Show filters
914 Total Results
Displaying 301-310 of 914
Sort by:
Attacker Value
Unknown

CVE-2023-26273

Disclosure Date: June 27, 2023 (last updated February 25, 2025)
IBM QRadar SIEM 7.5.0 could allow an authenticated user to perform unauthorized actions due to hazardous input validation. IBM X-Force ID: 248134.
Attacker Value
Unknown

CVE-2022-34352

Disclosure Date: June 27, 2023 (last updated February 25, 2025)
IBM QRadar SIEM 7.5.0 is vulnerable to information exposure allowing a delegated Admin tenant user with a specific domain security profile assigned to see data from other domains. IBM X-Force ID: 230403.
Attacker Value
Unknown

CVE-2023-35884

Disclosure Date: June 20, 2023 (last updated February 25, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in EventPrime plugin <= 3.0.5 versions.
Attacker Value
Unknown

CVE-2023-31411

Disclosure Date: June 19, 2023 (last updated February 25, 2025)
A remote unprivileged attacker can modify and access configuration settings on the EventCam App due to the absence of API authentication. The lack of authentication in the API allows the attacker to potentially compromise the functionality of the EventCam App.
Attacker Value
Unknown

CVE-2023-31410

Disclosure Date: June 19, 2023 (last updated February 25, 2025)
A remote unprivileged attacker can intercept the communication via e.g. Man-In-The-Middle, due to the absence of Transport Layer Security (TLS) in the SICK EventCam App. This lack of encryption in the communication channel can lead to the unauthorized disclosure of sensitive information. The attacker can exploit this weakness to eavesdrop on the communication between the EventCam App and the Client, and potentially manipulate the data being transmitted.
Attacker Value
Unknown

CVE-2022-4950

Disclosure Date: June 07, 2023 (last updated February 25, 2025)
Several WordPress plugins developed by Cool Plugins are vulnerable to arbitrary plugin installation and activation that can lead to remote code execution by authenticated attackers with minimal permissions, such as a subscriber.
Attacker Value
Unknown

CVE-2023-2407

Disclosure Date: June 03, 2023 (last updated February 25, 2025)
The Event Registration Calendar By vcita plugin, versions up to and including 3.9.1, and Online Payments – Get Paid with PayPal, Square & Stripe plugin, for WordPress are vulnerable to Cross-Site Request Forgery. This is due to missing nonce validation in the ls_parse_vcita_callback() function. This makes it possible for unauthenticated attackers to modify the plugin's settings and inject malicious JavaScript via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2023-2406

Disclosure Date: June 03, 2023 (last updated February 25, 2025)
The Event Registration Calendar By vcita plugin, versions up to and including 3.9.1, and Online Payments – Get Paid with PayPal, Square & Stripe plugin, for WordPress are vulnerable to Stored Cross-Site Scripting via the 'email' parameter in versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with the edit_posts capability, such as contributors and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2023-33326

Disclosure Date: May 28, 2023 (last updated February 25, 2025)
Unauth. Reflected (XSS) Cross-Site Scripting (XSS) vulnerability in EventPrime plugin <= 2.8.6 versions.
Attacker Value
Unknown

CVE-2022-47164

Disclosure Date: May 25, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in MagePeople Team Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 3.7.7 versions.