Show filters
255 Total Results
Displaying 121-130 of 255
Sort by:
Attacker Value
Unknown

CVE-2023-30944

Disclosure Date: May 02, 2023 (last updated February 24, 2025)
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the application database.
Attacker Value
Unknown

CVE-2023-30943

Disclosure Date: May 02, 2023 (last updated February 24, 2025)
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.
Attacker Value
Unknown

CVE-2023-1906

Disclosure Date: April 12, 2023 (last updated February 24, 2025)
A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.
Attacker Value
Unknown

CVE-2023-23891

Disclosure Date: April 06, 2023 (last updated February 24, 2025)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in OceanWP Ocean Extra plugin <= 2.1.1 versions. Needs the OceanWP theme installed and activated.
Attacker Value
Unknown

CVE-2023-24399

Disclosure Date: March 30, 2023 (last updated February 24, 2025)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in OceanWP Ocean Extra plugin <= 2.1.2 versions.
Attacker Value
Unknown

CVE-2023-0056

Disclosure Date: March 23, 2023 (last updated February 24, 2025)
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.
Attacker Value
Unknown

CVE-2023-1289

Disclosure Date: March 23, 2023 (last updated February 24, 2025)
A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a remote attacker to pass a specially crafted SVG file that leads to a segmentation fault, generating many trash files in "/tmp," resulting in a denial of service. When ImageMagick crashes, it generates a lot of trash files. These trash files can be large if the SVG file contains many render actions. In a denial of service attack, if a remote attacker uploads an SVG file of size t, ImageMagick generates files of size 103*t. If an attacker uploads a 100M SVG, the server will generate about 10G.
Attacker Value
Unknown

CVE-2023-0749

Disclosure Date: March 13, 2023 (last updated October 08, 2023)
The Ocean Extra WordPress plugin before 2.1.3 does not ensure that the template to be loaded via a shortcode is actually a template, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, such as draft, private or even password protected ones.
Attacker Value
Unknown

CVE-2022-3359

Disclosure Date: December 12, 2022 (last updated October 08, 2023)
The Shortcodes and extra features for Phlox theme WordPress plugin before 2.10.7 unserializes the content of an imported file, which could lead to PHP object injection when a user imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
Attacker Value
Unknown

CVE-2022-4170

Disclosure Date: December 09, 2022 (last updated February 24, 2025)
The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.