Show filters
698 Total Results
Displaying 141-150 of 698
Sort by:
Attacker Value
Unknown
CVE-2023-0747
Disclosure Date: February 08, 2023 (last updated February 24, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.
0
Attacker Value
Unknown
CVE-2022-46496
Disclosure Date: February 06, 2023 (last updated February 24, 2025)
BTicino Door Entry HOMETOUCH for iOS 1.4.2 was discovered to be missing an SSL certificate.
0
Attacker Value
Unknown
CVE-2022-32984
Disclosure Date: January 31, 2023 (last updated October 08, 2023)
BTCPay Server 1.3.0 through 1.5.3 allows a remote attacker to obtain sensitive information when a public Point of Sale app is exposed. The sensitive information, found in the HTML source code, includes the xpub of the store. Also, if the store isn't using the internal lightning node, the credentials of a lightning node are exposed.
0
Attacker Value
Unknown
CVE-2023-0493
Disclosure Date: January 26, 2023 (last updated February 24, 2025)
Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5.
0
Attacker Value
Unknown
CVE-2022-48281
Disclosure Date: January 23, 2023 (last updated February 24, 2025)
processCropSelections in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based buffer overflow (e.g., "WRITE of size 307203") via a crafted TIFF image.
0
Attacker Value
Unknown
CVE-2022-4336
Disclosure Date: December 09, 2022 (last updated February 24, 2025)
In BAOTA linux panel there exists a stored xss vulnerability attackers can use to obtain sensitive information via the log analysis feature.
0
Attacker Value
Unknown
CVE-2022-45824
Disclosure Date: December 05, 2022 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Advanced Booking Calendar plugin <= 1.7.1 on WordPress.
0
Attacker Value
Unknown
CVE-2022-45822
Disclosure Date: December 05, 2022 (last updated February 24, 2025)
Unauth. SQL Injection (SQLi) vulnerability in Advanced Booking Calendar plugin <= 1.7.1 on WordPress.
0
Attacker Value
Unknown
CVE-2022-44962
Disclosure Date: December 02, 2022 (last updated February 24, 2025)
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /calendar/viewcalendar.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Subject field.
0
Attacker Value
Unknown
CVE-2022-44961
Disclosure Date: December 02, 2022 (last updated February 24, 2025)
webtareas 2.4p5 was discovered to contain a cross-site scripting (XSS) vulnerability in the component /forums/editforum.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field.
0