Show filters
469 Total Results
Displaying 151-160 of 469
Sort by:
Attacker Value
Unknown

CVE-2023-46653

Disclosure Date: October 25, 2023 (last updated February 25, 2025)
Jenkins lambdatest-automation Plugin 1.20.10 and earlier logs LAMBDATEST Credentials access token at the INFO level, potentially resulting in its exposure.
Attacker Value
Unknown

CVE-2023-46652

Disclosure Date: October 25, 2023 (last updated February 25, 2025)
A missing permission check in Jenkins lambdatest-automation Plugin 1.20.9 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of LAMBDATEST credentials stored in Jenkins.
Attacker Value
Unknown

CVE-2023-5633

Disclosure Date: October 23, 2023 (last updated February 25, 2025)
The reference count changes made as part of the CVE-2023-33951 and CVE-2023-33952 fixes exposed a use-after-free flaw in the way memory objects were handled when they were being used to store a surface. When running inside a VMware guest with 3D acceleration enabled, a local, unprivileged user could potentially use this flaw to escalate their privileges.
Attacker Value
Unknown

CVE-2023-4499

Disclosure Date: October 13, 2023 (last updated February 25, 2025)
A potential security vulnerability has been identified in the HP ThinUpdate utility (also known as HP Recovery Image and Software Download Tool) which may lead to information disclosure. HP is releasing mitigation for the potential vulnerability.
Attacker Value
Unknown

CVE-2023-44261

Disclosure Date: October 10, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Dinesh Karki Block Plugin Update plugin <= 3.3 versions.
Attacker Value
Unknown

CVE-2023-41858

Disclosure Date: October 10, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Ashok Rane Order Delivery Date for WP e-Commerce plugin <= 1.2 versions.
Attacker Value
Unknown

CVE-2023-41650

Disclosure Date: October 06, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Venugopal Remove/hide Author, Date, Category Like Entry-Meta plugin <= 2.1 versions.
Attacker Value
Unknown

CVE-2023-25489

Disclosure Date: October 04, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Jeff Sherk Update Theme and Plugins from Zip File plugin <= 2.0.0 versions.
Attacker Value
Unknown

CVE-2023-41859

Disclosure Date: October 02, 2023 (last updated February 25, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ashok Rane Order Delivery Date for WP e-Commerce plugin <= 1.2 versions.
Attacker Value
Unknown

CVE-2023-41874

Disclosure Date: September 25, 2023 (last updated February 25, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Tyche Softwares Order Delivery Date for WooCommerce plugin <= 3.20.0 versions.