Show filters
529 Total Results
Displaying 211-220 of 529
Sort by:
Attacker Value
Unknown

CVE-2024-23985

Disclosure Date: January 25, 2024 (last updated February 02, 2024)
EzServer 6.4.017 allows a denial of service (daemon crash) via a long string, such as one for the RNTO command.
Attacker Value
Unknown

CVE-2023-5911

Disclosure Date: January 08, 2024 (last updated February 25, 2025)
The WP Custom Cursors | WordPress Cursor Plugin WordPress plugin through 3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Attacker Value
Unknown

CVE-2023-41613

Disclosure Date: December 04, 2023 (last updated February 25, 2025)
EzViz Studio v2.2.0 is vulnerable to DLL hijacking.
Attacker Value
Unknown

CVE-2023-48121

Disclosure Date: November 28, 2023 (last updated February 25, 2025)
An authentication bypass vulnerability in the Direct Connection Module in Ezviz CS-C6N-xxx prior to v5.3.x build 20230401, Ezviz CS-CV310-xxx prior to v5.3.x build 20230401, Ezviz CS-C6CN-xxx prior to v5.3.x build 20230401, Ezviz CS-C3N-xxx prior to v5.3.x build 20230401 allows remote attackers to obtain sensitive information by sending crafted messages to the affected devices.
Attacker Value
Unknown

CVE-2023-47829

Disclosure Date: November 22, 2023 (last updated February 25, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Codez Quick Call Button plugin <= 1.2.9 versions.
Attacker Value
Unknown

CVE-2023-32739

Disclosure Date: November 09, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Web_Trendy WP Custom Cursors | WordPress Cursor Plugin plugin < 3.2 versions.
Attacker Value
Unknown

CVE-2023-46117

Disclosure Date: October 20, 2023 (last updated February 25, 2025)
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities. A vulnerability has been identified in reconftw where inadequate validation of retrieved subdomains may lead to a Remote Code Execution (RCE) attack. An attacker can exploit this vulnerability by crafting a malicious CSP entry on it's own domain. Successful exploitation can lead to the execution of arbitrary code within the context of the application, potentially compromising the system. This issue has been addressed in version 2.7.1.1 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Attacker Value
Unknown

CVE-2023-25476

Disclosure Date: October 18, 2023 (last updated February 25, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Ezoic AmpedSense – AdSense Split Tester plugin <= 4.68 versions.
Attacker Value
Unknown

CVE-2023-3038

Disclosure Date: October 04, 2023 (last updated February 25, 2025)
SQL injection vulnerability in HelpDezk Community affecting version 1.1.10. This vulnerability could allow a remote attacker to send a specially crafted SQL query to the rows parameter of the jsonGrid route and extract all the information stored in the application.
Attacker Value
Unknown

CVE-2023-3037

Disclosure Date: October 04, 2023 (last updated February 25, 2025)
Improper authorization vulnerability in HelpDezk Community affecting version 1.1.10. This vulnerability could allow a remote attacker to access the platform without authentication and retrieve personal data via the jsonGrid parameter.