Show filters
1,431 Total Results
Displaying 291-300 of 1,431
Sort by:
Attacker Value
Unknown

CVE-2022-4118

Disclosure Date: May 08, 2023 (last updated February 24, 2025)
The Bitcoin / AltCoin Payment Gateway for WooCommerce & Multivendor store / shop WordPress plugin through 1.7.1 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by authenticated users
Attacker Value
Unknown

CVE-2023-30243

Disclosure Date: May 05, 2023 (last updated February 24, 2025)
Beijing Netcon NS-ASG Application Security Gateway v6.3 is vulnerable to SQL Injection via TunnelId that allows access to sensitive information.
Attacker Value
Unknown

CVE-2023-30242

Disclosure Date: May 05, 2023 (last updated February 24, 2025)
NS-ASG v6.3 was discovered to contain a SQL injection vulnerability via the component /admin/add_ikev2.php.
Attacker Value
Unknown

CVE-2023-29163

Disclosure Date: May 03, 2023 (last updated February 24, 2025)
When UDP profile with idle timeout set to immediate or the value 0 is configured on a virtual server, undisclosed traffic can cause TMM to terminate.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Attacker Value
Unknown

CVE-2023-28406

Disclosure Date: May 03, 2023 (last updated February 24, 2025)
A directory traversal vulnerability exists in an undisclosed page of the BIG-IP Configuration utility which may allow an authenticated attacker to read files with .xml extension. Access to restricted information is limited and the attacker does not control what information is obtained.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Attacker Value
Unknown

CVE-2023-27378

Disclosure Date: May 03, 2023 (last updated February 24, 2025)
Multiple reflected cross-site scripting (XSS) vulnerabilities exist in undisclosed pages of the BIG-IP Configuration utility which allow an attacker to run JavaScript in the context of the currently logged-in user.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Attacker Value
Unknown

CVE-2023-24594

Disclosure Date: May 03, 2023 (last updated February 24, 2025)
When an SSL profile is configured on a Virtual Server, undisclosed traffic can cause an increase in CPU or SSL accelerator resource utilization.   Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Attacker Value
Unknown

CVE-2023-29410

Disclosure Date: April 18, 2023 (last updated February 24, 2025)
A CWE-20: Improper Input Validation vulnerability exists that could allow an authenticated attacker to gain the same privilege as the application on the server when a malicious payload is provided over HTTP for the server to execute.
Attacker Value
Unknown

CVE-2023-1580

Disclosure Date: April 02, 2023 (last updated February 24, 2025)
Uncontrolled resource consumption in the logging feature in Devolutions Gateway 2023.1.1 and earlier allows an attacker to cause a denial of service by filling up the disk and render the system unusable.
Attacker Value
Unknown

CVE-2022-2848

Disclosure Date: March 29, 2023 (last updated February 24, 2025)
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-16486.