Show filters
714 Total Results
Displaying 121-130 of 714
Sort by:
Attacker Value
Unknown

CVE-2023-41646

Disclosure Date: September 07, 2023 (last updated October 08, 2023)
Buttercup v2.20.3 allows attackers to obtain the hash of the master password for the password manager via accessing the file /vaults.json/
Attacker Value
Unknown

CVE-2023-39164

Disclosure Date: September 04, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Molongui Author Box for Authors, Co-Authors, Multiple Authors and Guest Authors – Molongui plugin <= 4.6.19 versions.
Attacker Value
Unknown

CVE-2023-39291

Disclosure Date: August 25, 2023 (last updated October 08, 2023)
A vulnerability in the Connect Mobility Router component of MiVoice Connect through 9.6.2304.102 could allow an authenticated attacker with elevated privileges to conduct an information disclosure attack due to improper configuration. A successful exploit could allow an attacker to view system information.
Attacker Value
Unknown

CVE-2023-39290

Disclosure Date: August 25, 2023 (last updated October 08, 2023)
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through R19.3 SP3 (22.24.5800.0) could allow an authenticated attacker with elevated privileges to conduct an information disclosure attack due to improper configuration. A successful exploit could allow an attacker to view system information.
Attacker Value
Unknown

CVE-2023-39289

Disclosure Date: August 25, 2023 (last updated October 08, 2023)
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2208.101 could allow an unauthenticated attacker to conduct an account enumeration attack due to improper configuration. A successful exploit could allow an attacker to access system information.
Attacker Value
Unknown

CVE-2023-39288

Disclosure Date: August 25, 2023 (last updated October 08, 2023)
A vulnerability in the Connect Mobility Router component of Mitel MiVoice Connect through 9.6.2304.102 could allow an authenticated attacker with elevated privileges and internal network access to conduct a command argument injection due to insufficient parameter sanitization. A successful exploit could allow an attacker to access network information and to generate excessive network traffic.
Attacker Value
Unknown

CVE-2023-39287

Disclosure Date: August 25, 2023 (last updated October 08, 2023)
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an authenticated attacker with elevated privileges and internal network access to conduct a command argument injection due to insufficient parameter sanitization. A successful exploit could allow an attacker to access network information and to generate excessive network traffic.
Attacker Value
Unknown

CVE-2023-39975

Disclosure Date: August 16, 2023 (last updated October 08, 2023)
kdc/do_tgs_req.c in MIT Kerberos 5 (aka krb5) 1.21 before 1.21.2 has a double free that is reachable if an authenticated user can trigger an authorization-data handling failure. Incorrect data is copied from one ticket to another.
Attacker Value
Unknown

CVE-2023-39293

Disclosure Date: August 14, 2023 (last updated October 08, 2023)
A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute arbitrary commands within the context of the system.
Attacker Value
Unknown

CVE-2023-39292

Disclosure Date: August 14, 2023 (last updated October 08, 2023)
A SQL Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to access sensitive information and execute arbitrary database and management operations.