Show filters
463 Total Results
Displaying 111-120 of 463
Sort by:
Attacker Value
Unknown

CVE-2024-0348

Disclosure Date: January 09, 2024 (last updated January 13, 2024)
A vulnerability was found in SourceCodester Engineers Online Portal 1.0. It has been classified as problematic. Affected is an unknown function of the component File Upload Handler. The manipulation leads to resource consumption. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250116.
Attacker Value
Unknown

CVE-2024-0347

Disclosure Date: January 09, 2024 (last updated January 13, 2024)
A vulnerability was found in SourceCodester Engineers Online Portal 1.0 and classified as problematic. This issue affects some unknown processing of the file signup_teacher.php. The manipulation of the argument Password leads to weak password requirements. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250115.
Attacker Value
Unknown

CVE-2024-0260

Disclosure Date: January 07, 2024 (last updated January 11, 2024)
A vulnerability, which was classified as problematic, was found in SourceCodester Engineers Online Portal 1.0. Affected is an unknown function of the file change_password_teacher.php of the component Password Change. The manipulation leads to session expiration. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249816.
Attacker Value
Unknown

CVE-2023-50924

Disclosure Date: December 22, 2023 (last updated January 06, 2024)
Englesystem is a shift planning system for chaos events. Engelsystem prior to v3.4.1 performed insufficient validation of user supplied data for the DECT number, mobile number, and work-log comment fields. The values of those fields would be displayed in corresponding log overviews, allowing the injection and execution of Javascript code in another user's context. This vulnerability enables an authenticated user to inject Javascript into other user's sessions. The injected JS will be executed during normal usage of the system when viewing, e.g., overview pages. This issue has been fixed in version 3.4.1.
Attacker Value
Unknown

CVE-2023-50835

Disclosure Date: December 19, 2023 (last updated February 22, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Praveen Goswami Advanced Category Template.This issue affects Advanced Category Template: from n/a through 0.1.
Attacker Value
Unknown

CVE-2023-48887

Disclosure Date: December 01, 2023 (last updated December 07, 2023)
A deserialization vulnerability in Jupiter v1.3.1 allows attackers to execute arbitrary commands via sending a crafted RPC request.
Attacker Value
Unknown

CVE-2023-23684

Disclosure Date: November 13, 2023 (last updated December 21, 2023)
Server-Side Request Forgery (SSRF) vulnerability in WPGraphQL.This issue affects WPGraphQL: from n/a through 1.14.5.
Attacker Value
Unknown

CVE-2023-46963

Disclosure Date: November 04, 2023 (last updated November 15, 2023)
An issue in Beijing Yunfan Internet Technology Co., Ltd, Yunfan Learning Examination System v.6.5 allows a remote attacker to obtain sensitive information via the password parameter in the login function.
Attacker Value
Unknown

CVE-2023-45883

Disclosure Date: October 19, 2023 (last updated October 28, 2023)
A privilege escalation vulnerability exists within the Qumu Multicast Extension v2 before 2.0.63 for Windows. When a standard user triggers a repair of the software, a pop-up window opens with SYSTEM privileges. Standard users may use this to gain arbitrary code execution as SYSTEM.
Attacker Value
Unknown

CVE-2023-5538

Disclosure Date: October 18, 2023 (last updated October 25, 2023)
The MpOperationLogs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the IP Request Headers in versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.