Show filters
914 Total Results
Displaying 251-260 of 914
Sort by:
Attacker Value
Unknown

CVE-2023-50928

Disclosure Date: December 22, 2023 (last updated February 25, 2025)
"Sandbox Accounts for Events" provides multiple, temporary AWS accounts to a number of authenticated users simultaneously via a browser-based GUI. Authenticated users could potentially claim and access empty AWS accounts by sending request payloads to the account API containing non-existent event ids and self-defined budget & duration. This issue only affects cleaned AWS accounts, it is not possible to access AWS accounts in use or existing data/infrastructure. This issue has been patched in version 1.1.0.
Attacker Value
Unknown

CVE-2023-47525

Disclosure Date: December 21, 2023 (last updated February 25, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A WP Life Event Monster – Event Management, Tickets Booking, Upcoming Event allows Stored XSS.This issue affects Event Monster – Event Management, Tickets Booking, Upcoming Event: from n/a through 1.3.2.
Attacker Value
Unknown

CVE-2023-47146

Disclosure Date: December 19, 2023 (last updated February 25, 2025)
IBM Qradar SIEM 7.5 could allow a privileged user to obtain sensitive domain information due to data being misidentified. IBM X-Force ID: 270372.
Attacker Value
Unknown

CVE-2023-48772

Disclosure Date: December 18, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Arul Prasad J Prevent Landscape Rotation.This issue affects Prevent Landscape Rotation: from n/a through 2.0.
Attacker Value
Unknown

CVE-2023-6203

Disclosure Date: December 18, 2023 (last updated October 08, 2024)
The Events Calendar WordPress plugin before 6.2.8.1 discloses the content of password protected posts to unauthenticated users via a crafted request
Attacker Value
Unknown

CVE-2023-35867

Disclosure Date: December 18, 2023 (last updated February 25, 2025)
An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.
Attacker Value
Unknown

CVE-2023-49181

Disclosure Date: December 15, 2023 (last updated February 25, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Event Manager WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce allows Stored XSS.This issue affects WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce: from n/a through 3.1.40.
Attacker Value
Unknown

CVE-2023-49179

Disclosure Date: December 15, 2023 (last updated February 25, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in N.O.U.S. Open Useful and Simple Event post allows Stored XSS.This issue affects Event post: from n/a through 5.8.6.
Attacker Value
Unknown

CVE-2023-47827

Disclosure Date: November 30, 2023 (last updated February 25, 2025)
Incorrect Authorization vulnerability in NicheAddons Events Addon for Elementor allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Events Addon for Elementor: from n/a through 2.1.3.
Attacker Value
Unknown

CVE-2023-48326

Disclosure Date: November 30, 2023 (last updated February 25, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixelite Events Manager allows Reflected XSS.This issue affects Events Manager: from n/a through 6.4.5.