Show filters
727 Total Results
Displaying 131-140 of 727
Sort by:
Attacker Value
Unknown

CVE-2021-28998

Disclosure Date: May 08, 2023 (last updated February 24, 2025)
File upload vulnerability in CMS Made Simple through 2.2.15 allows remote authenticated attackers to gain a webshell via a crafted phar file.
Attacker Value
Unknown

CVE-2023-25461

Disclosure Date: April 25, 2023 (last updated February 24, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in namithjawahar Wp-Insert plugin <= 2.5.0 versions.
Attacker Value
Unknown

CVE-2023-30459

Disclosure Date: April 14, 2023 (last updated October 08, 2023)
SmartPTT SCADA 1.1.0.0 allows remote code execution (when the attacker has administrator privileges) by writing a malicious C# script and executing it on the server (via server settings in the administrator control panel on port 8101, by default).
Attacker Value
Unknown

CVE-2023-28447

Disclosure Date: March 28, 2023 (last updated February 24, 2025)
Smarty is a template engine for PHP. In affected versions smarty did not properly escape javascript code. An attacker could exploit this vulnerability to execute arbitrary JavaScript code in the context of the user's browser session. This may lead to unauthorized access to sensitive user data, manipulation of the web application's behavior, or unauthorized actions performed on behalf of the user. Users are advised to upgrade to either version 3.1.48 or to 4.3.1 to resolve this issue. There are no known workarounds for this vulnerability.
Attacker Value
Unknown

CVE-2023-26864

Disclosure Date: March 24, 2023 (last updated February 23, 2025)
SQL injection vulnerability found in PrestaShop smplredirectionsmanager v.1.1.19 and before allow a remote attacker to gain privileges via the SmplTools::getMatchingRedirectionsFromPartscomponent.
Attacker Value
Unknown

CVE-2023-1370

Disclosure Date: March 22, 2023 (last updated February 24, 2025)
[Json-smart](https://netplex.github.io/json-smart/) is a performance focused, JSON processor lib. When reaching a ‘[‘ or ‘{‘ character in the JSON input, the code parses an array or an object respectively. It was discovered that the code does not have any limit to the nesting of such arrays or objects. Since the parsing of nested arrays and objects is done recursively, nesting too many of them can cause a stack exhaustion (stack overflow) and crash the software.
Attacker Value
Unknown

CVE-2020-22647

Disclosure Date: March 16, 2023 (last updated February 24, 2025)
An issue found in DepositGame v.1.0 allows an attacker to gain sensitive information via the GetBonusWithdraw and withdraw functions.
Attacker Value
Unknown

CVE-2023-22892

Disclosure Date: March 08, 2023 (last updated February 24, 2025)
There exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticated users to read arbitrary files from Zephyr instances.
Attacker Value
Unknown

CVE-2023-22891

Disclosure Date: March 08, 2023 (last updated February 24, 2025)
There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users to reset passwords for other accounts.
Attacker Value
Unknown

CVE-2023-22890

Disclosure Date: March 08, 2023 (last updated February 24, 2025)
SmartBear Zephyr Enterprise through 7.15.0 allows unauthenticated users to upload large files, which could exhaust the local drive space, causing a denial of service condition.