Show filters
75 Total Results
Displaying 21-30 of 75
Sort by:
Attacker Value
Unknown
CVE-2023-6798
Disclosure Date: January 06, 2024 (last updated February 25, 2025)
The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is vulnerable to unauthorized settings update due to a missing capability check when updating settings in all versions up to, and including, 4.3.2. This makes it possible for authenticated attackers, with author-level access or above to change the plugin's settings including proxy settings, which are also exposed to authors.
0
Attacker Value
Unknown
CVE-2023-38126
Disclosure Date: December 19, 2023 (last updated February 25, 2025)
Softing edgeAggregator Restore Configuration Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing edgeAggregator. Authentication is required to exploit this vulnerability.
The specific flaw exists within the processing of backup zip files. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this to execute code in the context of root. Was ZDI-CAN-20543.
0
Attacker Value
Unknown
CVE-2023-5909
Disclosure Date: November 30, 2023 (last updated February 25, 2025)
KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.
0
Attacker Value
Unknown
CVE-2023-5908
Disclosure Date: November 30, 2023 (last updated February 25, 2025)
KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information.
0
Attacker Value
Unknown
CVE-2020-36758
Disclosure Date: October 20, 2023 (last updated February 25, 2025)
The RSS Aggregator by Feedzy plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.4.2. This is due to missing or incorrect nonce validation on the save_feedzy_post_type_meta() function. This makes it possible for unauthenticated attackers to update post meta via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2023-37956
Disclosure Date: July 12, 2023 (last updated February 25, 2025)
A missing permission check in Jenkins Test Results Aggregator Plugin 1.2.13 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
0
Attacker Value
Unknown
CVE-2023-37955
Disclosure Date: July 12, 2023 (last updated February 25, 2025)
A cross-site request forgery (CSRF) vulnerability in Jenkins Test Results Aggregator Plugin 1.2.13 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.
0
Attacker Value
Unknown
CVE-2015-10120
Disclosure Date: July 10, 2023 (last updated February 25, 2025)
A vulnerability, which was classified as problematic, was found in WDS Multisite Aggregate Plugin up to 1.0.0 on WordPress. Affected is the function update_options of the file includes/WDS_Multisite_Aggregate_Options.php. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. Upgrading to version 1.0.1 is able to address this issue. The name of the patch is 49e0bbcb6ff70e561365d9e0d26426598f63ca12. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-233364.
0
Attacker Value
Unknown
CVE-2023-20881
Disclosure Date: May 19, 2023 (last updated February 25, 2025)
Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override other users syslog drain credentials if they're aware of the client certificate used for that syslog drain. This applies even if the drain has zero certs. This would allow the user to override the private key and add or modify a certificate authority used for the connection.
0
Attacker Value
Unknown
CVE-2023-28670
Disclosure Date: April 02, 2023 (last updated February 24, 2025)
Jenkins Pipeline Aggregator View Plugin 1.13 and earlier does not escape a variable representing the current view's URL in inline JavaScript, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by authenticated attackers with Overall/Read permission.
0