Show filters
3,126 Total Results
Displaying 291-300 of 3,126
Sort by:
Attacker Value
Unknown

CVE-2023-4757

Disclosure Date: January 16, 2024 (last updated February 26, 2025)
The Staff / Employee Business Directory for Active Directory WordPress plugin before 1.2.3 does not sanitize and escape data returned from the LDAP server before rendering it in the page, allowing users who can control their entries in the LDAP directory to inject malicious javascript which could be used against high-privilege users such as a site admin.
Attacker Value
Unknown

CVE-2023-6339

Disclosure Date: January 02, 2024 (last updated February 25, 2025)
Google Nest WiFi Pro root code-execution & user-data compromise
Attacker Value
Unknown

CVE-2023-48419

Disclosure Date: January 02, 2024 (last updated February 25, 2025)
An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege 
Attacker Value
Unknown

CVE-2023-51431

Disclosure Date: December 29, 2023 (last updated January 06, 2024)
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.
Attacker Value
Unknown

CVE-2023-51006

Disclosure Date: December 28, 2023 (last updated January 06, 2024)
An issue in the openFile method of Chinese Perpetual Calendar v9.0.0 allows attackers to read any file via unspecified vectors.
Attacker Value
Unknown

CVE-2023-49772

Disclosure Date: December 20, 2023 (last updated February 25, 2025)
Deserialization of Untrusted Data vulnerability in Phpbits Creative Studio Genesis Simple Love.This issue affects Genesis Simple Love: from n/a through 2.0.
Attacker Value
Unknown

CVE-2023-48781

Disclosure Date: December 18, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Marketing Rapel MkRapel Regiones y Ciudades de Chile para WC.This issue affects MkRapel Regiones y Ciudades de Chile para WC: from n/a through 4.3.0.
Attacker Value
Unknown

CVE-2023-40691

Disclosure Date: December 18, 2023 (last updated February 25, 2025)
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 may reveal sensitive information contained in application configuration to developer and administrator users. IBM X-Force ID: 264805.
Attacker Value
Unknown

CVE-2023-49182

Disclosure Date: December 15, 2023 (last updated February 25, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fabio Marzocca List all posts by Authors, nested Categories and Titles allows Reflected XSS.This issue affects List all posts by Authors, nested Categories and Titles: from n/a through 2.7.10.
Attacker Value
Unknown

CVE-2023-49195

Disclosure Date: December 14, 2023 (last updated February 25, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kyle Phillips Nested Pages allows Stored XSS.This issue affects Nested Pages: from n/a through 3.2.6.