Show filters
1,232 Total Results
Displaying 131-140 of 1,232
Sort by:
Attacker Value
Unknown

CVE-2023-39978

Disclosure Date: August 08, 2023 (last updated February 25, 2025)
ImageMagick before 6.9.12-91 allows attackers to cause a denial of service (memory consumption) in Magick::Draw.
Attacker Value
Unknown

CVE-2023-4067

Disclosure Date: August 02, 2023 (last updated October 08, 2023)
The Bus Ticket Booking with Seat Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab_date' and 'tab_date_r' parameters in versions up to, and including, 5.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2023-3745

Disclosure Date: July 24, 2023 (last updated February 25, 2025)
A heap-based buffer overflow issue was found in ImageMagick's PushCharPixel() function in quantum-private.h. This issue may allow a local attacker to trick the user into opening a specially crafted file, triggering an out-of-bounds read error and allowing an application to crash, resulting in a denial of service.
Attacker Value
Unknown

CVE-2023-36383

Disclosure Date: July 18, 2023 (last updated February 25, 2025)
Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 3.9.5 versions.
Attacker Value
Unknown

CVE-2023-35044

Disclosure Date: July 11, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Drew Phillips Securimage-WP plugin <= 3.6.16 versions.
Attacker Value
Unknown

CVE-2023-36693

Disclosure Date: July 11, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Alain Gonzalez WP RSS Images plugin <= 1.1 versions.
Attacker Value
Unknown

CVE-2023-2026

Disclosure Date: July 10, 2023 (last updated October 08, 2023)
The Image Protector WordPress plugin through 1.1 does not properly sanitize some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
Attacker Value
Unknown

CVE-2023-22673

Disclosure Date: July 10, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in MageNet Website Monetization by MageNet plugin <= 1.0.29.1 versions.
Attacker Value
Unknown

CVE-2023-36183

Disclosure Date: July 03, 2023 (last updated February 25, 2025)
Buffer Overflow vulnerability in OpenImageIO v.2.4.12.0 and before allows a remote to execute arbitrary code and obtain sensitive information via a crafted file to the readimg function.
Attacker Value
Unknown

CVE-2023-35048

Disclosure Date: June 23, 2023 (last updated February 25, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in MagePeople Team Booking and Rental Manager for Bike plugin <= 1.2.1 versions.