Show filters
732 Total Results
Displaying 111-120 of 732
Sort by:
Attacker Value
Unknown

CVE-2023-33412

Disclosure Date: December 07, 2023 (last updated December 14, 2023)
The web interface in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions before 3.17.02, allows remote authenticated users to execute arbitrary commands via a crafted request targeting vulnerable cgi endpoints.
Attacker Value
Unknown

CVE-2023-33411

Disclosure Date: December 07, 2023 (last updated December 13, 2023)
A web server in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions up to 3.17.02, allows remote unauthenticated users to perform directory traversal, potentially disclosing sensitive information.
Attacker Value
Unknown

CVE-2023-46688

Disclosure Date: December 06, 2023 (last updated December 12, 2023)
Open redirect vulnerability in Pleasanter 1.3.47.0 and earlier allows a remote unauthenticated attacker to redirect users to arbitrary web sites via a specially crafted URL.
Attacker Value
Unknown

CVE-2023-45210

Disclosure Date: December 06, 2023 (last updated December 12, 2023)
Pleasanter 1.3.47.0 and earlier contains an improper access control vulnerability, which may allow a remote authenticated attacker to view the temporary files uploaded by other users who are not permitted to access.
Attacker Value
Unknown

CVE-2023-34439

Disclosure Date: December 06, 2023 (last updated December 13, 2023)
Pleasanter 1.3.47.0 and earlier contains a stored cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may be executed on the user's web browser.
Attacker Value
Unknown

CVE-2023-49146

Disclosure Date: November 22, 2023 (last updated November 29, 2023)
DOMSanitizer (aka dom-sanitizer) before 1.0.7 allows XSS via an SVG document because of mishandling of comments and greedy regular expressions.
Attacker Value
Unknown

CVE-2023-22818

Disclosure Date: November 15, 2023 (last updated November 23, 2023)
Multiple DLL Search Order Hijack vulnerabilities were addressed in the SanDisk Security Installer for Windows that could allow attackers with local access to execute arbitrary code by executing the installer in the same folder as the malicious DLL. This can lead to the execution of arbitrary code with the privileges of the vulnerable application or obtain a certain level of persistence on the compromised host. 
Attacker Value
Unknown

CVE-2023-47125

Disclosure Date: November 14, 2023 (last updated November 21, 2023)
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions DOM processing instructions are not handled correctly. This allows bypassing the cross-site scripting mechanism of typo3/html-sanitizer. This vulnerability has been addressed in versions 1.5.3 and 2.1.4. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Attacker Value
Unknown

CVE-2023-41138

Disclosure Date: November 09, 2023 (last updated November 18, 2023)
The AppsAnywhere macOS client-privileged helper can be tricked into executing arbitrary commands with elevated permissions by a local user process.
Attacker Value
Unknown

CVE-2023-41137

Disclosure Date: November 09, 2023 (last updated November 18, 2023)
Symmetric encryption used to protect messages between the AppsAnywhere server and client can be broken by reverse engineering the client and used to impersonate the AppsAnywhere server.