Show filters
1,462 Total Results
Displaying 181-190 of 1,462
Sort by:
Attacker Value
Unknown

CVE-2024-0263

Disclosure Date: January 07, 2024 (last updated February 25, 2025)
A vulnerability was found in ACME Ultra Mini HTTPd 1.21. It has been classified as problematic. This affects an unknown part of the component HTTP GET Request Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-249819.
Attacker Value
Unknown

CVE-2023-48419

Disclosure Date: January 02, 2024 (last updated February 25, 2025)
An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege 
Attacker Value
Unknown

CVE-2023-52132

Disclosure Date: December 31, 2023 (last updated February 25, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jewel Theme WP Adminify.This issue affects WP Adminify: from n/a through 3.1.6.
Attacker Value
Unknown

CVE-2023-7078

Disclosure Date: December 29, 2023 (last updated February 25, 2025)
Sending specially crafted HTTP requests to Miniflare's server could result in arbitrary HTTP and WebSocket requests being sent from the server. If Miniflare was configured to listen on external network interfaces (as was the default in wrangler until 3.19.0), an attacker on the local network could access other local servers.
Attacker Value
Unknown

CVE-2023-37225

Disclosure Date: December 25, 2023 (last updated February 25, 2025)
Pexip Infinity before 32 allows Webapp1 XSS via preconfigured links.
Attacker Value
Unknown

CVE-2023-31455

Disclosure Date: December 25, 2023 (last updated February 25, 2025)
Pexip Infinity before 31.2 has Improper Input Validation for RTCP, allowing remote attackers to trigger an abort.
Attacker Value
Unknown

CVE-2023-31289

Disclosure Date: December 25, 2023 (last updated February 25, 2025)
Pexip Infinity before 31.2 has Improper Input Validation for signalling, allowing remote attackers to trigger an abort.
Attacker Value
Unknown

CVE-2023-6784

Disclosure Date: December 20, 2023 (last updated February 25, 2025)
A malicious user could potentially use the Sitefinity system for the distribution of phishing emails.
Attacker Value
Unknown

CVE-2023-5384

Disclosure Date: December 18, 2023 (last updated February 25, 2025)
A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.
Attacker Value
Unknown

CVE-2023-5236

Disclosure Date: December 18, 2023 (last updated February 25, 2025)
A flaw was found in Infinispan, which does not detect circular object references when unmarshalling. An authenticated attacker with sufficient permissions could insert a maliciously constructed object into the cache and use it to cause out of memory errors and achieve a denial of service.