Show filters
991 Total Results
Displaying 141-150 of 991
Sort by:
Attacker Value
Unknown

CVE-2023-36457

Disclosure Date: July 05, 2023 (last updated February 25, 2025)
1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.3.6, an authenticated attacker can craft a malicious payload to achieve command injection when adding container repositories. The vulnerability has been fixed in v1.3.6.
Attacker Value
Unknown

CVE-2023-3479

Disclosure Date: June 30, 2023 (last updated February 25, 2025)
Cross-site Scripting (XSS) - Reflected in GitHub repository hestiacp/hestiacp prior to 1.7.8.
Attacker Value
Unknown

CVE-2023-34648

Disclosure Date: June 29, 2023 (last updated February 25, 2025)
A Cross Site Scripting vulnerability in PHPgurukl User Registration Login and User Management System with admin panel v.1.0 allows a local attacker to execute arbitrary code via a crafted script to the signup.php.
Attacker Value
Unknown

CVE-2023-36630

Disclosure Date: June 25, 2023 (last updated February 25, 2025)
In CloudPanel before 2.3.1, insecure file upload leads to privilege escalation and authentication bypass.
Attacker Value
Unknown

CVE-2023-23807

Disclosure Date: June 22, 2023 (last updated February 25, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Qumos MojoPlug Slide Panel plugin <= 1.1.2 versions.
Attacker Value
Unknown

CVE-2023-34965

Disclosure Date: June 13, 2023 (last updated February 25, 2025)
SSPanel-Uim 2023.3 does not restrict access to the /link/ interface which can lead to a leak of user information.
Attacker Value
Unknown

CVE-2023-33747

Disclosure Date: June 06, 2023 (last updated February 25, 2025)
CloudPanel v2.2.2 allows attackers to execute a path traversal.
Attacker Value
Unknown

CVE-2023-2887

Disclosure Date: May 25, 2023 (last updated February 25, 2025)
Authentication Bypass by Spoofing vulnerability in CBOT Chatbot allows Authentication Bypass.This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.
Attacker Value
Unknown

CVE-2023-2886

Disclosure Date: May 25, 2023 (last updated February 25, 2025)
Missing Origin Validation in WebSockets vulnerability in CBOT Chatbot allows Content Spoofing Via Application API Manipulation.This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.
Attacker Value
Unknown

CVE-2023-2885

Disclosure Date: May 25, 2023 (last updated February 25, 2025)
Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in CBOT Chatbot allows Adversary in the Middle (AiTM).This issue affects Chatbot: before Core: v4.0.3.4 Panel: v4.0.3.7.