Show filters
290 Total Results
Displaying 21-30 of 290
Sort by:
Attacker Value
Unknown

CVE-2024-4233

Disclosure Date: May 08, 2024 (last updated February 26, 2025)
Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce, Tyche Softwares Arconix Shortcodes, Tyche Softwares Arconix FAQ.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a through 4.8.1; Arconix Shortcodes: from n/a through 2.1.10; Arconix FAQ: from n/a through 1.9.3.
0
Attacker Value
Unknown

CVE-2023-49742

Disclosure Date: April 18, 2024 (last updated February 26, 2025)
Missing Authorization vulnerability in Support Genix.This issue affects Support Genix: from n/a through 1.2.3.
0
Attacker Value
Unknown

CVE-2024-27297

Disclosure Date: March 11, 2024 (last updated February 27, 2025)
Nix is a package manager for Linux and other Unix systems. A fixed-output derivations on Linux can send file descriptors to files in the Nix store to another program running on the host (or another fixed-output derivation) via Unix domain sockets in the abstract namespace. This allows to modify the output of the derivation, after Nix has registered the path as "valid" and immutable in the Nix database. In particular, this allows the output of fixed-output derivations to be modified from their expected content. This issue has been addressed in versions 2.3.18 2.18.2 2.19.4 and 2.20.5. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Attacker Value
Unknown

CVE-2023-32331

Disclosure Date: March 04, 2024 (last updated February 26, 2025)
IBM Connect:Express for UNIX 1.5.0 is vulnerable to a buffer overflow that could allow a remote attacker to cause a denial of service through its browser UI. IBM X-Force ID: 254979.
Attacker Value
Unknown

CVE-2024-25415

Disclosure Date: February 16, 2024 (last updated February 26, 2025)
A remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to execute arbitrary PHP code via injecting a crafted payload into the file english.php.
Attacker Value
Unknown

CVE-2023-37219

Disclosure Date: July 30, 2023 (last updated February 25, 2025)
Tadiran Telecom Composit - CWE-1236: Improper Neutralization of Formula Elements in a CSV File
Attacker Value
Unknown

CVE-2023-37218

Disclosure Date: July 30, 2023 (last updated February 25, 2025)
Tadiran Telecom Aeonix - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Attacker Value
Unknown

CVE-2023-37217

Disclosure Date: July 30, 2023 (last updated February 25, 2025)
Tadiran Telecom Aeonix - CWE-204: Observable Response Discrepancy
Attacker Value
Unknown

CVE-2023-29260

Disclosure Date: July 19, 2023 (last updated February 25, 2025)
IBM Sterling Connect:Express for UNIX 1.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 252135.
Attacker Value
Unknown

CVE-2023-29259

Disclosure Date: July 19, 2023 (last updated October 08, 2023)
IBM Sterling Connect:Express for UNIX 1.5 browser UI is vulnerable to attacks that rely on the use of cookies without the SameSite attribute. IBM X-Force ID: 252055.