Show filters
597 Total Results
Displaying 101-110 of 597
Sort by:
Attacker Value
Unknown

CVE-2023-4757

Disclosure Date: January 16, 2024 (last updated January 24, 2024)
The Staff / Employee Business Directory for Active Directory WordPress plugin before 1.2.3 does not sanitize and escape data returned from the LDAP server before rendering it in the page, allowing users who can control their entries in the LDAP directory to inject malicious javascript which could be used against high-privilege users such as a site admin.
Attacker Value
Unknown

CVE-2023-31229

Disclosure Date: December 29, 2023 (last updated January 06, 2024)
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WP Directory Kit.This issue affects WP Directory Kit: from n/a through 1.1.9.
Attacker Value
Unknown

CVE-2023-50845

Disclosure Date: December 28, 2023 (last updated January 05, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AyeCode - WordPress Business Directory Plugins GeoDirectory – WordPress Business Directory Plugin, or Classified Directory.This issue affects GeoDirectory – WordPress Business Directory Plugin, or Classified Directory: from n/a through 2.3.28.
Attacker Value
Unknown

CVE-2023-5803

Disclosure Date: November 30, 2023 (last updated December 06, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Business Directory Team Business Directory Plugin – Easy Listing Directories for WordPress allows Cross-Site Request Forgery.This issue affects Business Directory Plugin – Easy Listing Directories for WordPress: from n/a through 6.3.10.
Attacker Value
Unknown

CVE-2023-47659

Disclosure Date: November 14, 2023 (last updated November 21, 2023)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Lavacode Lava Directory Manager plugin <= 1.1.34 versions.
Attacker Value
Unknown

CVE-2023-4706

Disclosure Date: November 08, 2023 (last updated November 23, 2023)
A privilege escalation vulnerability was reported in Lenovo preloaded devices deployed using Microsoft AutoPilot under a standard user account due to incorrect default privileges.
Attacker Value
Unknown

CVE-2023-44219

Disclosure Date: October 27, 2023 (last updated November 08, 2023)
A local privilege escalation vulnerability in SonicWall Directory Services Connector Windows MSI client 4.1.21 and earlier versions allows a local low-privileged user to gain system privileges through running the recovery feature.
Attacker Value
Unknown

CVE-2023-46081

Disclosure Date: October 26, 2023 (last updated October 31, 2023)
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Lavacode Lava Directory Manager plugin <= 1.1.34 versions.
Attacker Value
Unknown

CVE-2023-5003

Disclosure Date: October 16, 2023 (last updated October 21, 2023)
The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains accessible to any users knowing the URL to do so.
Attacker Value
Unknown

CVE-2022-33165

Disclosure Date: October 14, 2023 (last updated October 19, 2023)
IBM Security Directory Server 6.4.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 228582.