Show filters
1,999 Total Results
Displaying 101-110 of 1,999
Sort by:
Attacker Value
Unknown

CVE-2017-20187

Disclosure Date: November 05, 2023 (last updated February 25, 2025)
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Magnesium-PHP up to 0.3.0. It has been classified as problematic. Affected is the function formatEmailString of the file src/Magnesium/Message/Base.php. The manipulation of the argument email/name leads to injection. Upgrading to version 0.3.1 is able to address this issue. The patch is identified as 500d340e1f6421007413cc08a8383475221c2604. It is recommended to upgrade the affected component. VDB-244482 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Attacker Value
Unknown

CVE-2022-4900

Disclosure Date: November 02, 2023 (last updated February 25, 2025)
A vulnerability was found in PHP where setting the environment variable PHP_CLI_SERVER_WORKERS to a large value leads to a heap buffer overflow.
Attacker Value
Unknown

CVE-2023-5199

Disclosure Date: October 30, 2023 (last updated February 25, 2025)
The PHP to Page plugin for WordPress is vulnerable Local File Inclusion to Remote Code Execution in versions up to, and including, 0.3 via the 'php-to-page' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to include local file and potentially execute code on the server. While subscribers may need to poison log files or otherwise get a file installed in order to achieve remote code execution, author and above users can upload files by default and achieve remote code execution easily.
Attacker Value
Unknown

CVE-2021-4418

Disclosure Date: October 20, 2023 (last updated February 25, 2025)
The Custom CSS, JS & PHP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.7. This is due to missing or incorrect nonce validation on the save() function. This makes it possible for unauthenticated attackers to save code snippets via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2023-45909

Disclosure Date: October 18, 2023 (last updated February 25, 2025)
zzzcms v2.2.0 was discovered to contain an open redirect vulnerability.
Attacker Value
Unknown

CVE-2023-5053

Disclosure Date: September 28, 2023 (last updated February 25, 2025)
Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is vulnerable to SQLI.
Attacker Value
Unknown

CVE-2023-5004

Disclosure Date: September 28, 2023 (last updated February 25, 2025)
Hospital management system version 378c157 allows to bypass authentication. This is possible because the application is vulnerable to SQLI.
Attacker Value
Unknown

CVE-2023-43132

Disclosure Date: September 25, 2023 (last updated February 25, 2025)
szvone vmqphp <=1.13 is vulnerable to SQL Injection. Unauthorized remote users can use sql injection attacks to obtain the hash of the administrator password.
Attacker Value
Unknown

CVE-2023-43144

Disclosure Date: September 22, 2023 (last updated February 25, 2025)
Projectworldsl Assets-management-system-in-php 1.0 is vulnerable to SQL Injection via the "id" parameter in delete.php.
Attacker Value
Unknown

CVE-2023-43274

Disclosure Date: September 21, 2023 (last updated February 25, 2025)
Phpjabbers PHP Shopping Cart 4.2 is vulnerable to SQL Injection via the id parameter.