Show filters
68 Total Results
Displaying 11-20 of 68
Sort by:
Attacker Value
Unknown
CVE-2023-48042
Disclosure Date: November 28, 2023 (last updated December 01, 2023)
Cross Site Scripting (XSS) in Search filters in Prestashop Amazzing filter version up to version 3.2.5, allows remote attackers to inject arbitrary JavaScript code.
0
Attacker Value
Unknown
CVE-2023-44962
Disclosure Date: October 11, 2023 (last updated October 17, 2023)
File Upload vulnerability in Koha Library Software 23.05.04 and before allows a remote attacker to read arbitrary files via the upload-cover-image.pl component.
0
Attacker Value
Unknown
CVE-2023-44961
Disclosure Date: October 11, 2023 (last updated October 17, 2023)
SQL Injection vulnerability in Koha Library Software 23.0.5.04 and before allows a remote attacker to obtain sensitive information via the intranet/cgi bin/cataloging/ysearch.pl. component.
0
Attacker Value
Unknown
CVE-2023-37250
Disclosure Date: August 20, 2023 (last updated October 08, 2023)
Unity Parsec has a TOCTOU race condition that permits local attackers to escalate privileges to SYSTEM if Parsec was installed in "Per User" mode. The application intentionally launches DLLs from a user-owned directory but intended to always perform integrity verification of those DLLs. This affects Parsec Loader versions through 8. Parsec Loader 9 is a fixed version.
0
Attacker Value
Unknown
CVE-2022-44742
Disclosure Date: March 23, 2023 (last updated November 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting vulnerability in Yannick Lefebvre Community Events plugin <= 1.4.8 versions.
0
Attacker Value
Unknown
CVE-2021-40604
Disclosure Date: June 13, 2022 (last updated October 07, 2023)
A Server-Side Request Forgery (SSRF) vulnerability in IPS Community Suite before 4.6.2 allows remote authenticated users to request arbitrary URLs or trigger deserialization via phar protocol when generating class names dynamically. In some cases an exploitation is possible by an unauthenticated user.
0
Attacker Value
Unknown
CVE-2021-39250
Disclosure Date: August 17, 2021 (last updated February 23, 2025)
Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows stored XSS, with resultant code execution, because an uploaded file can be placed in an IFRAME element within user-generated content. For code execution, the attacker can rely on the ability of an admin to install widgets, disclosure of the admin session ID in a Referer header, and the ability of an admin to use the templating engine (e.g., Edit HTML).
0
Attacker Value
Unknown
CVE-2021-39249
Disclosure Date: August 17, 2021 (last updated February 23, 2025)
Invision Community (aka IPS Community Suite or IP-Board) before 4.6.5.1 allows reflected XSS because the filenames of uploaded files become predictable through a brute-force attack against the PHP mt_rand function.
0
Attacker Value
Unknown
CVE-2021-24496
Disclosure Date: August 02, 2021 (last updated February 23, 2025)
The Community Events WordPress plugin before 1.4.8 does not sanitise, validate or escape its importrowscount and successimportcount GET parameters before outputting them back in an admin page, leading to a reflected Cross-Site Scripting issue which will be executed in the context of a logged in administrator
0
Attacker Value
Unknown
CVE-2021-32924
Disclosure Date: June 01, 2021 (last updated February 22, 2025)
Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because the IPS\cms\modules\front\pages\_builder::previewBlock method interacts unsafely with the IPS\_Theme::runProcessFunction method.
0