Show filters
774 Total Results
Displaying 151-160 of 774
Sort by:
Attacker Value
Unknown

CVE-2023-20861

Disclosure Date: March 23, 2023 (last updated October 08, 2023)
In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.
Attacker Value
Unknown

CVE-2023-21808

Disclosure Date: February 14, 2023 (last updated February 24, 2025)
.NET and Visual Studio Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2023-21722

Disclosure Date: February 14, 2023 (last updated February 24, 2025)
.NET Framework Denial of Service Vulnerability
Attacker Value
Unknown

CVE-2023-21894

Disclosure Date: January 18, 2023 (last updated February 24, 2025)
Vulnerability in the Oracle Global Lifecycle Management NextGen OUI Framework product of Oracle Fusion Middleware (component: NextGen Installer issues). Supported versions that are affected are Prior to 13.9.4.2.11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Global Lifecycle Management NextGen OUI Framework executes to compromise Oracle Global Lifecycle Management NextGen OUI Framework. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Global Lifecycle Management NextGen OUI Framework. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).
Attacker Value
Unknown

CVE-2015-10012

Disclosure Date: January 03, 2023 (last updated February 24, 2025)
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in sumocoders FrameworkUserBundle up to 1.3.x. It has been rated as problematic. Affected by this issue is some unknown functionality of the file Resources/views/Security/login.html.twig. The manipulation leads to information exposure through error message. Upgrading to version 1.4.0 is able to address this issue. The name of the patch is abe4993390ba9bd7821ab12678270556645f94c8. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-217268. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Attacker Value
Unknown

CVE-2016-15007

Disclosure Date: January 02, 2023 (last updated February 24, 2025)
A vulnerability was found in Centralized-Salesforce-Dev-Framework. It has been declared as problematic. Affected by this vulnerability is the function SObjectService of the file src/classes/SObjectService.cls of the component SOQL Handler. The manipulation of the argument orderDirection leads to injection. The patch is named db03ac5b8a9d830095991b529c067a030a0ccf7b. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-217195.
Attacker Value
Unknown

CVE-2021-4266

Disclosure Date: December 21, 2022 (last updated February 24, 2025)
A vulnerability classified as problematic has been found in Webdetails cpf up to 9.5.0.0-80. Affected is an unknown function of the file core/src/main/java/pt/webdetails/cpf/packager/DependenciesPackage.java. The manipulation of the argument baseUrl leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 9.5.0.0-81 is able to address this issue. The name of the patch is 3bff900d228e8cae3af256b447c5d15bdb03c174. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-216468.
Attacker Value
Unknown

CVE-2022-41089

Disclosure Date: December 13, 2022 (last updated November 18, 2023)
.NET Framework Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2022-4414

Disclosure Date: December 12, 2022 (last updated February 24, 2025)
Cross-site Scripting (XSS) - DOM in GitHub repository nuxt/framework prior to v3.0.0-rc.13.
Attacker Value
Unknown

CVE-2022-4413

Disclosure Date: December 12, 2022 (last updated February 24, 2025)
Cross-site Scripting (XSS) - Reflected in GitHub repository nuxt/framework prior to v3.0.0-rc.13.