Show filters
941 Total Results
Displaying 101-110 of 941
Sort by:
Attacker Value
Unknown
CVE-2023-6407
Disclosure Date: December 14, 2023 (last updated February 25, 2025)
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
vulnerability exists that could cause arbitrary file deletion upon service restart when accessed by
a local and low-privileged attacker.
0
Attacker Value
Unknown
CVE-2023-5630
Disclosure Date: December 14, 2023 (last updated February 25, 2025)
A CWE-494: Download of Code Without Integrity Check vulnerability exists that could allow a
privileged user to install an untrusted firmware.
0
Attacker Value
Unknown
CVE-2023-5629
Disclosure Date: December 14, 2023 (last updated February 25, 2025)
A CWE-601:URL Redirection to Untrusted Site (‘Open Redirect’) vulnerability exists that could
cause disclosure of information through phishing attempts over HTTP.
0
Attacker Value
Unknown
CVE-2023-6035
Disclosure Date: December 11, 2023 (last updated February 25, 2025)
The EazyDocs WordPress plugin before 2.3.4 does not properly sanitize and escape "data" parameter before using it in an SQL statement via an AJAX action, which could allow any authenticated users, such as subscribers, to perform SQL Injection attacks.
0
Attacker Value
Unknown
CVE-2023-47786
Disclosure Date: November 22, 2023 (last updated February 25, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LayerSlider plugin <= 7.7.9 versions.
0
Attacker Value
Unknown
CVE-2023-6032
Disclosure Date: November 15, 2023 (last updated February 25, 2025)
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
vulnerability exists that could cause a file system enumeration and file download when an
attacker navigates to the Network Management Card via HTTPS.
0
Attacker Value
Unknown
CVE-2023-5987
Disclosure Date: November 15, 2023 (last updated February 25, 2025)
A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting)
vulnerability that could cause a vulnerability leading to a cross site scripting condition where
attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing
the injected payload.
0
Attacker Value
Unknown
CVE-2023-5986
Disclosure Date: November 15, 2023 (last updated February 25, 2025)
A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input
attackers can cause the software’s web application to redirect to the chosen domain after a
successful login is performed.
0
Attacker Value
Unknown
CVE-2023-5985
Disclosure Date: November 15, 2023 (last updated February 25, 2025)
A CWE-79 Improper Neutralization of Input During Web Page Generation vulnerability
exists that could cause compromise of a user’s browser when an attacker with admin privileges
has modified system values.
0
Attacker Value
Unknown
CVE-2023-5984
Disclosure Date: November 15, 2023 (last updated February 25, 2025)
A CWE-494 Download of Code Without Integrity Check vulnerability exists that could allow
modified firmware to be uploaded when an authorized admin user begins a firmware update
procedure which could result in full control over the device.
0