Show filters
744 Total Results
Displaying 191-200 of 744
Sort by:
Attacker Value
Unknown

CVE-2023-34736

Disclosure Date: June 28, 2023 (last updated February 25, 2025)
Guantang Equipment Management System version 4.12 is vulnerable to Arbitrary File Upload.
Attacker Value
Unknown

CVE-2023-29438

Disclosure Date: June 26, 2023 (last updated February 25, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Eric Martin SimpleModal Contact Form (SMCF) plugin <= 1.2.9 versions.
Attacker Value
Unknown

CVE-2023-34188

Disclosure Date: June 23, 2023 (last updated February 25, 2025)
The HTTP server in Mongoose before 7.10 accepts requests containing negative Content-Length headers. By sending a single attack payload over TCP, an attacker can cause an infinite loop in which the server continuously reparses that payload, and does not respond to any other requests.
Attacker Value
Unknown

CVE-2023-2673

Disclosure Date: June 13, 2023 (last updated February 25, 2025)
Improper Input Validation vulnerability in PHOENIX CONTACT FL/TC MGUARD Family in multiple versions may allow UDP packets to bypass the filter rules and access the solely connected device behind the MGUARD which can be used for flooding attacks.
Attacker Value
Unknown

CVE-2022-47167

Disclosure Date: May 22, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Aram Kocharyan Crayon Syntax Highlighter plugin <= 2.8.4 versions.
Attacker Value
Unknown

CVE-2023-2713

Disclosure Date: May 20, 2023 (last updated February 25, 2025)
Authorization Bypass Through User-Controlled Key vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Authentication Abuse, Authentication Bypass.This issue affects Rental Module: before 23.05.15.
Attacker Value
Unknown

CVE-2023-2712

Disclosure Date: May 20, 2023 (last updated February 25, 2025)
Unrestricted Upload of File with Dangerous Type vulnerability in "Rental Module" developed by third-party for Ideasoft's E-commerce Platform allows Command Injection, Using Malicious Files, Upload a Web Shell to a Web Server.This issue affects Rental Module: before 23.05.15.
Attacker Value
Unknown

CVE-2023-2824

Disclosure Date: May 20, 2023 (last updated February 25, 2025)
A vulnerability was found in SourceCodester Dental Clinic Appointment Reservation System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/service.php of the component POST Parameter Handler. The manipulation of the argument service leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-229598 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-30247

Disclosure Date: May 12, 2023 (last updated February 24, 2025)
File Upload vulnerability found in Oretnom23 Storage Unit Rental Management System v.1.0 allows a remote attacker to execute arbitrary code via the update_settings parameter.
Attacker Value
Unknown

CVE-2023-2677

Disclosure Date: May 12, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as critical, was found in SourceCodester Covid-19 Contact Tracing System 1.0. This affects an unknown part of the file admin/establishment/manage.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-228891.