to upgrade the affected component. VDB-217626 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2022-44938
Disclosure Date: December 08, 2022 (last updated February 24, 2025)
Weak reset token generation in SeedDMS v6.0.20 and v5.1.7 allows attackers to execute a full account takeover via a brute force attack.
0