Show filters
285 Total Results
Displaying 101-110 of 285
Sort by:
Attacker Value
Unknown

CVE-2023-31459

Disclosure Date: May 24, 2023 (last updated October 08, 2023)
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect versions 9.6.2208.101 and earlier could allow an unauthenticated attacker with internal network access to authenticate with administrative privileges, because the initial installation does not enforce a password change. A successful exploit could allow an attacker to make arbitrary configuration changes and execute arbitrary commands.
Attacker Value
Unknown

CVE-2023-31457

Disclosure Date: May 24, 2023 (last updated October 08, 2023)
A vulnerability in the Headquarters server component of Mitel MiVoice Connect versions 19.3 SP2 (22.24.1500.0) and earlier could allow an unauthenticated attacker with internal network access to execute arbitrary scripts due to improper access control.
Attacker Value
Unknown

CVE-2023-25598

Disclosure Date: May 24, 2023 (last updated October 08, 2023)
A vulnerability in the conferencing component of Mitel MiVoice Connect through 19.3 SP2 and 20.x, 21.x, and 22.x through 22.24.1500.0 could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the home.php page. A successful exploit could allow an attacker to execute arbitrary scripts.
Attacker Value
Unknown

CVE-2023-2180

Disclosure Date: May 15, 2023 (last updated October 08, 2023)
The KIWIZ Invoices Certification & PDF System WordPress plugin through 2.1.3 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/downlaod arbitrary files, as well as perform PHAR unserialization (assuming they can upload a file on the server)
Attacker Value
Unknown

CVE-2023-28313

Disclosure Date: April 11, 2023 (last updated January 11, 2025)
Microsoft Dynamics 365 Customer Voice Cross-Site Scripting Vulnerability
Attacker Value
Unknown

CVE-2022-47148

Disclosure Date: March 01, 2023 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in WP Overnight PDF Invoices & Packing Slips for WooCommerce plugin <= 3.2.5 leading to popup dismiss.
Attacker Value
Unknown

CVE-2023-23011

Disclosure Date: February 07, 2023 (last updated February 24, 2025)
Cross Site Scripting (XSS) vulnerability in InvoicePlane 1.6 via filter_product input to file modal_product_lookups.php.
Attacker Value
Unknown

CVE-2023-0070

Disclosure Date: February 06, 2023 (last updated October 08, 2023)
The ResponsiveVoice Text To Speech WordPress plugin before 1.7.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2022-4372

Disclosure Date: January 02, 2023 (last updated October 08, 2023)
The Web Invoice WordPress plugin through 2.1.3 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by high privilege users such as admin by default. However, depending on the plugin configuration, other users, such as subscriber could exploit this as well
Attacker Value
Unknown

CVE-2022-4371

Disclosure Date: January 02, 2023 (last updated October 08, 2023)
The Web Invoice WordPress plugin through 2.1.3 does not properly sanitize and escape a parameter before using it in a SQL statement, leading to a SQL Injection exploitable by high privilege users such as admin by default. However, depending on the plugin configuration, other users, such as subscriber could exploit this as well