Show filters
506 Total Results
Displaying 111-120 of 506
Sort by:
Attacker Value
Unknown
CVE-2024-24821
Disclosure Date: February 09, 2024 (last updated February 26, 2025)
Composer is a dependency Manager for the PHP language. In affected versions several files within the local working directory are included during the invocation of Composer and in the context of the executing user. As such, under certain conditions arbitrary code execution may lead to local privilege escalation, provide lateral user movement or malicious code execution when Composer is invoked within a directory with tampered files. All Composer CLI commands are affected, including composer.phar's self-update. The following scenarios are of high risk: Composer being run with sudo, Pipelines which may execute Composer on untrusted projects, Shared environments with developers who run Composer individually on the same project. This vulnerability has been addressed in versions 2.7.0 and 2.2.23. It is advised that the patched versions are applied at the earliest convenience. Where not possible, the following should be addressed: Remove all sudo composer privileges for all users to mitigate…
0
Attacker Value
Unknown
CVE-2024-22779
Disclosure Date: February 02, 2024 (last updated February 26, 2025)
Directory Traversal vulnerability in Kihron ServerRPExposer v.1.0.2 and before allows a remote attacker to execute arbitrary code via the loadServerPack in ServerResourcePackProviderMixin.java.
0
Attacker Value
Unknown
CVE-2023-52193
Disclosure Date: February 01, 2024 (last updated February 26, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Live Composer Team Page Builder: Live Composer allows Stored XSS.This issue affects Page Builder: Live Composer: from n/a through 1.5.23.
0
Attacker Value
Unknown
CVE-2023-52206
Disclosure Date: January 08, 2024 (last updated February 25, 2025)
Deserialization of Untrusted Data vulnerability in Live Composer Team Page Builder: Live Composer live-composer-page-builder.This issue affects Page Builder: Live Composer: from n/a through 1.5.25.
0
Attacker Value
Unknown
CVE-2023-6309
Disclosure Date: November 27, 2023 (last updated February 25, 2025)
A vulnerability, which was classified as critical, was found in moses-smt mosesdecoder up to 4.0. This affects an unknown part of the file contrib/iSenWeb/trans_result.php. The manipulation of the argument input1 leads to os command injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-246135.
0
Attacker Value
Unknown
CVE-2023-39166
Disclosure Date: November 13, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in tagDiv tagDiv Composer allows Cross-Site Scripting (XSS).This issue affects tagDiv Composer: from n/a before 4.4.
0
Attacker Value
Unknown
CVE-2023-43795
Disclosure Date: October 25, 2023 (last updated February 25, 2025)
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The OGC Web Processing Service (WPS) specification is designed to process information from any server using GET and POST requests. This presents the opportunity for Server Side Request Forgery. This vulnerability has been patched in version 2.22.5 and 2.23.2.
0
Attacker Value
Unknown
CVE-2023-41339
Disclosure Date: October 25, 2023 (last updated February 25, 2025)
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. The WMS specification defines an ``sld=<url>`` parameter for GetMap, GetLegendGraphic and GetFeatureInfo operations for user supplied "dynamic styling". Enabling the use of dynamic styles, without also configuring URL checks, provides the opportunity for Service Side Request Forgery. This vulnerability can be used to steal user NetNTLMv2 hashes which could be relayed or cracked externally to gain further access. This vulnerability has been patched in versions 2.22.5 and 2.23.2.
0
Attacker Value
Unknown
CVE-2023-31582
Disclosure Date: October 25, 2023 (last updated February 25, 2025)
jose4j before v0.9.3 allows attackers to set a low iteration count of 1000 or less.
0
Attacker Value
Unknown
CVE-2023-45727
Disclosure Date: October 18, 2023 (last updated February 25, 2025)
Proself Enterprise/Standard Edition Ver5.62 and earlier, Proself Gateway Edition Ver1.65 and earlier, and Proself Mail Sanitize Edition Ver1.08 and earlier allow a remote unauthenticated attacker to conduct XML External Entity (XXE) attacks. By processing a specially crafted request containing malformed XML data, arbitrary files on the server containing account information may be read by the attacker.
0