Show filters
461 Total Results
Displaying 101-110 of 461
Sort by:
Attacker Value
Unknown

CVE-2023-4769

Disclosure Date: November 03, 2023 (last updated November 14, 2023)
A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfig.do component. This vulnerability could allow an authenticated attacker to launch targeted attacks, such as a cross-port attack, service enumeration and other attacks via HTTP requests.
Attacker Value
Unknown

CVE-2023-4768

Disclosure Date: November 03, 2023 (last updated November 14, 2023)
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.pdf.
Attacker Value
Unknown

CVE-2023-4767

Disclosure Date: November 03, 2023 (last updated November 14, 2023)
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.csv.
Attacker Value
Unknown

CVE-2023-43485

Disclosure Date: October 10, 2023 (last updated October 18, 2023)
When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audit log.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Attacker Value
Unknown

CVE-2023-41964

Disclosure Date: October 10, 2023 (last updated October 18, 2023)
The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Attacker Value
Unknown

CVE-2023-41854

Disclosure Date: October 10, 2023 (last updated October 13, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Softaculous Ltd. WpCentral plugin <= 1.5.7 versions.
Attacker Value
Unknown

CVE-2023-40519

Disclosure Date: October 03, 2023 (last updated October 09, 2023)
A cross-site scripting (XSS) vulnerability in the bpk-common/auth/login/index.html login portal in Broadpeak Centralized Accounts Management Auth Agent 01.01.00.19219575_ee9195b0, 01.01.01.30097902_fd999e76, and 00.12.01.9565588_1254b459 allows remote attackers to inject arbitrary web script or HTML via the disconnectMessage parameter.
Attacker Value
Unknown

CVE-2023-4129

Disclosure Date: September 27, 2023 (last updated October 08, 2023)
Dell Data Protection Central, version 19.9, contains an Inadequate Encryption Strength Vulnerability. An unauthenticated network attacker could potentially exploit this vulnerability, allowing an attacker to recover plaintext from a block of ciphertext.
Attacker Value
Unknown

CVE-2023-38167

Disclosure Date: August 08, 2023 (last updated January 11, 2025)
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2023-30297

Disclosure Date: August 04, 2023 (last updated October 08, 2023)
An issue found in N-able Technologies N-central Server before 2023.4 allows a local attacker to execute arbitrary code via the monitoring function of the server.