Show filters
1,431 Total Results
Displaying 281-290 of 1,431
Sort by:
Attacker Value
Unknown

CVE-2023-29713

Disclosure Date: June 09, 2023 (last updated February 25, 2025)
Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via a crafted payload to the GET request after the /css/ directory.
Attacker Value
Unknown

CVE-2023-29712

Disclosure Date: June 09, 2023 (last updated February 25, 2025)
Cross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via a crafted payload to the X-Rewrite-URL parameter.
Attacker Value
Unknown

CVE-2023-2187

Disclosure Date: June 07, 2023 (last updated February 25, 2025)
On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WebMonitor.An unauthenticated user can use this vulnerability to forcefully log out of any currently logged-in user by sending a "password change event". Furthermore, an attacker could use this vulnerability to spam the logged-in user with false events.
Attacker Value
Unknown

CVE-2023-2186

Disclosure Date: June 07, 2023 (last updated February 25, 2025)
On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send a specially crafted broadcast message including format string characters to the SCADA Data Gateway to perform unrestricted memory reads.An unauthenticated user can use this format string vulnerability to repeatedly crash the GTWWebMonitor.exe process to DoS the Web Monitor. Furthermore, an authenticated user can leverage this vulnerability to leak memory from the GTWWebMonitor.exe process. This could be leveraged in an exploit chain to gain code execution.
Attacker Value
Unknown

CVE-2023-28043

Disclosure Date: June 01, 2023 (last updated February 25, 2025)
Dell SCG 5.14 contains an information disclosure vulnerability during the SRS to SCG upgrade path. A remote low privileged malicious user could potentially exploit this vulnerability to retrieve the plain text.
Attacker Value
Unknown

CVE-2023-23955

Disclosure Date: June 01, 2023 (last updated February 25, 2025)
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Server-Side Request Forgery vulnerability.
Attacker Value
Unknown

CVE-2023-23954

Disclosure Date: June 01, 2023 (last updated February 25, 2025)
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Stored Cross-Site Scripting vulnerability.
Attacker Value
Unknown

CVE-2023-23953

Disclosure Date: June 01, 2023 (last updated October 08, 2023)
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to an Elevation of Privilege vulnerability.
Attacker Value
Unknown

CVE-2023-23952

Disclosure Date: June 01, 2023 (last updated February 25, 2025)
Advanced Secure Gateway and Content Analysis, prior to 7.3.13.1 / 3.1.6.0, may be susceptible to a Command Injection vulnerability.
Attacker Value
Unknown

CVE-2022-46822

Disclosure Date: May 09, 2023 (last updated February 24, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in JC Development Team WooCommerce JazzCash Gateway Plugin plugin <= 2.0 versions.