Show filters
744 Total Results
Displaying 141-150 of 744
Sort by:
Attacker Value
Unknown

CVE-2023-46142

Disclosure Date: December 14, 2023 (last updated February 25, 2025)
A incorrect permission assignment for critical resource vulnerability in PLCnext products allows an remote attacker with low privileges to gain full access on the affected devices.
Attacker Value
Unknown

CVE-2023-46141

Disclosure Date: December 14, 2023 (last updated February 25, 2025)
Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device.
Attacker Value
Unknown

CVE-2023-0757

Disclosure Date: December 14, 2023 (last updated February 25, 2025)
Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to upload arbitrary malicious code and gain full access on the affected device.
Attacker Value
Unknown

CVE-2023-5239

Disclosure Date: November 27, 2023 (last updated December 02, 2023)
The Security & Malware scan by CleanTalk WordPress plugin before 2.121 retrieves client IP addresses from potentially untrusted headers, allowing an attacker to manipulate its value. This may be used to bypass bruteforce protection.
Attacker Value
Unknown

CVE-2023-47631

Disclosure Date: November 14, 2023 (last updated February 25, 2025)
vantage6 is a framework to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). In affected versions a node does not check if an image is allowed to run if a `parent_id` is set. A malicious party that breaches the server may modify it to set a fake `parent_id` and send a task of a non-whitelisted algorithm. The node will then execute it because the `parent_id` that is set prevents checks from being run. This impacts all servers that are breached by an expert user. This vulnerability has been patched in version 4.1.2. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Attacker Value
Unknown

CVE-2023-46802

Disclosure Date: November 06, 2023 (last updated February 25, 2025)
e-Tax software Version3.0.10 and earlier improperly restricts XML external entity references (XXE) due to the configuration of the embedded XML parser. By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.
Attacker Value
Unknown

CVE-2023-5828

Disclosure Date: October 27, 2023 (last updated February 25, 2025)
A vulnerability was found in Nanning Ontall Longxing Industrial Development Zone Project Construction and Installation Management System up to 20231026. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file login.aspx. The manipulation of the argument tbxUserName leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-243727.
Attacker Value
Unknown

CVE-2023-46376

Disclosure Date: October 27, 2023 (last updated February 25, 2025)
Zentao Biz version 8.7 and before is vulnerable to Information Disclosure.
Attacker Value
Unknown

CVE-2023-46375

Disclosure Date: October 27, 2023 (last updated February 25, 2025)
ZenTao Biz version 4.1.3 and before is vulnerable to Cross Site Request Forgery (CSRF).
Attacker Value
Unknown

CVE-2023-46491

Disclosure Date: October 27, 2023 (last updated February 25, 2025)
ZenTao Biz version 4.1.3 and before has a Cross Site Scripting (XSS) vulnerability in the Version Library.