Show filters
598 Total Results
Displaying 181-190 of 598
Sort by:
Attacker Value
Unknown

CVE-2023-30904

Disclosure Date: June 16, 2023 (last updated February 25, 2025)
A security vulnerability in HPE Insight Remote Support may result in the local disclosure of privileged LDAP information.
Attacker Value
Unknown

CVE-2020-36718

Disclosure Date: June 07, 2023 (last updated February 25, 2025)
The GDPR CCPA Compliance Support plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3 via deserialization of untrusted input "njt_gdpr_allow_permissions" value. This allows unauthenticated attackers to inject a PHP Object.
Attacker Value
Unknown

CVE-2023-33007

Disclosure Date: May 16, 2023 (last updated February 24, 2025)
Jenkins LoadComplete support Plugin 1.0 and earlier does not escape the LoadComplete test name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Attacker Value
Unknown

CVE-2023-33002

Disclosure Date: May 16, 2023 (last updated February 24, 2025)
Jenkins TestComplete support Plugin 2.8.1 and earlier does not escape the TestComplete project name, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Attacker Value
Unknown

CVE-2023-1730

Disclosure Date: May 02, 2023 (last updated February 24, 2025)
The SupportCandy WordPress plugin before 3.1.5 does not validate and escape user input before using it in an SQL statement, which could allow unauthenticated attackers to perform SQL injection attacks
Attacker Value
Unknown

CVE-2023-29443

Disclosure Date: April 26, 2023 (last updated February 24, 2025)
Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint.
Attacker Value
Unknown

CVE-2023-0276

Disclosure Date: April 24, 2023 (last updated October 08, 2023)
The Weaver Xtreme Theme Support WordPress plugin before 6.2.7 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2023-21971

Disclosure Date: April 18, 2023 (last updated October 08, 2023)
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors as well as unauthorized update, insert or delete access to some of MySQL Connectors accessible data and unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:H).
Attacker Value
Unknown

CVE-2022-47154

Disclosure Date: March 14, 2023 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Pi Websolution CSS JS Manager, Async JavaScript, Defer Render Blocking CSS supports WooCommerce plugin <= 2.4.49 versions.
Attacker Value
Unknown

CVE-2023-26601

Disclosure Date: March 06, 2023 (last updated February 24, 2025)
Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 14000 allow Denial-of-Service (DoS).