Show filters
1,840 Total Results
Displaying 321-330 of 1,840
Sort by:
Attacker Value
Unknown

CVE-2023-1183

Disclosure Date: July 10, 2023 (last updated February 25, 2025)
A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.
Attacker Value
Unknown

CVE-2021-30205

Disclosure Date: June 27, 2023 (last updated February 25, 2025)
Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1_SC_UTF8 allows unauthenticated attackers to browse departments and usernames.
Attacker Value
Unknown

CVE-2021-30203

Disclosure Date: June 27, 2023 (last updated February 25, 2025)
A reflected cross-site scripting (XSS) vulnerability in the zero parameter of dzzoffice 2.02.1_SC_UTF8 allows attackers to execute arbitrary web scripts or HTML.
Attacker Value
Unknown

CVE-2023-34939

Disclosure Date: June 22, 2023 (last updated February 25, 2025)
Onlyoffice Community Server before v12.5.2 was discovered to contain a remote code execution (RCE) vulnerability via the component UploadProgress.ashx.
Attacker Value
Unknown

CVE-2023-28295

Disclosure Date: June 17, 2023 (last updated February 25, 2025)
Microsoft Publisher Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2023-28287

Disclosure Date: June 17, 2023 (last updated February 25, 2025)
Microsoft Publisher Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2023-33146

Disclosure Date: June 14, 2023 (last updated February 25, 2025)
Microsoft Office Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2023-33133

Disclosure Date: June 14, 2023 (last updated February 25, 2025)
Microsoft Excel Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2023-32029

Disclosure Date: June 14, 2023 (last updated February 25, 2025)
Microsoft Excel Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2023-32548

Disclosure Date: June 13, 2023 (last updated February 25, 2025)
OS command injection vulnerability exists in WPS Office version 10.8.0.6186. If a remote attacker who can conduct a man-in-the-middle attack connects the product to a malicious server and sends a specially crafted data, an arbitrary OS command may be executed on the system where the product is installed.