Show filters
255 Total Results
Displaying 101-110 of 255
Sort by:
Attacker Value
Unknown
CVE-2023-5311
Disclosure Date: October 25, 2023 (last updated February 25, 2025)
The WP EXtra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the register() function in versions up to, and including, 6.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to modify the contents of the .htaccess files located in a site's root directory or /wp-content and /wp-includes folders and achieve remote code execution.
0
Attacker Value
Unknown
CVE-2023-45386
Disclosure Date: October 17, 2023 (last updated February 25, 2025)
In the module extratabspro before version 2.2.8 from MyPresta.eu for PrestaShop, a guest can perform SQL injection via `extratabspro::searchcategory()`, `extratabspro::searchproduct()` and `extratabspro::searchmanufacturer().'
0
Attacker Value
Unknown
CVE-2023-4469
Disclosure Date: October 06, 2023 (last updated November 09, 2023)
The Profile Extra Fields by BestWebSoft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the prflxtrflds_export_file function in versions up to, and including, 1.2.7. This makes it possible for unauthenticated attackers to expose potentially sensitive user data, including data entered into custom fields.
0
Attacker Value
Unknown
CVE-2023-3428
Disclosure Date: October 04, 2023 (last updated February 25, 2025)
A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local attacker to trick the user into opening a specially crafted file, resulting in an application crash and denial of service.
0
Attacker Value
Unknown
CVE-2023-40201
Disclosure Date: October 03, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in FuturioWP Futurio Extra plugin <= 1.8.4 versions leads to activation of arbitrary plugin.
0
Attacker Value
Unknown
CVE-2022-4318
Disclosure Date: September 25, 2023 (last updated February 25, 2025)
A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.
0
Attacker Value
Unknown
CVE-2023-38253
Disclosure Date: July 14, 2023 (last updated February 25, 2025)
An out-of-bounds read flaw was found in w3m, in the growbuf_to_Str function in indep.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.
0
Attacker Value
Unknown
CVE-2023-38252
Disclosure Date: July 14, 2023 (last updated February 25, 2025)
An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.
0
Attacker Value
Unknown
CVE-2020-36760
Disclosure Date: July 12, 2023 (last updated November 09, 2023)
The Ocean Extra plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.5]. This is due to missing or incorrect nonce validation on the add_core_extensions_bundle_validation() function. This makes it possible for unauthenticated attackers to validate extension bundles via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2023-34432
Disclosure Date: July 10, 2023 (last updated February 25, 2025)
A heap buffer overflow vulnerability was found in sox, in the lsx_readbuf function at sox/src/formats_i.c:98:16. This flaw can lead to a denial of service, code execution, or information disclosure.
0