Show filters
100 Total Results
Displaying 11-20 of 100
Sort by:
Attacker Value
Unknown
CVE-2021-4427
Disclosure Date: July 12, 2023 (last updated November 09, 2023)
The Vuukle Comments, Reactions, Share Bar, Revenue plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.31. This is due to missing or incorrect nonce validation in the /admin/partials/free-comments-for-wordpress-vuukle-admin-display.php file. This makes it possible for unauthenticated attackers to edit the plugins settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2023-35948
Disclosure Date: July 06, 2023 (last updated October 08, 2023)
Novu provides an API for sending notifications through multiple channels. Versions prior to 0.16.0 contain an open redirect vulnerability in the "Sign In with GitHub" functionality of Novu's open-source repository. It could have allowed an attacker to force a victim into opening a malicious URL and thus, potentially log into the repository under the victim's account gaining full control of the account. This vulnerability only affected the Novu Cloud and Open-Source deployments if the user manually enabled the GitHub OAuth on their self-hosted instance of Novu. Users should upgrade to version 0.16.0 to receive a patch.
0
Attacker Value
Unknown
CVE-2023-3520
Disclosure Date: July 06, 2023 (last updated October 08, 2023)
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in GitHub repository it-novum/openitcockpit prior to 4.6.6.
0
Attacker Value
Unknown
CVE-2023-36663
Disclosure Date: June 25, 2023 (last updated October 08, 2023)
it-novum openITCOCKPIT (aka open IT COCKPIT) 4.6.4 before 4.6.5 allows SQL Injection (by authenticated users) via the sort parameter of the API interface.
0
Attacker Value
Unknown
CVE-2023-3218
Disclosure Date: June 13, 2023 (last updated October 08, 2023)
Race Condition within a Thread in GitHub repository it-novum/openitcockpit prior to 4.6.5.
0
Attacker Value
Unknown
CVE-2023-27748
Disclosure Date: April 13, 2023 (last updated October 08, 2023)
BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authenticity check for uploaded firmware. This can allow attackers to upload crafted firmware which contains backdoors and enables arbitrary code execution.
0
Attacker Value
Unknown
CVE-2023-27747
Disclosure Date: April 13, 2023 (last updated October 08, 2023)
BlackVue DR750-2CH LTE v.1.012_2022.10.26 does not employ authentication in its web server. This vulnerability allows attackers to access sensitive information such as configurations and recordings.
0
Attacker Value
Unknown
CVE-2023-27746
Disclosure Date: April 13, 2023 (last updated October 08, 2023)
BlackVue DR750-2CH LTE v.1.012_2022.10.26 was discovered to contain a weak default passphrase which can be easily cracked via a brute force attack if the WPA2 handshake is intercepted.
0
Attacker Value
Unknown
CVE-2022-47762
Disclosure Date: February 03, 2023 (last updated October 08, 2023)
In gin-vue-admin < 2.5.5, the download module has a Path Traversal vulnerability.
0
Attacker Value
Unknown
CVE-2022-39345
Disclosure Date: October 25, 2022 (last updated October 08, 2023)
Gin-vue-admin is a backstage management system based on vue and gin, which separates the front and rear of the full stack. Gin-vue-admin prior to 2.5.4 is vulnerable to path traversal, which leads to file upload vulnerabilities. Version 2.5.4 contains a patch for this issue. There are no workarounds aside from upgrading to a patched version.
0