Show filters
809 Total Results
Displaying 141-150 of 809
Sort by:
Attacker Value
Unknown

CVE-2023-40618

Disclosure Date: September 20, 2023 (last updated February 25, 2025)
A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start versions 4, 5, 6, 7 as well as Visual Project Explorer 1.0, allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'service' parameter in 'headstart_snapshot.php'.
Attacker Value
Unknown

CVE-2023-40617

Disclosure Date: September 13, 2023 (last updated February 25, 2025)
A reflected cross-site scripting (XSS) vulnerability in OpenKnowledgeMaps Head Start 7 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload into the 'file' parameter in 'displayPDF.php'.
Attacker Value
Unknown

CVE-2023-37393

Disclosure Date: September 04, 2023 (last updated February 25, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Atarim Visual Website Collaboration, Feedback & Project Management – Atarim plugin <= 3.9.3 versions.
Attacker Value
Unknown

CVE-2023-39970

Disclosure Date: August 17, 2023 (last updated February 25, 2025)
Unrestricted Upload of File with Dangerous Type vulnerability in AcyMailing component for Joomla. It allows remote code execution.
Attacker Value
Unknown

CVE-2023-33366

Disclosure Date: August 03, 2023 (last updated February 25, 2025)
A SQL injection vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows authenticated users to inject arbitrary SQL directives into an SQL statement and execute arbitrary SQL commands.
Attacker Value
Unknown

CVE-2023-33365

Disclosure Date: August 03, 2023 (last updated February 25, 2025)
A path traversal vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated attackers to fetch arbitrary files from the server's web server.
Attacker Value
Unknown

CVE-2023-33364

Disclosure Date: August 03, 2023 (last updated February 25, 2025)
An OS Command injection vulnerability exists in Suprema BioStar 2 before V2.9.1, which allows authenticated users to execute arbitrary OS commands on the BioStar 2 server.
Attacker Value
Unknown

CVE-2023-33363

Disclosure Date: August 03, 2023 (last updated February 25, 2025)
An authentication bypass vulnerability exists in Suprema BioStar 2 before 2.9.1, which allows unauthenticated users to access some functionality on BioStar 2 servers.
Attacker Value
Unknown

CVE-2023-34017

Disclosure Date: July 25, 2023 (last updated February 25, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FiveStarPlugins Five Star Restaurant Reservations plugin <= 2.6.7 versions.
Attacker Value
Unknown

CVE-2023-37985

Disclosure Date: July 17, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in FiveStarPlugins Restaurant Menu and Food Ordering plugin <= 2.4.6 versions.