Show filters
3,126 Total Results
Displaying 321-330 of 3,126
Sort by:
Attacker Value
Unknown
CVE-2023-22076
Disclosure Date: October 17, 2023 (last updated October 24, 2023)
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data as well as unauthorized read access to a subset of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
0
Attacker Value
Unknown
CVE-2023-35024
Disclosure Date: October 14, 2023 (last updated February 25, 2025)
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 258349.
0
Attacker Value
Unknown
CVE-2023-41763
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
Skype for Business Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2023-36789
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
Skype for Business Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2023-36786
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
Skype for Business Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2023-36780
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
Skype for Business Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2023-42474
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
SAP BusinessObjects Web Intelligence - version 420, has a URL with parameter that could be vulnerable to XSS attack. The attacker could send a malicious link to a user that would possibly allow an attacker to retrieve the sensitive information.
0
Attacker Value
Unknown
CVE-2023-41365
Disclosure Date: October 10, 2023 (last updated February 25, 2025)
SAP Business One (B1i) - version 10.0, allows an authorized attacker to retrieve the details stack trace of the fault message to conduct the XXE injection, which will lead to information disclosure. After successful exploitation, an attacker can cause limited impact on the confidentiality and no impact to the integrity and availability.
0
Attacker Value
Unknown
CVE-2023-20268
Disclosure Date: September 27, 2023 (last updated February 25, 2025)
A vulnerability in the packet processing functionality of Cisco access point (AP) software could allow an unauthenticated, adjacent attacker to exhaust resources on an affected device.
This vulnerability is due to insufficient management of resources when handling certain types of traffic. An attacker could exploit this vulnerability by sending a series of specific wireless packets to an affected device. A successful exploit could allow the attacker to consume resources on an affected device. A sustained attack could lead to the disruption of the Control and Provisioning of Wireless Access Points (CAPWAP) tunnel and intermittent loss of wireless client traffic.
0
Attacker Value
Unknown
CVE-2023-4505
Disclosure Date: September 27, 2023 (last updated October 08, 2023)
The Staff / Employee Business Directory for Active Directory plugin for WordPress is vulnerable to LDAP Passback in versions up to, and including, 1.2.3. This is due to insufficient validation when changing the LDAP server. This makes it possible for authenticated attackers, with administrative access and above, to change the LDAP server and retrieve the credentials for the original LDAP server.
0