Show filters
153 Total Results
Displaying 31-40 of 153
Sort by:
Attacker Value
Unknown
CVE-2024-24868
Disclosure Date: February 28, 2024 (last updated February 29, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager.This issue affects SP Project & Document Manager: from n/a through 4.69.
0
Attacker Value
Unknown
CVE-2023-49108
Disclosure Date: December 04, 2023 (last updated December 08, 2023)
Path traversal vulnerability exists in RakRak Document Plus Ver.3.2.0.0 to Ver.6.4.0.7 (excluding Ver.6.1.1.3a). If this vulnerability is exploited, arbitrary files on the server may be obtained or deleted by a user of the product with specific privileges.
0
Attacker Value
Unknown
CVE-2023-6376
Disclosure Date: November 30, 2023 (last updated December 12, 2023)
Henschen & Associates court document management software does not sufficiently randomize file names of cached documents, allowing a remote, unauthenticated attacker to access restricted documents.
0
Attacker Value
Unknown
CVE-2023-36677
Disclosure Date: November 03, 2023 (last updated November 10, 2023)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Smartypants SP Project & Document Manager allows SQL Injection.This issue affects SP Project & Document Manager: from n/a through 4.67.
0
Attacker Value
Unknown
CVE-2023-5830
Disclosure Date: October 27, 2023 (last updated November 08, 2023)
A vulnerability classified as critical has been found in ColumbiaSoft Document Locator. This affects an unknown part of the file /api/authentication/login of the component WebTools. The manipulation of the argument Server leads to improper authentication. It is possible to initiate the attack remotely. Upgrading to version 7.2 SP4 and 2021.1 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-243729 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-4034
Disclosure Date: September 05, 2023 (last updated February 25, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Digita Information Technology Smartrise Document Management System allows SQL Injection.This issue affects Smartrise Document Management System: before Hvl-2.0.
0
Attacker Value
Unknown
CVE-2023-40758
Disclosure Date: August 28, 2023 (last updated February 25, 2025)
User enumeration is found in PHPJabbers Document Creator v1.0. This issue occurs during password recovery, where a difference in messages could allow an attacker to determine if the user is valid or not, enabling a brute force attack with valid users.
0
Attacker Value
Unknown
CVE-2023-30188
Disclosure Date: August 14, 2023 (last updated February 25, 2025)
Memory Exhaustion vulnerability in ONLYOFFICE Document Server 4.0.3 through 7.3.2 allows remote attackers to cause a denial of service via crafted JavaScript file.
0
Attacker Value
Unknown
CVE-2023-30187
Disclosure Date: August 14, 2023 (last updated February 25, 2025)
An out of bounds memory access vulnerability in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
0
Attacker Value
Unknown
CVE-2023-30186
Disclosure Date: August 14, 2023 (last updated February 25, 2025)
A use after free issue discovered in ONLYOFFICE DocumentServer 4.0.3 through 7.3.2 allows remote attackers to run arbitrary code via crafted JavaScript file.
0