Show filters
598 Total Results
Displaying 171-180 of 598
Sort by:
Attacker Value
Unknown

CVE-2023-35785

Disclosure Date: August 28, 2023 (last updated February 25, 2025)
Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data Security Plus 6110 and below, Eventlog Analyzer 12301 and below, Exchange Reporter Plus 5709 and below, Log360 5315 and below, Log360 UEBA 4045 and below, M365 Manager Plus 4529 and below, M365 Security Plus 4529 and below, Recovery Manager Plus 6061 and below, ServiceDesk Plus 14204 and below and 143xx 14302 and below, ServiceDesk Plus MSP 14300 and below, SharePoint Manager Plus 4402 and below, and Support Center Plus 14300 and below are vulnerable to 2FA bypass via a few TOTP authenticators. Note: A valid pair of username and password is required to leverage this vulnerability.
Attacker Value
Unknown

CVE-2023-40766

Disclosure Date: August 28, 2023 (last updated February 25, 2025)
User enumeration is found in in PHPJabbers Ticket Support Script v3.2. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
Attacker Value
Unknown

CVE-2023-40753

Disclosure Date: August 28, 2023 (last updated February 25, 2025)
There is a Cross Site Scripting (XSS) vulnerability in the message parameter of index.php in PHPJabbers Ticket Support Script v3.2.
Attacker Value
Unknown

CVE-2023-27515

Disclosure Date: August 11, 2023 (last updated February 25, 2025)
Cross-site scripting (XSS) for the Intel(R) DSA software before version 23.1.9 may allow unauthenticated user to potentially enable escalation of privilege via network access.
Attacker Value
Unknown

CVE-2023-27392

Disclosure Date: August 11, 2023 (last updated February 25, 2025)
Incorrect default permissions in the Intel(R) Support android application before version v23.02.07 may allow a privileged user to potentially enable information disclosure via local access.
Attacker Value
Unknown

CVE-2023-39776

Disclosure Date: August 10, 2023 (last updated February 25, 2025)
A File Upload vulnerability in PHPJabbers Ticket Support Script v3.2 allows attackers to execute arbitrary code via uploading a crafted file.
Attacker Value
Unknown

CVE-2023-38331

Disclosure Date: July 28, 2023 (last updated February 25, 2025)
Zoho ManageEngine Support Center Plus 14001 and below is vulnerable to stored XSS in the products module.
Attacker Value
Unknown

CVE-2023-34197

Disclosure Date: July 07, 2023 (last updated February 25, 2025)
Zoho ManageEngine ServiceDesk Plus before 14202, ServiceDesk Plus MSP before 14300, and SupportCenter Plus before 14300 have a privilege escalation vulnerability in the Release module that allows unprivileged users to access the Reminders of a release ticket and make modifications.
Attacker Value
Unknown

CVE-2023-2805

Disclosure Date: June 19, 2023 (last updated October 08, 2023)
The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the agents[] parameter in the set_add_agent_leaves AJAX function before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
Attacker Value
Unknown

CVE-2023-2719

Disclosure Date: June 19, 2023 (last updated October 08, 2023)
The SupportCandy WordPress plugin before 3.1.7 does not properly sanitise and escape the `id` parameter for an Agent in the REST API before using it in an SQL statement, leading to an SQL Injection exploitable by users with a role as low as Subscriber.