Show filters
69 Total Results
Displaying 31-40 of 69
Sort by:
Attacker Value
Unknown
CVE-2023-43119
Disclosure Date: October 16, 2023 (last updated October 28, 2023)
An Access Control issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, also fixed in 22.7, 31.7.2 allows attackers to gain escalated privileges using crafted telnet commands via Redis server.
0
Attacker Value
Unknown
CVE-2023-43118
Disclosure Date: October 16, 2023 (last updated October 28, 2023)
Cross Site Request Forgery (CSRF) vulnerability in Chalet application in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, fixed in 31.7.2 and 32.5.1.5 allows attackers to run arbitrary code and cause other unspecified impacts via /jsonrpc API.
0
Attacker Value
Unknown
CVE-2023-43120
Disclosure Date: October 16, 2023 (last updated October 25, 2023)
An issue discovered in Extreme Networks Switch Engine (EXOS) before 32.5.1.5, before 22.7 and before 31.7.1 allows attackers to gain escalated privileges via crafted HTTP request.
0
Attacker Value
Unknown
CVE-2023-39584
Disclosure Date: September 08, 2023 (last updated October 08, 2023)
Hexo up to v7.0.0 (RC2) was discovered to contain an arbitrary file read vulnerability.
0
Attacker Value
Unknown
CVE-2023-3055
Disclosure Date: June 03, 2023 (last updated October 08, 2023)
The Page Builder by AZEXO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.27.133. This is due to missing or incorrect nonce validation on the 'azh_save' function. This makes it possible for unauthenticated attackers to update the post content and inject malicious JavaScript via a forged request, granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2023-3053
Disclosure Date: June 03, 2023 (last updated October 08, 2023)
The Page Builder by AZEXO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'azh_add_post' function in versions up to, and including, 1.27.133. This makes it possible for authenticated attackers to create a post with any post type and post status.
0
Attacker Value
Unknown
CVE-2023-3052
Disclosure Date: June 03, 2023 (last updated October 08, 2023)
The Page Builder by AZEXO plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.27.133. This is due to missing or incorrect nonce validation on the 'azh_add_post', 'azh_duplicate_post', 'azh_update_post' and 'azh_remove_post' functions. This makes it possible for unauthenticated attackers to create, modify, and delete a post via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2023-3051
Disclosure Date: June 03, 2023 (last updated October 08, 2023)
The Page Builder by AZEXO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'azh_post' shortcode in versions up to, and including, 1.27.133 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2022-38792
Disclosure Date: August 27, 2022 (last updated October 08, 2023)
The exotel (aka exotel-py) package in PyPI as of 0.1.6 includes a code execution backdoor inserted by a third party.
0
Attacker Value
Unknown
CVE-2022-32278
Disclosure Date: June 13, 2022 (last updated October 07, 2023)
XFCE 4.16 allows attackers to execute arbitrary code because xdg-open can execute a .desktop file on an attacker-controlled FTP server.
0