Show filters
171 Total Results
Displaying 31-40 of 171
Sort by:
Attacker Value
Unknown

CVE-2023-2992

Disclosure Date: June 26, 2023 (last updated September 16, 2024)
An unauthenticated  denial of service vulnerability exists in the SMM v1, SMM v2, and FPC management web server which can be triggered under crafted conditions. Rebooting SMM or FPC will restore access to the management web server.
Attacker Value
Unknown

CVE-2023-2180

Disclosure Date: May 15, 2023 (last updated October 08, 2023)
The KIWIZ Invoices Certification & PDF System WordPress plugin through 2.1.3 does not validate the path of files to be downloaded, which could allow unauthenticated attacker to read/downlaod arbitrary files, as well as perform PHAR unserialization (assuming they can upload a file on the server)
Attacker Value
Unknown

CVE-2023-1566

Disclosure Date: March 22, 2023 (last updated October 08, 2023)
A vulnerability was found in SourceCodester Medical Certificate Generator App 1.0. It has been declared as critical. This vulnerability affects unknown code of the file action.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-223558 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-26284

Disclosure Date: March 15, 2023 (last updated November 08, 2023)
IBM MQ Certified Container 9.3.0.1 through 9.3.0.3 and 9.3.1.0 through 9.3.1.1 could allow authenticated users with the cluster to be granted administration access to the MQ console due to improper access controls. IBM X-Force ID: 248417.
Attacker Value
Unknown

CVE-2022-43874

Disclosure Date: March 15, 2023 (last updated November 08, 2023)
IBM App Connect Enterprise Certified Container 4.1, 4.2, 5.0, 5.1, 5.2, 6.0, 6.1, 6.2, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 239963.
Attacker Value
Unknown

CVE-2023-1006

Disclosure Date: February 24, 2023 (last updated October 08, 2023)
A vulnerability was found in SourceCodester Medical Certificate Generator App 1.0. It has been classified as problematic. This affects an unknown part of the component New Record Handler. The manipulation of the argument Firstname/Middlename/Lastname/Suffix/Nationality/Doctor Fullname/Doctor Suffix with the input "><script>prompt(1)</script> leads to cross site scripting. It is possible to initiate the attack remotely. The associated identifier of this vulnerability is VDB-221739.
Attacker Value
Unknown

CVE-2023-0774

Disclosure Date: February 10, 2023 (last updated October 08, 2023)
A vulnerability has been found in SourceCodester Medical Certificate Generator App 1.0 and classified as critical. This vulnerability affects unknown code of the file action.php. The manipulation of the argument lastname leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-220558 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-0707

Disclosure Date: February 07, 2023 (last updated October 08, 2023)
A vulnerability was found in SourceCodester Medical Certificate Generator App 1.0. It has been rated as critical. Affected by this issue is the function delete_record of the file function.php. The manipulation of the argument id leads to sql injection. VDB-220346 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-0706

Disclosure Date: February 07, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as critical, has been found in SourceCodester Medical Certificate Generator App 1.0. Affected by this issue is some unknown functionality of the file manage_record.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The identifier of this vulnerability is VDB-220340.
Attacker Value
Unknown

CVE-2022-42439

Disclosure Date: February 06, 2023 (last updated November 08, 2023)
IBM App Connect Enterprise 11.0.0.17 through 11.0.0.19 and 12.0.4.0 and 12.0.5.0 contains an unspecified vulnerability in the Discovery Connector nodes which may cause a 3rd party system’s credentials to be exposed to a privileged attacker. IBM X-Force ID: 238211.