Show filters
1,715 Total Results
Displaying 231-240 of 1,715
Sort by:
Attacker Value
Unknown

CVE-2023-25788

Disclosure Date: October 04, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Saphali Saphali Woocommerce Lite plugin <= 1.8.13 versions.
Attacker Value
Unknown

CVE-2023-40307

Disclosure Date: September 28, 2023 (last updated February 25, 2025)
An attacker with standard privileges on macOS when requesting administrator privileges from the application can submit input which causes a buffer overflow resulting in a crash of the application. This could make the application unavailable and allow reading or modification of data.
Attacker Value
Unknown

CVE-2023-4665

Disclosure Date: September 15, 2023 (last updated February 25, 2025)
Incorrect Execution-Assigned Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation.This issue affects Saphira Connect: before 9.
Attacker Value
Unknown

CVE-2023-4664

Disclosure Date: September 15, 2023 (last updated February 25, 2025)
Incorrect Default Permissions vulnerability in Saphira Saphira Connect allows Privilege Escalation.This issue affects Saphira Connect: before 9.
Attacker Value
Unknown

CVE-2023-4663

Disclosure Date: September 15, 2023 (last updated February 25, 2025)
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Saphira Saphira Connect allows Reflected XSS.This issue affects Saphira Connect: before 9.
Attacker Value
Unknown

CVE-2023-4662

Disclosure Date: September 15, 2023 (last updated February 25, 2025)
Execution with Unnecessary Privileges vulnerability in Saphira Saphira Connect allows Remote Code Inclusion.This issue affects Saphira Connect: before 9.
Attacker Value
Unknown

CVE-2023-4661

Disclosure Date: September 15, 2023 (last updated February 25, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saphira Saphira Connect allows SQL Injection.This issue affects Saphira Connect: before 9.
Attacker Value
Unknown

CVE-2023-40625

Disclosure Date: September 12, 2023 (last updated February 25, 2025)
S4CORE (Manage Purchase Contracts App) - versions 102, 103, 104, 105, 106, 107, does not perform necessary authorization checks for an authenticated user. This could allow an attacker to perform unintended actions resulting in escalation of privileges which has low impact on confidentiality and integrity with no impact on availibility of the system.
Attacker Value
Unknown

CVE-2023-40624

Disclosure Date: September 12, 2023 (last updated February 25, 2025)
SAP NetWeaver AS ABAP (applications based on Unified Rendering) - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_UI 758, SAP_BASIS 702, SAP_BASIS 731, allows an attacker to inject JavaScript code that can be executed in the web-application. An attacker could thereby control the behavior of this web-application.
Attacker Value
Unknown

CVE-2023-40623

Disclosure Date: September 12, 2023 (last updated February 25, 2025)
SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory under temporary directory and link it to a directory with operating system files. On successful exploitation the attacker can delete all the operating system files causing a limited impact on integrity and completely compromising the availability of the system.