Show filters
223 Total Results
Displaying 21-30 of 223
Sort by:
Attacker Value
Unknown

CVE-2024-25126

Disclosure Date: February 29, 2024 (last updated February 15, 2025)
Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, leading to a possible denial of service vulnerability (ReDos 2nd degree polynomial). This vulnerability is patched in 3.0.9.1 and 2.2.8.1.
Attacker Value
Unknown

CVE-2023-5041

Disclosure Date: January 17, 2024 (last updated January 25, 2024)
The Track The Click WordPress plugin before 0.3.12 does not properly sanitize query parameters to the stats REST endpoint before using them in a database query, allowing a logged in user with an author role or higher to perform time based blind SQLi attacks on the database.
Attacker Value
Unknown

CVE-2020-22336

Disclosure Date: July 06, 2023 (last updated October 08, 2023)
An issue was discovered in pdfcrack 0.17 thru 0.18, allows attackers to execute arbitrary code via a stack overflow in the MD5 function.
Attacker Value
Unknown

CVE-2023-23822

Disclosure Date: June 12, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Ludwig Media UTM Tracker plugin <= 1.3.1 versions.
Attacker Value
Unknown

CVE-2023-3184

Disclosure Date: June 09, 2023 (last updated October 08, 2023)
A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /classes/Users.php?f=save. The manipulation of the argument firstname/middlename/lastname/username leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-231164.
Attacker Value
Unknown

CVE-2023-2678

Disclosure Date: May 12, 2023 (last updated October 08, 2023)
A vulnerability has been found in SourceCodester File Tracker Manager System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /file_manager/admin/save_user.php of the component POST Parameter Handler. The manipulation of the argument firstname leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-228892.
Attacker Value
Unknown

CVE-2023-2643

Disclosure Date: May 11, 2023 (last updated October 08, 2023)
A vulnerability classified as critical was found in SourceCodester File Tracker Manager System 1.0. This vulnerability affects unknown code of the file register/update_password.php of the component POST Parameter Handler. The manipulation of the argument new_password leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-228772.
Attacker Value
Unknown

CVE-2023-30112

Disclosure Date: April 26, 2023 (last updated October 08, 2023)
Medicine Tracker System in PHP 1.0.0 is vulnerable to SQL Injection.
Attacker Value
Unknown

CVE-2023-30111

Disclosure Date: April 26, 2023 (last updated October 08, 2023)
Medicine Tracker System in PHP 1.0.0 is vulnerable to Cross Site Scripting (XSS).
Attacker Value
Unknown

CVE-2023-30106

Disclosure Date: April 26, 2023 (last updated October 08, 2023)
Sourcecodester Medicine Tracker System in PHP 1.0.0 is vulnerable to Cross Site Scripting (XSS) via page=about.