Show filters
914 Total Results
Displaying 261-270 of 914
Sort by:
Attacker Value
Unknown
CVE-2023-4252
Disclosure Date: November 27, 2023 (last updated November 30, 2023)
The EventPrime WordPress plugin through 3.2.9 specifies the price of a booking in the client request, allowing an attacker to purchase bookings without payment.
0
Attacker Value
Unknown
CVE-2023-33874
Disclosure Date: November 14, 2023 (last updated February 25, 2025)
Uncontrolled search path in some Intel(R) NUC 12 Pro Kits & Mini PCs - NUC12WS Intel(R) HID Event Filter Driver installation software before version 2.2.2.1 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2023-47697
Disclosure Date: November 13, 2023 (last updated February 25, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WP Event Manager WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin <= 3.1.39 versions.
0
Attacker Value
Unknown
CVE-2023-43057
Disclosure Date: November 11, 2023 (last updated February 25, 2025)
IBM QRadar SIEM 7.5.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 267484.
0
Attacker Value
Unknown
CVE-2023-31093
Disclosure Date: November 09, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Chronosly Chronosly Events Calendar plugin <= 2.6.2 versions.
0
Attacker Value
Unknown
CVE-2023-5519
Disclosure Date: October 31, 2023 (last updated February 25, 2025)
The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks.
0
Attacker Value
Unknown
CVE-2023-5238
Disclosure Date: October 31, 2023 (last updated February 25, 2025)
The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to an HTML Injection on the plugin in the search area of the website.
0
Attacker Value
Unknown
CVE-2023-4251
Disclosure Date: October 31, 2023 (last updated February 25, 2025)
The EventPrime WordPress plugin before 3.2.0 does not have CSRF checks when creating bookings, which could allow attackers to make logged in users create unwanted bookings via CSRF attacks.
0
Attacker Value
Unknown
CVE-2023-4250
Disclosure Date: October 31, 2023 (last updated February 25, 2025)
The EventPrime WordPress plugin before 3.2.0 does not sanitise and escape some parameters before outputting them back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
0
Attacker Value
Unknown
CVE-2023-43041
Disclosure Date: October 29, 2023 (last updated February 25, 2025)
IBM QRadar SIEM 7.5 is vulnerable to information exposure allowing a delegated Admin tenant user with a specific domain security profile assigned to see data from other domains. This vulnerability is due to an incomplete fix for CVE-2022-34352. IBM X-Force ID: 266808.
0