Show filters
234 Total Results
Displaying 31-40 of 234
Sort by:
Attacker Value
Unknown
CVE-2023-37656
Disclosure Date: July 11, 2023 (last updated October 08, 2023)
WebsiteGuide v0.2 is vulnerable to Remote Command Execution (RCE) via image upload.
0
Attacker Value
Unknown
CVE-2023-1864
Disclosure Date: June 07, 2023 (last updated October 08, 2023)
FANUC ROBOGUIDE-HandlingPRO Versions 9 Rev.ZD and prior is vulnerable to
a path traversal, which could allow an attacker to remotely read files
on the system running the affected software.
0
Attacker Value
Unknown
CVE-2023-32113
Disclosure Date: May 09, 2023 (last updated April 01, 2024)
SAP GUI for Windows - version 7.70, 8.0, allows an unauthorized attacker to gain NTLM authentication information of a victim by tricking it into clicking a prepared shortcut file. Depending on the authorizations of the victim, the attacker can read and modify potentially sensitive information after successful exploitation.
0
Attacker Value
Unknown
CVE-2023-0420
Disclosure Date: April 24, 2023 (last updated October 08, 2023)
The Custom Post Type and Taxonomy GUI Manager WordPress plugin through 1.1 does not have CSRF, and is lacking sanitising as well as escaping in some parameters, allowing attackers to make a logged in admin put Stored Cross-Site Scripting payloads via CSRF
0
Attacker Value
Unknown
CVE-2023-26922
Disclosure Date: March 08, 2023 (last updated October 08, 2023)
SQL injection vulnerability found in Varisicte matrix-gui v.2 allows a remote attacker to execute arbitrary code via the shell_exect parameter to the \www\pages\matrix-gui-2.0 endpoint.
0
Attacker Value
Unknown
CVE-2023-26235
Disclosure Date: February 21, 2023 (last updated October 08, 2023)
JD-GUI 1.6.6 allows XSS via util/net/InterProcessCommunicationUtil.java.
0
Attacker Value
Unknown
CVE-2023-26234
Disclosure Date: February 21, 2023 (last updated October 08, 2023)
JD-GUI 1.6.6 allows deserialization via UIMainWindowPreferencesProvider.singleInstance.
0
Attacker Value
Unknown
CVE-2015-10059
Disclosure Date: January 17, 2023 (last updated October 08, 2023)
A vulnerability has been found in s134328 Webapplication-Veganguide and classified as problematic. This vulnerability affects unknown code of the file p05-integration/app/shared/api/apiService.js. The manipulation of the argument country/city leads to cross site scripting. The attack can be initiated remotely. The name of the patch is 2aa760fa4e779e40a28206a32ac22ac10356f519. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-218416.
0
Attacker Value
Unknown
CVE-2022-3609
Disclosure Date: December 12, 2022 (last updated October 08, 2023)
The GetYourGuide Ticketing WordPress plugin before 1.0.4 does not sanitise and escape some parameters, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2022-43264
Disclosure Date: November 16, 2022 (last updated December 22, 2024)
Arobas Music Guitar Pro for iPad and iPhone before v1.10.2 allows attackers to perform directory traversal and download arbitrary files via a crafted web request.
0