Show filters
400 Total Results
Displaying 31-40 of 400
Sort by:
Attacker Value
Unknown

CVE-2023-7074

Disclosure Date: January 29, 2024 (last updated February 03, 2024)
The WP SOCIAL BOOKMARK MENU WordPress plugin through 1.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
Attacker Value
Unknown

CVE-2023-47033

Disclosure Date: January 19, 2024 (last updated January 31, 2024)
MultiSigWallet 0xF0C99 was discovered to contain a reentrancy vulnerability via the function executeTransaction.
Attacker Value
Unknown

CVE-2024-0405

Disclosure Date: January 17, 2024 (last updated January 25, 2024)
The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin, version 1.5.3, is vulnerable to Post-Authenticated SQL Injection via multiple JSON parameters in the /wp-json/burst/v1/data/compare endpoint. Affected parameters include 'browser', 'device', 'page_id', 'page_url', 'platform', and 'referrer'. This vulnerability arises due to insufficient escaping of user-supplied parameters and the lack of adequate preparation in SQL queries. As a result, authenticated attackers with editor access or higher can append additional SQL queries into existing ones, potentially leading to unauthorized access to sensitive information from the database.
Attacker Value
Unknown

CVE-2023-49000

Disclosure Date: December 27, 2023 (last updated September 21, 2024)
An issue in ArtistScope ArtisBrowser v.34.1.5 and before allows an attacker to bypass intended access restrictions via interaction with the com.artis.browser.IntentReceiverActivity component. NOTE: this is disputed by the vendor, who indicates that ArtisBrowser 34 does not support CSS3.
Attacker Value
Unknown

CVE-2023-48390

Disclosure Date: December 15, 2023 (last updated December 23, 2023)
Multisuns EasyLog web+ has a code injection vulnerability. An unauthenticated remote attacker can exploit this vulnerability to inject code and access the system to perform arbitrary system operations or disrupt service.
Attacker Value
Unknown

CVE-2023-48389

Disclosure Date: December 15, 2023 (last updated December 23, 2023)
Multisuns EasyLog web+ has a path traversal vulnerability within its parameter in a specific URL. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and download arbitrary system files.
Attacker Value
Unknown

CVE-2023-48388

Disclosure Date: December 15, 2023 (last updated December 23, 2023)
Multisuns EasyLog web+ has a vulnerability of using hard-coded credentials. An remote attacker can exploit this vulnerability to access the system to perform arbitrary system operations or disrupt service.
Attacker Value
Unknown

CVE-2023-49802

Disclosure Date: December 11, 2023 (last updated December 15, 2023)
The LinkedCustomFields plugin for MantisBT allows users to link values between two custom fields, creating linked drop-downs. Prior to version 2.0.1, cross-site scripting in the MantisBT LinkedCustomFields plugin allows Javascript execution, when a crafted Custom Field is linked via the plugin and displayed when reporting a new Issue or editing an existing one. This issue is fixed in version 2.0.1. As a workaround, one may utilize MantisBT's default Content Security Policy, which blocks script execution.
Attacker Value
Unknown

CVE-2023-5761

Disclosure Date: December 07, 2023 (last updated December 13, 2023)
The Burst Statistics – Privacy-Friendly Analytics for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'url' parameter in versions 1.4.0 to 1.4.6.1 (free) and versions 1.4.0 to 1.5.0 (pro) due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Attacker Value
Unknown

CVE-2023-27611

Disclosure Date: November 12, 2023 (last updated November 18, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in audrasjb Reusable Blocks Extended plugin <= 0.9 versions.