Show filters
255 Total Results
Displaying 121-130 of 255
Sort by:
Attacker Value
Unknown
CVE-2023-30944
Disclosure Date: May 02, 2023 (last updated February 24, 2025)
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the application database.
0
Attacker Value
Unknown
CVE-2023-30943
Disclosure Date: May 02, 2023 (last updated February 24, 2025)
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.
0
Attacker Value
Unknown
CVE-2023-1906
Disclosure Date: April 12, 2023 (last updated February 24, 2025)
A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.
0
Attacker Value
Unknown
CVE-2023-23891
Disclosure Date: April 06, 2023 (last updated February 24, 2025)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in OceanWP Ocean Extra plugin <= 2.1.1 versions. Needs the OceanWP theme installed and activated.
0
Attacker Value
Unknown
CVE-2023-24399
Disclosure Date: March 30, 2023 (last updated February 24, 2025)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in OceanWP Ocean Extra plugin <= 2.1.2 versions.
0
Attacker Value
Unknown
CVE-2023-0056
Disclosure Date: March 23, 2023 (last updated February 24, 2025)
An uncontrolled resource consumption vulnerability was discovered in HAProxy which could crash the service. This issue could allow an authenticated remote attacker to run a specially crafted malicious server in an OpenShift cluster. The biggest impact is to availability.
0
Attacker Value
Unknown
CVE-2023-1289
Disclosure Date: March 23, 2023 (last updated February 24, 2025)
A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a remote attacker to pass a specially crafted SVG file that leads to a segmentation fault, generating many trash files in "/tmp," resulting in a denial of service. When ImageMagick crashes, it generates a lot of trash files. These trash files can be large if the SVG file contains many render actions. In a denial of service attack, if a remote attacker uploads an SVG file of size t, ImageMagick generates files of size 103*t. If an attacker uploads a 100M SVG, the server will generate about 10G.
0
Attacker Value
Unknown
CVE-2023-0749
Disclosure Date: March 13, 2023 (last updated October 08, 2023)
The Ocean Extra WordPress plugin before 2.1.3 does not ensure that the template to be loaded via a shortcode is actually a template, allowing any authenticated users such as subscriber to retrieve the content of arbitrary posts, such as draft, private or even password protected ones.
0
Attacker Value
Unknown
CVE-2022-3359
Disclosure Date: December 12, 2022 (last updated October 08, 2023)
The Shortcodes and extra features for Phlox theme WordPress plugin before 2.10.7 unserializes the content of an imported file, which could lead to PHP object injection when a user imports (intentionally or not) a malicious file and a suitable gadget chain is present on the blog.
0
Attacker Value
Unknown
CVE-2022-4170
Disclosure Date: December 09, 2022 (last updated February 24, 2025)
The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.
0