Show filters
941 Total Results
Displaying 121-130 of 941
Sort by:
Attacker Value
Unknown
CVE-2023-3329
Disclosure Date: August 02, 2023 (last updated February 25, 2025)
SpiderControl SCADA Webserver versions 2.08 and prior are vulnerable to path traversal. An attacker with administrative privileges could overwrite files on the webserver using the HMI's upload file feature. This could create size zero files anywhere on the webserver, potentially overwriting system files and creating a denial-of-service condition.
0
Attacker Value
Unknown
CVE-2023-35043
Disclosure Date: July 25, 2023 (last updated February 25, 2025)
Unauth. Stored Cross-Site Scripting (XSS) vulnerability in Neha Goel Recent Posts Slider plugin <= 1.1 versions.
0
Attacker Value
Unknown
CVE-2023-29414
Disclosure Date: July 12, 2023 (last updated February 25, 2025)
A CWE-120: Buffer Copy without Checking Size of Input (Classic Buffer Overflow) vulnerability
exists that could cause user privilege escalation if a local user sends specific string input to a
local function call.
0
Attacker Value
Unknown
CVE-2023-37199
Disclosure Date: July 12, 2023 (last updated February 25, 2025)
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that
could cause remote code execution when an admin user on DCE tampers with backups which
are then manually restored.
0
Attacker Value
Unknown
CVE-2023-37198
Disclosure Date: July 12, 2023 (last updated February 25, 2025)
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that
could cause remote code execution when an admin user on DCE uploads or tampers with install
packages.
0
Attacker Value
Unknown
CVE-2023-37197
Disclosure Date: July 12, 2023 (last updated February 25, 2025)
A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command
('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to
access unauthorized content, change, or delete content, or perform unauthorized actions when
tampering with the mass configuration settings of endpoints on DCE.
0
Attacker Value
Unknown
CVE-2023-37196
Disclosure Date: July 12, 2023 (last updated February 25, 2025)
A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command
('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to
access unauthorized content, change, or delete content, or perform unauthorized actions when
tampering with the alert settings of endpoints on DCE.
0
Attacker Value
Unknown
CVE-2023-35778
Disclosure Date: July 11, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Neha Goel Recent Posts Slider plugin <= 1.1 versions.
0
Attacker Value
Unknown
CVE-2023-3001
Disclosure Date: June 14, 2023 (last updated February 25, 2025)
A CWE-502: Deserialization of Untrusted Data vulnerability exists in the Dashboard module that
could cause an interpretation of malicious payload data, potentially leading to remote code
execution when an attacker gets the user to open a malicious file.
0
Attacker Value
Unknown
CVE-2023-2570
Disclosure Date: June 14, 2023 (last updated February 25, 2025)
A CWE-129: Improper Validation of Array Index vulnerability exists that could cause local
denial-of-service, and potentially kernel execution when a malicious actor with local user access
crafts a script/program using an unpredictable index to an IOCTL call in the Foxboro.sys driver.
0