Show filters
727 Total Results
Displaying 121-130 of 727
Sort by:
Attacker Value
Unknown

CVE-2023-37288

Disclosure Date: July 10, 2023 (last updated February 25, 2025)
SmartBPM.NET component has a vulnerability of path traversal within its file download function. An unauthenticated remote attacker can exploit this vulnerability to access arbitrary system files.
Attacker Value
Unknown

CVE-2023-37286

Disclosure Date: July 10, 2023 (last updated February 25, 2025)
SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code and disrupt service.
Attacker Value
Unknown

CVE-2023-36970

Disclosure Date: July 06, 2023 (last updated February 25, 2025)
A Cross-site scripting (XSS) vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web script or HTML via the File Upload function.
Attacker Value
Unknown

CVE-2023-36969

Disclosure Date: July 06, 2023 (last updated February 25, 2025)
CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.
Attacker Value
Unknown

CVE-2023-3504

Disclosure Date: July 04, 2023 (last updated February 25, 2025)
A vulnerability was found in SmartWeb Infotech Job Board 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /settings/account of the component My Profile Page. The manipulation of the argument filename leads to unrestricted upload. The attack may be launched remotely. The identifier of this vulnerability is VDB-232952. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2023-3063

Disclosure Date: June 30, 2023 (last updated November 09, 2023)
The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.67. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers with subscriber privileges or above, to change user passwords and potentially take over administrator accounts.
Attacker Value
Unknown

CVE-2023-34650

Disclosure Date: June 28, 2023 (last updated February 25, 2025)
PHPgurukl Small CRM v.1.0 is vulnerable to Cross Site Scripting (XSS).
Attacker Value
Unknown

CVE-2022-33974

Disclosure Date: May 29, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds (Tweets Widget) plugin <= 1.8.4 versions.
Attacker Value
Unknown

CVE-2023-31763

Disclosure Date: May 24, 2023 (last updated February 25, 2025)
Weak security in the transmitter of AGShome Smart Alarm v1.0 allows attackers to gain full access to the system via a code replay attack.
Attacker Value
Unknown

CVE-2021-28999

Disclosure Date: May 08, 2023 (last updated February 24, 2025)
SQL Injection vulnerability in CMS Made Simple through 2.2.15 allows remote attackers to execute arbitrary commands via the m1_sortby parameter to modules/News/function.admin_articlestab.php.