Show filters
138 Total Results
Displaying 21-30 of 138
Sort by:
Attacker Value
Unknown

CVE-2024-2281

Disclosure Date: March 08, 2024 (last updated March 08, 2024)
A vulnerability was found in boyiddha Automated-Mess-Management-System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php of the component Setting Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-256048. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown

CVE-2023-47257

Disclosure Date: February 01, 2024 (last updated February 08, 2024)
ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.
Attacker Value
Unknown

CVE-2023-47256

Disclosure Date: February 01, 2024 (last updated February 08, 2024)
ConnectWise ScreenConnect through 23.8.4 allows local users to connect to arbitrary relay servers via implicit trust of proxy settings
Attacker Value
Unknown

CVE-2023-7127

Disclosure Date: December 28, 2023 (last updated January 06, 2024)
A vulnerability classified as critical was found in code-projects Automated Voting System 1.0. This vulnerability affects unknown code of the component Login. The manipulation of the argument idno leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-249130 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-7126

Disclosure Date: December 28, 2023 (last updated January 06, 2024)
A vulnerability classified as critical has been found in code-projects Automated Voting System 1.0. This affects an unknown part of the file /admin/ of the component Admin Login. The manipulation of the argument username leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-249129 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-33318

Disclosure Date: December 20, 2023 (last updated December 29, 2023)
Unrestricted Upload of File with Dangerous Type vulnerability in WooCommerce AutomateWoo.This issue affects AutomateWoo: from n/a through 4.9.40.
Attacker Value
Unknown

CVE-2023-33330

Disclosure Date: December 20, 2023 (last updated December 27, 2023)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce AutomateWoo.This issue affects AutomateWoo: from n/a through 4.9.50.
Attacker Value
Unknown

CVE-2023-32743

Disclosure Date: December 20, 2023 (last updated December 29, 2023)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WooCommerce AutomateWoo.This issue affects AutomateWoo: from n/a through 5.7.1.
Attacker Value
Unknown

CVE-2023-32745

Disclosure Date: November 09, 2023 (last updated November 16, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in WooCommerce AutomateWoo plugin <= 5.7.1 versions.
Attacker Value
Unknown

CVE-2023-40050

Disclosure Date: October 31, 2023 (last updated November 09, 2023)
Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution.