Show filters
727 Total Results
Displaying 111-120 of 727
Sort by:
Attacker Value
Unknown

CVE-2023-4441

Disclosure Date: August 21, 2023 (last updated February 25, 2025)
A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /patient/appointment.php. The manipulation of the argument sheduledate leads to sql injection. The attack can be initiated remotely. VDB-237562 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-4440

Disclosure Date: August 20, 2023 (last updated February 25, 2025)
A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0. It has been classified as critical. This affects an unknown part of the file appointment.php. The manipulation of the argument sheduledate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-237561 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-36530

Disclosure Date: August 10, 2023 (last updated February 25, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Smartypants SP Project & Document Manager plugin <= 4.67 versions.
Attacker Value
Unknown

CVE-2023-4142

Disclosure Date: August 04, 2023 (last updated October 08, 2023)
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus1' parameter. This allows authenticated attackers with author-level permissions or above, if the administrator previously grants access in the plugin settings, to execute code on the server. The author resolved this vulnerability by removing the ability for authors and editors to import files, please note that this means remote code execution is still possible for site administrators, use the plugin with caution.
Attacker Value
Unknown

CVE-2023-4141

Disclosure Date: August 04, 2023 (last updated October 08, 2023)
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus2' parameter. This allows authenticated attackers with author-level permissions or above, if the administrator previously grants access in the plugin settings, to create a PHP file and execute code on the server. The author resolved this vulnerability by removing the ability for authors and editors to import files, please note that this means php file creation is still allowed for site administrators, use the plugin with caution.
Attacker Value
Unknown

CVE-2023-4140

Disclosure Date: August 04, 2023 (last updated October 08, 2023)
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 7.9.8 due to insufficient restriction on the 'get_header_values' function. This makes it possible for authenticated attackers, with minimal permissions such as an author, if the administrator previously grants access in the plugin settings, to modify their user role by supplying the 'wp_capabilities->cus1' parameter.
Attacker Value
Unknown

CVE-2023-4139

Disclosure Date: August 04, 2023 (last updated November 09, 2023)
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Sensitive Information Exposure via Directory Listing due to missing restriction in export folder indexing in versions up to, and including, 7.9.8. This makes it possible for unauthenticated attackers to list and view exported files.
Attacker Value
Unknown

CVE-2023-30146

Disclosure Date: August 04, 2023 (last updated February 25, 2025)
Assmann Digitus Plug&View IP Camera HT-IP211HDP, version 2.000.022 allows unauthenticated attackers to download a copy of the camera's settings and the administrator credentials.
Attacker Value
Unknown

CVE-2023-25475

Disclosure Date: July 18, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Vladimir Prelovac Smart YouTube PRO plugin <= 4.3 versions.
Attacker Value
Unknown

CVE-2023-37287

Disclosure Date: July 10, 2023 (last updated February 25, 2025)
SmartBPM.NET has a vulnerability of using hard-coded authentication key. An unauthenticated remote attacker can exploit this vulnerability to access system with regular user privilege to read application data, and execute submission and approval processes.