Show filters
255 Total Results
Displaying 101-110 of 255
Sort by:
Attacker Value
Unknown

CVE-2023-5311

Disclosure Date: October 25, 2023 (last updated February 25, 2025)
The WP EXtra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the register() function in versions up to, and including, 6.2. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to modify the contents of the .htaccess files located in a site's root directory or /wp-content and /wp-includes folders and achieve remote code execution.
Attacker Value
Unknown

CVE-2023-45386

Disclosure Date: October 17, 2023 (last updated February 25, 2025)
In the module extratabspro before version 2.2.8 from MyPresta.eu for PrestaShop, a guest can perform SQL injection via `extratabspro::searchcategory()`, `extratabspro::searchproduct()` and `extratabspro::searchmanufacturer().'
Attacker Value
Unknown

CVE-2023-4469

Disclosure Date: October 06, 2023 (last updated November 09, 2023)
The Profile Extra Fields by BestWebSoft plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the prflxtrflds_export_file function in versions up to, and including, 1.2.7. This makes it possible for unauthenticated attackers to expose potentially sensitive user data, including data entered into custom fields.
Attacker Value
Unknown

CVE-2023-3428

Disclosure Date: October 04, 2023 (last updated February 25, 2025)
A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local attacker to trick the user into opening a specially crafted file, resulting in an application crash and denial of service.
Attacker Value
Unknown

CVE-2023-40201

Disclosure Date: October 03, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in FuturioWP Futurio Extra plugin <= 1.8.4 versions leads to activation of arbitrary plugin.
Attacker Value
Unknown

CVE-2022-4318

Disclosure Date: September 25, 2023 (last updated February 25, 2025)
A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable.
Attacker Value
Unknown

CVE-2023-38253

Disclosure Date: July 14, 2023 (last updated February 25, 2025)
An out-of-bounds read flaw was found in w3m, in the growbuf_to_Str function in indep.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.
Attacker Value
Unknown

CVE-2023-38252

Disclosure Date: July 14, 2023 (last updated February 25, 2025)
An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.
Attacker Value
Unknown

CVE-2020-36760

Disclosure Date: July 12, 2023 (last updated November 09, 2023)
The Ocean Extra plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.5]. This is due to missing or incorrect nonce validation on the add_core_extensions_bundle_validation() function. This makes it possible for unauthenticated attackers to validate extension bundles via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2023-34432

Disclosure Date: July 10, 2023 (last updated February 25, 2025)
A heap buffer overflow vulnerability was found in sox, in the lsx_readbuf function at sox/src/formats_i.c:98:16. This flaw can lead to a denial of service, code execution, or information disclosure.