Show filters
1,431 Total Results
Displaying 211-220 of 1,431
Sort by:
Attacker Value
Unknown

CVE-2023-47140

Disclosure Date: January 08, 2024 (last updated February 25, 2025)
IBM CICS Transaction Gateway 9.3 could allow a user to transfer or view files due to improper access controls.
Attacker Value
Unknown

CVE-2023-50093

Disclosure Date: January 03, 2024 (last updated February 25, 2025)
APIIDA API Gateway Manager for Broadcom Layer7 v2023.2.2 is vulnerable to Host Header Injection.
Attacker Value
Unknown

CVE-2023-50092

Disclosure Date: January 03, 2024 (last updated February 25, 2025)
APIIDA API Gateway Manager for Broadcom Layer7 v2023.2 is vulnerable to Cross Site Scripting (XSS).
Attacker Value
Unknown

CVE-2023-6064

Disclosure Date: January 01, 2024 (last updated February 25, 2025)
The PayHere Payment Gateway WordPress plugin before 2.2.12 automatically creates publicly-accessible log files containing sensitive information when transactions occur.
Attacker Value
Unknown

CVE-2023-52269

Disclosure Date: December 31, 2023 (last updated February 25, 2025)
MDaemon SecurityGateway through 9.0.3 allows XSS via a crafted Message Content Filtering rule. This might allow domain administrators to conduct attacks against global administrators.
Attacker Value
Unknown

CVE-2023-7161

Disclosure Date: December 29, 2023 (last updated February 25, 2025)
A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3.1. This affects an unknown part of the file index.php?para=index of the component Login. The manipulation of the argument check_VirtualSiteId leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249183.
Attacker Value
Unknown

CVE-2023-7094

Disclosure Date: December 25, 2023 (last updated February 25, 2025)
A vulnerability classified as problematic was found in Netentsec NS-ASG Application Security Gateway 6.3. Affected by this vulnerability is an unknown functionality of the file /protocol/nsasg6.0.tgz. The manipulation leads to information disclosure. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-248941 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2023-7026

Disclosure Date: December 21, 2023 (last updated February 25, 2025)
A vulnerability was found in Lightxun IPTV Gateway up to 20231208. It has been rated as problematic. This issue affects some unknown processing of the file /ZHGXTV/index.php/admin/index/web_upload_template.html. The manipulation of the argument file leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-248579.
Attacker Value
Unknown

CVE-2023-32230

Disclosure Date: December 18, 2023 (last updated February 25, 2025)
An improper handling of a malformed API request to an API server in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation.
Attacker Value
Unknown

CVE-2023-6911

Disclosure Date: December 18, 2023 (last updated February 25, 2025)
Multiple WSO2 products have been identified as vulnerable due to improper output encoding, a Stored Cross Site Scripting (XSS) attack can be carried out by an attacker injecting a malicious payload into the Registry feature of the Management Console.