Show filters
61 Total Results
Displaying 21-30 of 61
Sort by:
Attacker Value
Unknown

CVE-2023-34051

Disclosure Date: October 20, 2023 (last updated October 31, 2023)
VMware Aria Operations for Logs contains an authentication bypass vulnerability. An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution.
Attacker Value
Unknown

CVE-2023-5538

Disclosure Date: October 18, 2023 (last updated October 25, 2023)
The MpOperationLogs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the IP Request Headers in versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2023-20865

Disclosure Date: April 20, 2023 (last updated October 08, 2023)
VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operations for Logs can execute arbitrary commands as root.
Attacker Value
Unknown

CVE-2023-20864

Disclosure Date: April 20, 2023 (last updated October 08, 2023)
VMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root.
Attacker Value
Unknown

CVE-2022-31520

Disclosure Date: July 11, 2022 (last updated October 07, 2023)
The Luxas98/logstash-management-api repository through 2020-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Attacker Value
Unknown

CVE-2022-23409

Disclosure Date: January 31, 2022 (last updated February 23, 2025)
The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php.
Attacker Value
Unknown

CVE-2021-24767

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
The Redirect 404 Error Page to Homepage or Custom Page with Logs WordPress plugin before 1.7.9 does not check for CSRF when deleting logs, which could allow attacker to make a logged in admin delete them via a CSRF attack
Attacker Value
Unknown

CVE-2021-32752

Disclosure Date: July 09, 2021 (last updated February 23, 2025)
Ether Logs is a package that allows one to check one's logs in the Craft 3 utilities section. A vulnerability was found in versions prior to 3.0.4 that allowed authenticated admin users to access any file on the server. The vulnerability has been fixed in version 3.0.4. As a workaround, one may disable the plugin if untrustworthy sources have admin access.
Attacker Value
Unknown

CVE-2021-22138

Disclosure Date: May 13, 2021 (last updated February 22, 2025)
In Logstash versions after 6.4.0 and before 6.8.15 and 7.12.0 a TLS certificate validation flaw was found in the monitoring feature. When specifying a trusted server CA certificate Logstash would not properly verify the certificate returned by the monitoring server. This could result in a man in the middle style attack against the Logstash monitoring data.
Attacker Value
Unknown

CVE-2021-29438

Disclosure Date: April 13, 2021 (last updated February 22, 2025)
The Nextcloud dialogs library (npm package @nextcloud/dialogs) before 3.1.2 insufficiently escaped text input passed to a toast. If your application displays toasts with user-supplied input, this could lead to a XSS vulnerability. The vulnerability has been patched in version 3.1.2 If you need to display HTML in the toast, explicitly pass the `options.isHTML` config flag.