Show filters
13,174 Total Results
Displaying 1,051-1,060 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2023-6446

Disclosure Date: January 11, 2024 (last updated January 17, 2024)
The Calculated Fields Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.40 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Attacker Value
Unknown

CVE-2023-42934

Disclosure Date: January 10, 2024 (last updated January 17, 2024)
An information disclosure issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sonoma 14, iOS 17 and iPadOS 17. An app with root privileges may be able to access private information.
Attacker Value
Unknown

CVE-2020-26630

Disclosure Date: January 10, 2024 (last updated January 17, 2024)
A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a special payload in the 'Doctor Specialization' field under the 'Go to Doctors' tab after logging in as an admin.
Attacker Value
Unknown

CVE-2020-26627

Disclosure Date: January 10, 2024 (last updated January 17, 2024)
A Time-Based SQL Injection vulnerability was discovered in Hospital Management System V4.0 which can allow an attacker to dump database information via a crafted payload entered into the 'Admin Remark' parameter under the 'Contact Us Queries -> Unread Query' tab.
Attacker Value
Unknown

CVE-2024-0351

Disclosure Date: January 09, 2024 (last updated January 13, 2024)
A vulnerability classified as problematic has been found in SourceCodester Engineers Online Portal 1.0. This affects an unknown part. The manipulation leads to session fixiation. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250119.
Attacker Value
Unknown

CVE-2024-21668

Disclosure Date: January 09, 2024 (last updated January 17, 2024)
react-native-mmkv is a library that allows easy use of MMKV inside React Native applications. Before version 2.11.0, the react-native-mmkv logged the optional encryption key for the MMKV database into the Android system log. The key can be obtained by anyone with access to the Android Debugging Bridge (ADB) if it is enabled in the phone settings. This bug is not present on iOS devices. By logging the encryption secret to the system logs, attackers can trivially recover the secret by enabling ADB and undermining an app's thread model. This issue has been patched in version 2.11.0.
Attacker Value
Unknown

CVE-2024-21319

Disclosure Date: January 09, 2024 (last updated January 17, 2024)
Microsoft Identity Denial of service vulnerability
Attacker Value
Unknown

CVE-2024-21316

Disclosure Date: January 09, 2024 (last updated January 13, 2024)
Windows Server Key Distribution Service Security Feature Bypass
Attacker Value
Unknown

CVE-2024-21305

Disclosure Date: January 09, 2024 (last updated January 13, 2024)
Hypervisor-Protected Code Integrity (HVCI) Security Feature Bypass Vulnerability
Attacker Value
Unknown

CVE-2024-20676

Disclosure Date: January 09, 2024 (last updated January 15, 2024)
Azure Storage Mover Remote Code Execution Vulnerability