Show filters
841 Total Results
Displaying 351-360 of 841
Sort by:
Attacker Value
Unknown
CVE-2023-33509
Disclosure Date: May 31, 2023 (last updated February 25, 2025)
KramerAV VIA GO² < 4.0.1.1326 is vulnerable to SQL Injection.
0
Attacker Value
Unknown
CVE-2023-33508
Disclosure Date: May 31, 2023 (last updated February 25, 2025)
KramerAV VIA GO² < 4.0.1.1326 is vulnerable to unauthenticated file upload resulting in Remote Code Execution (RCE).
0
Attacker Value
Unknown
CVE-2023-33507
Disclosure Date: May 31, 2023 (last updated October 08, 2023)
KramerAV VIA GO² < 4.0.1.1326 is vulnerable to Unauthenticated arbitrary file read.
0
Attacker Value
Unknown
CVE-2023-32698
Disclosure Date: May 30, 2023 (last updated February 25, 2025)
nFPM is an alternative to fpm. The file permissions on the checked-in files were not maintained. Hence, when nfpm packaged
the files (without extra config for enforcing it’s own permissions) files could go out with bad permissions (chmod 666 or 777). Anyone using nfpm for creating packages without checking/setting file permissions before packaging could result in bad permissions for files/folders.
0
Attacker Value
Unknown
CVE-2023-32691
Disclosure Date: May 30, 2023 (last updated February 25, 2025)
gost (GO Simple Tunnel) is a simple tunnel written in golang. Sensitive secrets such as passwords, token and API keys should be compared only using a constant-time comparison function. Untrusted input, sourced from a HTTP header, is compared directly with a secret. Since this comparison is not secure, an attacker can mount a side-channel timing attack to guess the password. As a workaround, this can be easily fixed using a constant time comparing function such as `crypto/subtle`'s `ConstantTimeCompare`.
0
Attacker Value
Unknown
CVE-2023-2500
Disclosure Date: May 25, 2023 (last updated February 25, 2025)
The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.3.19 via deserialization of untrusted input from the 'go_pricing' shortcode 'data' parameter. This allows authenticated attackers, with subscriber-level permissions and above, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
0
Attacker Value
Unknown
CVE-2023-2498
Disclosure Date: May 24, 2023 (last updated February 25, 2025)
The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 3.3.19 due to insufficient input sanitization and output escaping. This makes it possible for contributor-level attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2023-2496
Disclosure Date: May 24, 2023 (last updated February 25, 2025)
The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized arbitrary file uploads due to an improper capability check on the 'validate_upload' function in versions up to, and including, 3.3.19. This makes it possible for authenticated attackers with a role that the administrator previously granted access to the plugin to upload arbitrary files on the affected site's server which may make remote code execution possible.
0
Attacker Value
Unknown
CVE-2023-2494
Disclosure Date: May 24, 2023 (last updated February 25, 2025)
The Go Pricing - WordPress Responsive Pricing Tables plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'process_postdata' function in versions up to, and including, 3.3.19. This makes it possible for authenticated attackers with a role that the administrator previously granted access to the plugin to modify access to the plugin when it should only be the administrator's privilege.
0
Attacker Value
Unknown
CVE-2023-2676
Disclosure Date: May 12, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as critical, has been found in H3C R160 V1004004. Affected by this issue is some unknown functionality of the file /goForm/aspForm. The manipulation of the argument go leads to stack-based buffer overflow. The exploit has been disclosed to the public and may be used. VDB-228890 is the identifier assigned to this vulnerability.
0