Show filters
478 Total Results
Displaying 101-110 of 478
Sort by:
Attacker Value
Unknown

CVE-2022-1617

Disclosure Date: January 16, 2024 (last updated January 24, 2024)
The WP-Invoice WordPress plugin through 4.3.1 does not have CSRF check in place when updating its settings, and is lacking sanitisation as well as escaping in some of them, allowing attacker to make a logged in admin change them and add XSS payload in them
Attacker Value
Unknown

CVE-2021-24151

Disclosure Date: January 16, 2024 (last updated January 24, 2024)
The WP Editor WordPress plugin before 1.2.7 did not sanitise or validate its setting fields leading to an authenticated (admin+) blind SQL injection issue via an arbitrary parameter when making a request to save the settings.
Attacker Value
Unknown

CVE-2023-6496

Disclosure Date: January 11, 2024 (last updated January 18, 2024)
The Manage Notification E-mails plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.8.5 via the card_famne_export_settings function. This makes it possible for unauthenticated attackers to obtain plugin settings.
Attacker Value
Unknown

CVE-2023-3043

Disclosure Date: January 09, 2024 (last updated January 13, 2024)
AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack-based buffer overflow via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.
Attacker Value
Unknown

CVE-2023-37297

Disclosure Date: January 09, 2024 (last updated January 13, 2024)
AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.
Attacker Value
Unknown

CVE-2023-37296

Disclosure Date: January 09, 2024 (last updated January 13, 2024)
AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack memory corruption via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.
Attacker Value
Unknown

CVE-2023-37295

Disclosure Date: January 09, 2024 (last updated January 13, 2024)
AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.
Attacker Value
Unknown

CVE-2023-37294

Disclosure Date: January 09, 2024 (last updated January 13, 2024)
AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a heap memory corruption via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.
Attacker Value
Unknown

CVE-2023-37293

Disclosure Date: January 09, 2024 (last updated January 13, 2024)
AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause a stack-based buffer overflow via an adjacent network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.
Attacker Value
Unknown

CVE-2023-34333

Disclosure Date: January 09, 2024 (last updated January 13, 2024)
AMI’s SPx contains a vulnerability in the BMC where an Attacker may cause an untrusted pointer to dereference via a local network. A successful exploitation of this vulnerability may lead to a loss of confidentiality, integrity, and/or availability.