Show filters
3,126 Total Results
Displaying 301-310 of 3,126
Sort by:
Attacker Value
Unknown
CVE-2023-42478
Disclosure Date: December 12, 2023 (last updated February 25, 2025)
SAP Business Objects Business Intelligence Platform is vulnerable to stored XSS allowing an attacker to upload agnostic documents in the system which when opened by any other user could lead to high impact on integrity of the application.
0
Attacker Value
Unknown
CVE-2023-42476
Disclosure Date: December 12, 2023 (last updated February 25, 2025)
SAP Business Objects Web Intelligence - version 420, allows an authenticated attacker to inject JavaScript code into Web Intelligence documents which is then executed in the victim’s browser each time the vulnerable page is visited. Successful exploitation can lead to exposure of the data that the user has access to. In the worst case, attacker could access data from reporting databases.
0
Attacker Value
Unknown
CVE-2020-36768
Disclosure Date: December 03, 2023 (last updated February 25, 2025)
A vulnerability was found in rl-institut NESP2 Initial Release/1.0. It has been classified as critical. Affected is an unknown function of the file app/database.py. The manipulation leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The patch is identified as 07c0cdf36cf6a4345086d07b54423723a496af5e. It is recommended to apply a patch to fix this issue. VDB-246642 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-5803
Disclosure Date: November 30, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Business Directory Team Business Directory Plugin – Easy Listing Directories for WordPress allows Cross-Site Request Forgery.This issue affects Business Directory Plugin – Easy Listing Directories for WordPress: from n/a through 6.3.10.
0
Attacker Value
Unknown
CVE-2023-6062
Disclosure Date: November 20, 2023 (last updated February 25, 2025)
An arbitrary file write vulnerability exists where an authenticated, remote attacker with administrator privileges on the Nessus application could alter Nessus Rules variables to overwrite arbitrary files on the remote host, which could lead to a denial of service condition.
0
Attacker Value
Unknown
CVE-2023-36437
Disclosure Date: November 14, 2023 (last updated February 25, 2025)
Azure DevOps Server Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2023-31403
Disclosure Date: November 14, 2023 (last updated February 25, 2025)
SAP Business One installation - version 10.0, does not perform proper authentication and authorization checks for SMB shared folder. As a result, any malicious user can read and write to the SMB shared folder. Additionally, the files in the folder can be executed or be used by the installation process leading to considerable impact on confidentiality, integrity and availability.
0
Attacker Value
Unknown
CVE-2023-6098
Disclosure Date: November 13, 2023 (last updated February 25, 2025)
An XSS vulnerability has been discovered in ICS Business Manager affecting version 7.06.0028.7066. A remote attacker could send a specially crafted string exploiting the obdd_act parameter, allowing the attacker to steal an authenticated user's session, and perform actions within the application.
0
Attacker Value
Unknown
CVE-2023-6097
Disclosure Date: November 13, 2023 (last updated February 25, 2025)
A SQL injection vulnerability has been found in ICS Business Manager, affecting version 7.06.0028.7089. This vulnerability could allow a remote user to send a specially crafted SQL query and retrieve all the information stored in the database. The data could also be modified or deleted, causing the application to malfunction.
0
Attacker Value
Unknown
CVE-2023-47237
Disclosure Date: November 09, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Martin Gibson Auto Publish for Google My Business plugin <= 3.7 versions.
0