Show filters
123 Total Results
Displaying 21-30 of 123
Sort by:
Attacker Value
Unknown

CVE-2023-47767

Disclosure Date: November 22, 2023 (last updated November 29, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fla-shop.Com Interactive World Map plugin <= 3.2.0 versions.
Attacker Value
Unknown

CVE-2023-47223

Disclosure Date: November 08, 2023 (last updated November 15, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WP Map Plugins Basic Interactive World Map plugin <= 2.0 versions.
Attacker Value
Unknown

CVE-2023-3010

Disclosure Date: October 25, 2023 (last updated February 14, 2025)
Grafana is an open-source platform for monitoring and observability. The WorldMap panel plugin, versions before 1.0.4 contains a DOM XSS vulnerability.
Attacker Value
Unknown

CVE-2023-45060

Disclosure Date: October 12, 2023 (last updated October 18, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Fla-shop.Com Interactive World Map plugin <= 3.2.0 versions.
Attacker Value
Unknown

CVE-2023-38357

Disclosure Date: August 01, 2023 (last updated October 08, 2023)
Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized access to user sessions.
Attacker Value
Unknown

CVE-2023-35925

Disclosure Date: June 23, 2023 (last updated October 08, 2023)
FastAsyncWorldEdit (FAWE) is designed for efficient world editing. This vulnerability enables the attacker to select a region with the `Infinity` keyword (case-sensitive!) and executes any operation. This has a possibility of bringing the performing server down. This issue has been fixed in version 2.6.3.
Attacker Value
Unknown

CVE-2023-31518

Disclosure Date: May 23, 2023 (last updated October 08, 2023)
A heap use-after-free in the component CDataFileReader::GetItem of teeworlds v0.7.5 allows attackers to cause a Denial of Service (DoS) via a crafted map file.
Attacker Value
Unknown

CVE-2023-31517

Disclosure Date: May 23, 2023 (last updated March 07, 2024)
A memory leak in the component CConsole::Chain of Teeworlds v0.7.5 allows attackers to cause a Denial of Service (DoS) via opening a crafted file.
Attacker Value
Unknown

CVE-2023-0145

Disclosure Date: March 20, 2023 (last updated October 08, 2023)
The Saan World Clock WordPress plugin through 1.8 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2022-31265

Disclosure Date: May 26, 2022 (last updated February 23, 2025)
The replay feature in the client in Wargaming World of Warships 0.11.4 allows remote attackers to execute code when a user launches a replay from an untrusted source.