Show filters
809 Total Results
Displaying 151-160 of 809
Sort by:
Attacker Value
Unknown
CVE-2023-37985
Disclosure Date: July 17, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in FiveStarPlugins Restaurant Menu and Food Ordering plugin <= 2.4.6 versions.
0
Attacker Value
Unknown
CVE-2023-3127
Disclosure Date: July 11, 2023 (last updated February 25, 2025)
An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.
0
Attacker Value
Unknown
CVE-2023-3620
Disclosure Date: July 11, 2023 (last updated February 25, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository amauric/tarteaucitron.js prior to v1.13.1.
0
Attacker Value
Unknown
CVE-2023-33243
Disclosure Date: June 15, 2023 (last updated February 25, 2025)
RedTeam Pentesting discovered that the web interface of STARFACE as well as its REST API allows authentication using the SHA512 hash of the password instead of the cleartext password. While storing password hashes instead of cleartext passwords in an application's database generally has become best practice to protect users' passwords in case of a database compromise, this is rendered ineffective when allowing to authenticate using the password hash.
0
Attacker Value
Unknown
CVE-2023-29159
Disclosure Date: June 01, 2023 (last updated February 25, 2025)
Directory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to view files in a web service which was built using Starlette.
0
Attacker Value
Unknown
CVE-2023-1158
Disclosure Date: May 24, 2023 (last updated February 25, 2025)
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x expose dashboard prompts to users who are not part of the authorization list.
0
Attacker Value
Unknown
CVE-2022-4815
Disclosure Date: May 24, 2023 (last updated February 25, 2025)
Hitachi Vantara Pentaho Business Analytics Server versions before 9.4.0.1 and 9.3.0.3, including 8.3.x deserialize untrusted JSON data without constraining the parser to approved classes and methods.
0
Attacker Value
Unknown
CVE-2022-46851
Disclosure Date: May 23, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Brainstorm Force Starter Templates plugin <= 3.1.20 versions.
0
Attacker Value
Unknown
CVE-2023-31923
Disclosure Date: May 22, 2023 (last updated February 25, 2025)
Suprema BioStar 2 before 2022 Q4, v2.9.1 has Insecure Permissions. A vulnerability in the web application allows an authenticated attacker with "User Operator" privileges to create a highly privileged user account. The vulnerability is caused by missing server-side validation, which can be exploited to gain full administrator privileges on the system.
0
Attacker Value
Unknown
CVE-2022-35798
Disclosure Date: May 18, 2023 (last updated January 11, 2025)
Azure Arc Jumpstart Information Disclosure Vulnerability
0