Show filters
68 Total Results
Displaying 11-20 of 68
Sort by:
Attacker Value
Unknown

CVE-2023-52203

Disclosure Date: January 08, 2024 (last updated January 12, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Oliver Seidel, Bastian Germann cformsII allows Stored XSS.This issue affects cformsII: from n/a through 15.0.5.
Attacker Value
Unknown

CVE-2023-43902

Disclosure Date: November 14, 2023 (last updated November 18, 2023)
Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator privileges via a crafted password reset token.
Attacker Value
Unknown

CVE-2023-43901

Disclosure Date: November 14, 2023 (last updated November 18, 2023)
Incorrect access control in the AdHoc User creation form of EMSigner v2.8.7 allows unauthenticated attackers to arbitrarily modify usernames and privileges by using the email address of a registered user.
Attacker Value
Unknown

CVE-2023-43900

Disclosure Date: November 14, 2023 (last updated November 18, 2023)
Insecure Direct Object References (IDOR) in EMSigner v2.8.7 allow attackers to gain unauthorized access to application content and view sensitive data of other users via manipulation of the documentID and EncryptedDocumentId parameters.
Attacker Value
Unknown

CVE-2023-44475

Disclosure Date: October 10, 2023 (last updated October 13, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Michael Simpson Add Shortcodes Actions And Filters plugin <= 2.0.9 versions.
Attacker Value
Unknown

CVE-2023-25449

Disclosure Date: June 15, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Oliver Seidel, Bastian Germann cformsII plugin <= 15.0.4 versions.
Attacker Value
Unknown

CVE-2016-15024

Disclosure Date: February 19, 2023 (last updated October 20, 2023)
A vulnerability was found in doomsider shadow. It has been classified as problematic. Affected is an unknown function. The manipulation leads to denial of service. Attacking locally is a requirement. The complexity of an attack is rather high. The exploitability is told to be difficult. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The patch is identified as 3332c5ba9ec3014ddc74e2147190a050eee97bc0. It is recommended to apply a patch to fix this issue. VDB-221478 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2021-32415

Disclosure Date: December 13, 2022 (last updated October 08, 2023)
EXEMSI MSI Wrapper Versions prior to 10.0.50 and at least since version 6.0.91 will introduce a local privilege escalation vulnerability in installers it creates.
Attacker Value
Unknown

CVE-2022-31877

Disclosure Date: November 28, 2022 (last updated October 08, 2023)
An issue in the component MSI.TerminalServer.exe of MSI Center v1.0.41.0 allows attackers to escalate privileges via a crafted TCP packet.
Attacker Value
Unknown

CVE-2022-38532

Disclosure Date: September 19, 2022 (last updated October 08, 2023)
Micro-Star International Co., Ltd MSI Center 1.0.50.0 was discovered to contain a vulnerability in the component C_Features of MSI.CentralServer.exe. This vulnerability allows attackers to escalate privileges via running a crafted executable.