Show filters
1,231 Total Results
Displaying 101-110 of 1,231
Sort by:
Attacker Value
Unknown

CVE-2023-5506

Disclosure Date: November 07, 2023 (last updated February 25, 2025)
The ImageMapper plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'imgmap_delete_area_ajax' function in versions up to, and including, 1.2.6. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to delete arbitrary posts and pages.
Attacker Value
Unknown

CVE-2023-42299

Disclosure Date: November 02, 2023 (last updated February 25, 2025)
Buffer Overflow vulnerability in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service via the read_subimage_data function.
Attacker Value
Unknown

CVE-2023-42295

Disclosure Date: October 23, 2023 (last updated February 25, 2025)
An issue in OpenImageIO oiio v.2.4.12.0 allows a remote attacker to execute arbitrary code and cause a denial of service via the read_rle_image function of file bifs/unquantize.c
Attacker Value
Unknown

CVE-2023-3279

Disclosure Date: October 16, 2023 (last updated October 19, 2023)
The WordPress Gallery Plugin WordPress plugin before 3.39 does not validate some block attributes before using them to generate paths passed to include function/s, allowing Admin users to perform LFI attacks
Attacker Value
Unknown

CVE-2023-3155

Disclosure Date: October 16, 2023 (last updated February 25, 2025)
The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to Arbitrary File Read and Delete due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.
Attacker Value
Unknown

CVE-2023-3154

Disclosure Date: October 16, 2023 (last updated October 20, 2023)
The WordPress Gallery Plugin WordPress plugin before 3.39 is vulnerable to PHAR Deserialization due to a lack of input parameter validation in the `gallery_edit` function, allowing an attacker to access arbitrary resources on the server.
Attacker Value
Unknown

CVE-2023-3428

Disclosure Date: October 04, 2023 (last updated February 25, 2025)
A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local attacker to trick the user into opening a specially crafted file, resulting in an application crash and denial of service.
Attacker Value
Unknown

CVE-2023-41879

Disclosure Date: September 11, 2023 (last updated February 25, 2025)
Magento LTS is the official OpenMage LTS codebase. Guest orders may be viewed without authentication using a "guest-view" cookie which contains the order's "protect_code". This code is 6 hexadecimal characters which is arguably not enough to prevent a brute-force attack. Exposing each order would require a separate brute force attack. This issue has been patched in versions 19.5.1 and 20.1.1.
Attacker Value
Unknown

CVE-2021-36036

Disclosure Date: September 06, 2023 (last updated February 25, 2025)
Magento versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper access control vulnerability within Magento's Media Gallery Upload workflow. By storing a specially crafted file in the website gallery, an authenticated attacker with administrative privilege can gain access to delete the .htaccess file. This could result in the attacker achieving remote code execution.
Attacker Value
Unknown

CVE-2021-36023

Disclosure Date: September 06, 2023 (last updated February 25, 2025)
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Injection vulnerability in the Widgets Update Layout. An attacker with admin privileges can trigger a specially crafted script to achieve remote code execution.