Show filters
1,431 Total Results
Displaying 251-260 of 1,431
Sort by:
Attacker Value
Unknown

CVE-2023-44144

Disclosure Date: October 02, 2023 (last updated February 25, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Dreamfox Payment gateway per Product for WooCommerce plugin <= 3.2.7 versions.
Attacker Value
Unknown

CVE-2023-43320

Disclosure Date: September 27, 2023 (last updated October 09, 2023)
An issue in Proxmox Server Solutions GmbH Proxmox VE v.5.4 thru v.8.0, Proxmox Backup Server v.1.1 thru v.3.0, and Proxmox Mail Gateway v.7.1 thru v.8.0 allows a remote authenticated attacker to escalate privileges via bypassing the two-factor authentication component.
Attacker Value
Unknown

CVE-2023-39252

Disclosure Date: September 21, 2023 (last updated February 25, 2025)
Dell SCG Policy Manager 5.16.00.14 contains a broken cryptographic algorithm vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by performing MitM attacks and let attackers obtain sensitive information.
Attacker Value
Unknown

CVE-2023-41011

Disclosure Date: September 14, 2023 (last updated February 25, 2025)
Command Execution vulnerability in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the shortcut_telnet.cg component.
Attacker Value
Unknown

CVE-2023-4948

Disclosure Date: September 14, 2023 (last updated November 09, 2023)
The WooCommerce CVR Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the refresh_order_cvr_data AJAX action in versions up to 6.1.0. This makes it possible for authenticated attackers with contributor-level access and above, to update CVR numbers for orders.
Attacker Value
Unknown

CVE-2023-4400

Disclosure Date: September 13, 2023 (last updated February 25, 2025)
A password management vulnerability in Skyhigh Secure Web Gateway (SWG) in main releases 11.x prior to 11.2.14, 10.x prior to 10.2.25 and controlled release 12.x prior to 12.2.1, allows some authentication information stored in configuration files to be extracted through SWG REST API. This was possible due to SWG storing the password in plain text in some configuration files.
Attacker Value
Unknown

CVE-2023-41012

Disclosure Date: September 05, 2023 (last updated February 25, 2025)
An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the authentication mechanism.
Attacker Value
Unknown

CVE-2023-39809

Disclosure Date: August 21, 2023 (last updated February 25, 2025)
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a command injection vulnerability via the system_hostname parameter at /manage/network-basic.php.
Attacker Value
Unknown

CVE-2023-39808

Disclosure Date: August 21, 2023 (last updated February 25, 2025)
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a hardcoded root password which allows attackers to login with root privileges via the SSH service.
Attacker Value
Unknown

CVE-2023-39807

Disclosure Date: August 21, 2023 (last updated February 25, 2025)
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a SQL injection vulnerability via the a_passwd parameter at /portal/user-register.php.