Show filters
588 Total Results
Displaying 151-160 of 588
Sort by:
Attacker Value
Unknown

CVE-2023-33372

Disclosure Date: August 04, 2023 (last updated October 08, 2023)
Connected IO v2.1.0 and prior uses a hard-coded username/password pair embedded in their device's firmware used for device communication using MQTT. An attacker who gained access to these credentials is able to connect to the MQTT broker and send messages on behalf of devices, impersonating them. in order to sign and verify JWT session tokens, allowing attackers to sign arbitrary session tokens and bypass authentication.
Attacker Value
Unknown

CVE-2023-38493

Disclosure Date: July 25, 2023 (last updated October 08, 2023)
Armeria is a microservice framework Spring supports Matrix variables. When Spring integration is used, Armeria calls Spring controllers via `TomcatService` or `JettyService` with the path that may contain matrix variables. Prior to version 1.24.3, the Armeria decorators might not invoked because of the matrix variables. If an attacker sends a specially crafted request, the request may bypass the authorizer. Version 1.24.3 contains a patch for this issue.
Attacker Value
Unknown

CVE-2023-37974

Disclosure Date: July 17, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Justin Klein WP Social AutoConnect plugin <= 4.6.1 versions.
Attacker Value
Unknown

CVE-2023-2330

Disclosure Date: July 17, 2023 (last updated October 08, 2023)
The Caldera Forms Google Sheets Connector WordPress plugin before 1.3 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
Attacker Value
Unknown

CVE-2023-2329

Disclosure Date: July 17, 2023 (last updated October 08, 2023)
The WooCommerce Google Sheet Connector WordPress plugin before 1.3.6 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
Attacker Value
Unknown

CVE-2021-46896

Disclosure Date: July 06, 2023 (last updated October 08, 2023)
Buffer Overflow vulnerability in PX4-Autopilot allows attackers to cause a denial of service via handler function handling msgid 332.
Attacker Value
Unknown

CVE-2023-2333

Disclosure Date: July 04, 2023 (last updated October 08, 2023)
The Ninja Forms Google Sheet Connector WordPress plugin before 1.2.7, gsheetconnector-ninja-forms-pro WordPress plugin through 1.2.7 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Attacker Value
Unknown

CVE-2023-2324

Disclosure Date: July 04, 2023 (last updated October 08, 2023)
The Elementor Forms Google Sheet Connector WordPress plugin before 1.0.7, gsheetconnector-for-elementor-forms-pro WordPress plugin through 1.0.7 does not escape some parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Attacker Value
Unknown

CVE-2023-2321

Disclosure Date: July 04, 2023 (last updated October 08, 2023)
The WPForms Google Sheet Connector WordPress plugin before 3.4.6, gsheetconnector-wpforms-pro WordPress plugin through 3.4.6 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
Attacker Value
Unknown

CVE-2023-2320

Disclosure Date: July 04, 2023 (last updated October 08, 2023)
The CF7 Google Sheets Connector WordPress plugin before 5.0.2, cf7-google-sheets-connector-pro WordPress plugin through 5.0.2 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin