Show filters
468 Total Results
Displaying 121-130 of 468
Sort by:
Attacker Value
Unknown

CVE-2023-25544

Disclosure Date: March 01, 2023 (last updated February 24, 2025)
Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks.
Attacker Value
Unknown

CVE-2023-24567

Disclosure Date: March 01, 2023 (last updated February 24, 2025)
Dell NetWorker versions 19.5 and earlier contain 'RabbitMQ' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks.
Attacker Value
Unknown

CVE-2023-0072

Disclosure Date: February 06, 2023 (last updated October 08, 2023)
The WC Vendors Marketplace WordPress plugin before 2.4.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2022-4677

Disclosure Date: February 06, 2023 (last updated October 08, 2023)
The Leaflet Maps Marker WordPress plugin before 3.12.7 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
Attacker Value
Unknown

CVE-2023-24576

Disclosure Date: February 03, 2023 (last updated February 24, 2025)
EMC NetWorker may potentially be vulnerable to an unauthenticated remote code execution vulnerability in the NetWorker Client execution service (nsrexecd) irrespective of any auth used.
Attacker Value
Unknown

CVE-2023-21851

Disclosure Date: January 18, 2023 (last updated February 24, 2025)
Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Marketing accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
Attacker Value
Unknown

CVE-2022-4508

Disclosure Date: January 16, 2023 (last updated October 08, 2023)
The ConvertKit WordPress plugin before 2.0.5 does not validate and escapes some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as a contributor to perform Stored Cross-Site Scripting attacks, which could be used against high-privilege users such as admins.
Attacker Value
Unknown

CVE-2022-4298

Disclosure Date: January 02, 2023 (last updated October 08, 2023)
The Wholesale Market WordPress plugin before 2.2.1 does not have authorisation check, as well as does not validate user input used to generate system path, allowing unauthenticated attackers to download arbitrary file from the server.
Attacker Value
Unknown

CVE-2022-4109

Disclosure Date: January 02, 2023 (last updated October 08, 2023)
The Wholesale Market for WooCommerce WordPress plugin before 2.0.0 does not validate user input against path traversal attacks, allowing high privilege users such as admin to download arbitrary logs from the server even when they should not be able to (for example in multisite)
Attacker Value
Unknown

CVE-2022-4108

Disclosure Date: December 19, 2022 (last updated October 08, 2023)
The Wholesale Market for WooCommerce WordPress plugin before 1.0.8 does not validate user input used to generate system path, allowing high privilege users such as admin to download arbitrary file from the server even when they should not be able to (for example in multisite)