Show filters
570 Total Results
Displaying 141-150 of 570
Sort by:
Attacker Value
Unknown

CVE-2023-26119

Disclosure Date: April 03, 2023 (last updated February 24, 2025)
Versions of the package net.sourceforge.htmlunit:htmlunit from 0 and before 3.0.0 are vulnerable to Remote Code Execution (RCE) via XSTL, when browsing the attacker’s webpage.
Attacker Value
Unknown

CVE-2022-44742

Disclosure Date: March 23, 2023 (last updated February 24, 2025)
Auth. (admin+) Stored Cross-Site Scripting vulnerability in Yannick Lefebvre Community Events plugin <= 1.4.8 versions.
Attacker Value
Unknown

CVE-2023-1559

Disclosure Date: March 22, 2023 (last updated February 24, 2025)
A vulnerability classified as problematic was found in SourceCodester Storage Unit Rental Management System 1.0. This vulnerability affects unknown code of the file classes/Users.php?f=save. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-223552.
Attacker Value
Unknown

CVE-2023-0937

Disclosure Date: March 20, 2023 (last updated October 08, 2023)
The VK All in One Expansion Unit WordPress plugin before 9.87.1.0 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers
Attacker Value
Unknown

CVE-2023-28343

Disclosure Date: March 14, 2023 (last updated February 24, 2025)
OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone parameter, because of set_timezone in models/management_model.php.
Attacker Value
Unknown

CVE-2023-1197

Disclosure Date: March 06, 2023 (last updated February 24, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository uvdesk/community-skeleton prior to 1.1.0.
Attacker Value
Unknown

CVE-2023-0230

Disclosure Date: February 27, 2023 (last updated October 08, 2023)
The VK All in One Expansion Unit WordPress plugin before 9.86.0.0 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2023-25761

Disclosure Date: February 15, 2023 (last updated February 24, 2025)
Jenkins JUnit Plugin 1166.va_436e268e972 and earlier does not escape test case class names in JavaScript expressions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control test case class names in the JUnit resources processed by the plugin.
Attacker Value
Unknown

CVE-2022-22564

Disclosure Date: February 14, 2023 (last updated February 24, 2025)
Dell EMC Unity versions before 5.2.0.0.5.173 , use(es) broken cryptographic algorithm. A remote unauthenticated attacker could potentially exploit this vulnerability by performing MitM attacks and let attackers obtain sensitive information.
Attacker Value
Unknown

CVE-2021-3439

Disclosure Date: February 01, 2023 (last updated October 08, 2023)
HP has identified a potential vulnerability in BIOS firmware of some Workstation products. Firmware updates are being released to mitigate these potential vulnerabilities.