Show filters
332 Total Results
Displaying 101-110 of 332
Sort by:
Attacker Value
Unknown

CVE-2023-37656

Disclosure Date: July 11, 2023 (last updated October 08, 2023)
WebsiteGuide v0.2 is vulnerable to Remote Command Execution (RCE) via image upload.
Attacker Value
Unknown

CVE-2023-22673

Disclosure Date: July 10, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in MageNet Website Monetization by MageNet plugin <= 1.0.29.1 versions.
Attacker Value
Unknown

CVE-2023-3534

Disclosure Date: July 07, 2023 (last updated February 17, 2024)
A vulnerability was found in SourceCodester Shopping Website 1.0. It has been classified as critical. Affected is an unknown function of the file check_availability.php. The manipulation of the argument email leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-233286 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-3503

Disclosure Date: July 04, 2023 (last updated February 17, 2024)
A vulnerability has been found in SourceCodester Shopping Website 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file insert-product.php. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-232951.
Attacker Value
Unknown

CVE-2023-3502

Disclosure Date: July 04, 2023 (last updated February 17, 2024)
A vulnerability, which was classified as critical, was found in SourceCodester Shopping Website 1.0. Affected is an unknown function of the file search-result.php. The manipulation of the argument product leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-232950 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-36817

Disclosure Date: July 03, 2023 (last updated February 25, 2025)
`tktchurch/website` contains the codebase for The King's Temple Church website. In version 0.1.0, a Stripe API key was found in the public code repository of the church's project. This sensitive information was unintentionally committed and subsequently exposed in the codebase. If an unauthorized party gains access to this key, they could potentially carry out transactions on behalf of the organization, leading to financial losses. Additionally, they could access sensitive customer information, leading to privacy violations and potential legal implications. The affected component is the codebase of our project, specifically the file(s) where the Stripe API key is embedded. The key should have been stored securely, and not committed to the codebase. The maintainers plan to revoke the leaked Stripe API key immediately, generate a new one, and not commit the key to the codebase.
Attacker Value
Unknown

CVE-2023-3458

Disclosure Date: June 29, 2023 (last updated February 25, 2025)
A vulnerability was found in SourceCodester Shopping Website 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file forgot-password.php. The manipulation of the argument contact leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-232675.
Attacker Value
Unknown

CVE-2023-3457

Disclosure Date: June 29, 2023 (last updated February 25, 2025)
A vulnerability was found in SourceCodester Shopping Website 1.0. It has been classified as critical. Affected is an unknown function of the file index.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-232674 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2020-36722

Disclosure Date: June 07, 2023 (last updated February 25, 2025)
The Visual Composer plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 26.0 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
Attacker Value
Unknown

CVE-2020-36703

Disclosure Date: June 07, 2023 (last updated February 25, 2025)
The Elementor Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG image uploads in versions up to, and including 2.9.7 This makes it possible for authenticated attackers with the upload_files capability to inject arbitrary web scripts in pages that will execute whenever a user accesses the page with the stored web scripts.