Show filters
234 Total Results
Displaying 101-110 of 234
Sort by:
Attacker Value
Unknown

CVE-2023-36691

Disclosure Date: July 10, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Albert Peschar WebwinkelKeur plugin <= 3.24 versions.
Attacker Value
Unknown

CVE-2023-22834

Disclosure Date: June 27, 2023 (last updated February 25, 2025)
The Contour Service was not checking that users had permission to create an analysis for a given dataset. This could allow an attacker to clutter up Compass folders with extraneous analyses, that the attacker would otherwise not have permission to create.
Attacker Value
Unknown

CVE-2023-2634

Disclosure Date: June 05, 2023 (last updated October 08, 2023)
The Get your number WordPress plugin through 1.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Attacker Value
Unknown

CVE-2023-23883

Disclosure Date: May 09, 2023 (last updated February 24, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in David Gwyer WP Content Filter plugin <= 3.0.1 versions.
Attacker Value
Unknown

CVE-2023-30797

Disclosure Date: April 19, 2023 (last updated February 24, 2025)
Netflix Lemur before version 1.3.2 used insufficiently random values when generating default credentials. The insufficiently random values may allow an attacker to guess the credentials and gain access to resources managed by Lemur.
Attacker Value
Unknown

CVE-2023-23591

Disclosure Date: April 12, 2023 (last updated February 24, 2025)
The Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain sensitive information from application server logs when debug logging is enabled. The fixed versions are 8.2.18.7, 8.2.18.2.2, 8.3.11.1, and 8.3.14.1.
Attacker Value
Unknown

CVE-2023-26860

Disclosure Date: April 10, 2023 (last updated February 24, 2025)
SQL injection vulnerability found in PrestaShop Igbudget v.1.0.3 and before allow a remote attacker to gain privileges via the LgBudgetBudgetModuleFrontController::displayAjaxGenerateBudget component.
Attacker Value
Unknown

CVE-2023-1738

Disclosure Date: March 30, 2023 (last updated February 24, 2025)
A vulnerability has been found in SourceCodester Young Entrepreneur E-Negosyo System 1.0 and classified as critical. This vulnerability affects unknown code of the file index.php?q=product. The manipulation of the argument search leads to sql injection. The attack can be initiated remotely. VDB-224626 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-1737

Disclosure Date: March 30, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as critical, was found in SourceCodester Young Entrepreneur E-Negosyo System 1.0. This affects an unknown part of the file login.php. The manipulation of the argument U_USERNAME leads to sql injection. It is possible to initiate the attack remotely. The identifier VDB-224625 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-1736

Disclosure Date: March 30, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as critical, has been found in SourceCodester Young Entrepreneur E-Negosyo System 1.0. Affected by this issue is some unknown functionality of the file cart/controller.php?action=add. The manipulation of the argument PROID leads to sql injection. The identifier of this vulnerability is VDB-224624.