Show filters
93 Total Results
Displaying 21-30 of 93
Sort by:
Attacker Value
Unknown
CVE-2024-23501
Disclosure Date: February 29, 2024 (last updated January 17, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shopfiles Ltd Ebook Store allows Stored XSS.This issue affects Ebook Store: from n/a through 5.788.
0
Attacker Value
Unknown
CVE-2024-0563
Disclosure Date: February 23, 2024 (last updated February 23, 2024)
Denial of service condition in M-Files Server in versions before 24.2 (excluding 23.2 SR7 and 23.8 SR5) allows anonymous user to cause denial of service against other anonymous users.
0
Attacker Value
Unknown
CVE-2023-6912
Disclosure Date: December 20, 2023 (last updated August 28, 2024)
Lack of protection against brute force attacks in M-Files Server before 23.12.13205.0 allows an attacker unlimited authentication attempts, potentially compromising targeted M-Files user accounts by guessing passwords.
0
Attacker Value
Unknown
CVE-2023-6910
Disclosure Date: December 20, 2023 (last updated January 30, 2024)
A vulnerable API method in M-Files Server before 23.12.13195.0 allows for uncontrolled resource consumption. Authenticated attacker can exhaust server storage space to a point where the server can no longer serve requests.
0
Attacker Value
Unknown
CVE-2023-4460
Disclosure Date: December 04, 2023 (last updated December 08, 2023)
The Uploading SVG, WEBP and ICO files WordPress plugin through 1.2.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.
0
Attacker Value
Unknown
CVE-2023-6239
Disclosure Date: November 28, 2023 (last updated August 28, 2024)
Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specific configuration of metadata-driven permissions in M-Files Server versions 23.9, 23.10, and 23.11 before 23.11.13168.7, potentially enabling unauthorized access to the object.
0
Attacker Value
Unknown
CVE-2023-6189
Disclosure Date: November 22, 2023 (last updated August 28, 2024)
Missing access permissions checks
in the M-Files server before 23.11.13156.0 allow attackers to perform data write and export
jobs using the M-Files API methods.
0
Attacker Value
Unknown
CVE-2023-6117
Disclosure Date: November 22, 2023 (last updated November 30, 2023)
A possibility of unwanted server memory consumption was detected through the obsolete functionalities in the Rest API methods of the M-Files server
before 23.11.13156.0 which allows attackers to execute DoS attacks.
0
Attacker Value
Unknown
CVE-2023-4836
Disclosure Date: October 31, 2023 (last updated November 09, 2023)
The WordPress File Sharing Plugin WordPress plugin before 2.0.5 does not check authorization before displaying files and folders, allowing users to gain access to those filed by manipulating IDs which can easily be brute forced
0
Attacker Value
Unknown
CVE-2023-4393
Disclosure Date: October 30, 2023 (last updated November 09, 2023)
HTML and SMTP injections on the registration page of LiquidFiles versions 3.7.13 and below, allow an attacker to perform more advanced phishing attacks against an organization.
0