Show filters
1,840 Total Results
Displaying 271-280 of 1,840
Sort by:
Attacker Value
Unknown

CVE-2023-5261

Disclosure Date: September 29, 2023 (last updated February 25, 2025)
A vulnerability, which was classified as critical, was found in Tongda OA 2017. Affected is an unknown function of the file general/hr/manage/staff_title_evaluation/delete.php. The manipulation of the argument EVALUATION_ID leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. VDB-240870 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-32541

Disclosure Date: September 27, 2023 (last updated February 25, 2025)
A use-after-free vulnerability exists in the footerr functionality of Hancom Office 2020 HWord 11.0.0.7520. A specially crafted .doc file can lead to a use-after-free. An attacker can trick a user into opening a malformed file to trigger this vulnerability.
Attacker Value
Unknown

CVE-2023-5042

Disclosure Date: September 20, 2023 (last updated February 25, 2025)
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40713.
Attacker Value
Unknown

CVE-2023-5030

Disclosure Date: September 17, 2023 (last updated February 25, 2025)
A vulnerability has been found in Tongda OA up to 11.10 and classified as critical. This vulnerability affects unknown code of the file general/hr/recruit/plan/delete.php. The manipulation of the argument PLAN_ID leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239872.
Attacker Value
Unknown

CVE-2023-5026

Disclosure Date: September 17, 2023 (last updated February 25, 2025)
A vulnerability classified as problematic has been found in Tongda OA 11.10. Affected is an unknown function of the file /general/ipanel/menu_code.php?MENU_TYPE=FAV. The manipulation of the argument OA_SUB_WINDOW leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239868.
Attacker Value
Unknown

CVE-2023-5023

Disclosure Date: September 17, 2023 (last updated February 25, 2025)
A vulnerability was found in Tongda OA 2017 and classified as critical. Affected by this issue is some unknown functionality of the file general/hr/manage/staff_relatives/delete.php. The manipulation of the argument RELATIVES_ID leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-239864.
Attacker Value
Unknown

CVE-2023-5019

Disclosure Date: September 17, 2023 (last updated February 25, 2025)
A vulnerability classified as critical was found in Tongda OA. This vulnerability affects unknown code of the file general/hr/manage/staff_reinstatement/delete.php. The manipulation of the argument REINSTATEMENT_ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-239860.
Attacker Value
Unknown

CVE-2023-41764

Disclosure Date: September 12, 2023 (last updated February 25, 2025)
Microsoft Office Spoofing Vulnerability
Attacker Value
Unknown

CVE-2023-36767

Disclosure Date: September 12, 2023 (last updated February 25, 2025)
Microsoft Office Security Feature Bypass Vulnerability
Attacker Value
Unknown

CVE-2023-36766

Disclosure Date: September 12, 2023 (last updated February 25, 2025)
Microsoft Excel Information Disclosure Vulnerability