Show filters
77 Total Results
Displaying 31-40 of 77
Sort by:
Attacker Value
Unknown
CVE-2023-29986
Disclosure Date: May 11, 2023 (last updated October 08, 2023)
spring-boot-actuator-logview 0.2.13 allows Directory Traversal to sibling directories via LogViewEndpoint.view.
0
Attacker Value
Unknown
CVE-2020-36620
Disclosure Date: December 21, 2022 (last updated February 24, 2025)
A vulnerability was found in Brondahl EnumStringValues up to 4.0.0. It has been declared as problematic. This vulnerability affects the function GetStringValuesWithPreferences_Uncache of the file EnumStringValues/EnumExtensions.cs. The manipulation leads to resource consumption. Upgrading to version 4.0.1 is able to address this issue. The name of the patch is c0fc7806beb24883cc2f9543ebc50c0820297307. It is recommended to upgrade the affected component. VDB-216466 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2022-40206
Disclosure Date: November 26, 2022 (last updated February 24, 2025)
Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subscriber or higher user roles to mark any forum post as private/public.
0
Attacker Value
Unknown
CVE-2022-40192
Disclosure Date: November 17, 2022 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
0
Attacker Value
Unknown
CVE-2022-3979
Disclosure Date: November 13, 2022 (last updated February 24, 2025)
A vulnerability was found in NagVis up to 1.9.33 and classified as problematic. This issue affects the function checkAuthCookie of the file share/server/core/classes/CoreLogonMultisite.php. The manipulation of the argument hash leads to incorrect type conversion. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. Upgrading to version 1.9.34 is able to address this issue. The identifier of the patch is 7574fd8a2903282c2e0d1feef5c4876763db21d5. It is recommended to upgrade the affected component. The identifier VDB-213557 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2022-40200
Disclosure Date: November 09, 2022 (last updated February 24, 2025)
Auth. (subscriber+) Arbitrary File Upload vulnerability in wpForo Forum plugin <= 2.0.9 on WordPress.
0
Attacker Value
Unknown
CVE-2022-43492
Disclosure Date: October 28, 2022 (last updated February 24, 2025)
Auth. (subscriber+) Insecure Direct Object References (IDOR) vulnerability in Comments – wpDiscuz plugin 7.4.2 on WordPress.
0
Attacker Value
Unknown
CVE-2022-2628
Disclosure Date: October 03, 2022 (last updated February 24, 2025)
The DSGVO All in one for WP WordPress plugin before 4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2022-40632
Disclosure Date: September 26, 2022 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in gVectors Team wpForo Forum plugin <= 2.0.5 on WordPress leading to topic deletion.
0
Attacker Value
Unknown
CVE-2022-40205
Disclosure Date: September 26, 2022 (last updated February 24, 2025)
Insecure direct object references (IDOR) vulnerability in the wpForo Forum plugin <= 2.0.5 on WordPress allows attackers with subscriber or higher user roles to mark any forum post as solved/unsolved.
0