Show filters
727 Total Results
Displaying 121-130 of 727
Sort by:
Attacker Value
Unknown
CVE-2023-37288
Disclosure Date: July 10, 2023 (last updated February 25, 2025)
SmartBPM.NET component has a vulnerability of path traversal within its file download function. An unauthenticated remote attacker can exploit this vulnerability to access arbitrary system files.
0
Attacker Value
Unknown
CVE-2023-37286
Disclosure Date: July 10, 2023 (last updated February 25, 2025)
SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code and disrupt service.
0
Attacker Value
Unknown
CVE-2023-36970
Disclosure Date: July 06, 2023 (last updated February 25, 2025)
A Cross-site scripting (XSS) vulnerability in CMS Made Simple v2.2.17 allows remote attackers to inject arbitrary web script or HTML via the File Upload function.
0
Attacker Value
Unknown
CVE-2023-36969
Disclosure Date: July 06, 2023 (last updated February 25, 2025)
CMS Made Simple v2.2.17 is vulnerable to Remote Command Execution via the File Upload Function.
0
Attacker Value
Unknown
CVE-2023-3504
Disclosure Date: July 04, 2023 (last updated February 25, 2025)
A vulnerability was found in SmartWeb Infotech Job Board 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /settings/account of the component My Profile Page. The manipulation of the argument filename leads to unrestricted upload. The attack may be launched remotely. The identifier of this vulnerability is VDB-232952. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2023-3063
Disclosure Date: June 30, 2023 (last updated November 09, 2023)
The SP Project & Document Manager plugin for WordPress is vulnerable to Insecure Direct Object References in versions up to, and including, 4.67. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources. This makes it possible for authenticated attackers with subscriber privileges or above, to change user passwords and potentially take over administrator accounts.
0
Attacker Value
Unknown
CVE-2023-34650
Disclosure Date: June 28, 2023 (last updated February 25, 2025)
PHPgurukl Small CRM v.1.0 is vulnerable to Cross Site Scripting (XSS).
0
Attacker Value
Unknown
CVE-2022-33974
Disclosure Date: May 29, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Smash Balloon Custom Twitter Feeds (Tweets Widget) plugin <= 1.8.4 versions.
0
Attacker Value
Unknown
CVE-2023-31763
Disclosure Date: May 24, 2023 (last updated February 25, 2025)
Weak security in the transmitter of AGShome Smart Alarm v1.0 allows attackers to gain full access to the system via a code replay attack.
0
Attacker Value
Unknown
CVE-2021-28999
Disclosure Date: May 08, 2023 (last updated February 24, 2025)
SQL Injection vulnerability in CMS Made Simple through 2.2.15 allows remote attackers to execute arbitrary commands via the m1_sortby parameter to modules/News/function.admin_articlestab.php.
0