Show filters
167 Total Results
Displaying 31-40 of 167
Sort by:
Attacker Value
Unknown

CVE-2023-36038

Disclosure Date: November 14, 2023 (last updated December 01, 2023)
ASP.NET Core Denial of Service Vulnerability
Attacker Value
Unknown

CVE-2023-38180

Disclosure Date: August 08, 2023 (last updated January 24, 2025)
.NET and Visual Studio Denial of Service Vulnerability
0
Attacker Value
Unknown

CVE-2023-35391

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
ASP.NET Core SignalR and Visual Studio Information Disclosure Vulnerability
Attacker Value
Unknown

CVE-2023-37287

Disclosure Date: July 10, 2023 (last updated October 08, 2023)
SmartBPM.NET has a vulnerability of using hard-coded authentication key. An unauthenticated remote attacker can exploit this vulnerability to access system with regular user privilege to read application data, and execute submission and approval processes.
Attacker Value
Unknown

CVE-2023-37288

Disclosure Date: July 10, 2023 (last updated October 08, 2023)
SmartBPM.NET component has a vulnerability of path traversal within its file download function. An unauthenticated remote attacker can exploit this vulnerability to access arbitrary system files.
Attacker Value
Unknown

CVE-2023-37286

Disclosure Date: July 10, 2023 (last updated October 08, 2023)
SmartSoft SmartBPM.NET has a vulnerability of using hard-coded machine key. An unauthenticated remote attacker can use the machine key to send serialized payload to the server to execute arbitrary code and disrupt service.
Attacker Value
Unknown

CVE-2023-33404

Disclosure Date: June 26, 2023 (last updated October 08, 2023)
An Unrestricted Upload vulnerability, due to insufficient validation on UploadControlled.cs file, in BlogEngine.Net version 3.3.8.0 and earlier allows remote attackers to execute remote code.
Attacker Value
Unknown

CVE-2023-33405

Disclosure Date: June 21, 2023 (last updated October 08, 2023)
Blogengine.net 3.3.8.0 and earlier is vulnerable to Open Redirect.
Attacker Value
Unknown

CVE-2023-22858

Disclosure Date: March 06, 2023 (last updated October 08, 2023)
An Improper Access Control vulnerability in BlogEngine.NET 3.3.8.0, allows unauthenticated visitors to access the files of unpublished blogs.
Attacker Value
Unknown

CVE-2023-22857

Disclosure Date: March 06, 2023 (last updated October 08, 2023)
A stored Cross-site Scripting (XSS) vulnerability in BlogEngine.NET 3.3.8.0, allows injection of arbitrary JavaScript in the security context of a blog visitor through an injection of a malicious payload into a blog post.