Show filters
1,868 Total Results
Displaying 41-50 of 1,868
Sort by:
Attacker Value
Unknown
CVE-2023-44397
Disclosure Date: October 30, 2023 (last updated November 07, 2023)
CloudExplorer Lite is an open source, lightweight cloud management platform. Prior to version 1.4.1, the gateway filter of CloudExplorer Lite uses a controller with path starting with `matching/API/`, which can cause a permission bypass. Version 1.4.1 contains a patch for this issue.
0
Attacker Value
Unknown
CVE-2023-42147
Disclosure Date: September 20, 2023 (last updated October 08, 2023)
An issue in CloudExplorer Lite 1.3.1 allows an attacker to obtain sensitive information via the login key component.
0
Attacker Value
Unknown
CVE-2021-36646
Disclosure Date: September 06, 2023 (last updated October 08, 2023)
A Cross Site Scrtpting (XSS) vulnerability in KodExplorer 4.45 allows remote attackers to run arbitrary code via /index.php page.
0
Attacker Value
Unknown
CVE-2023-35785
Disclosure Date: August 28, 2023 (last updated March 13, 2024)
Zoho ManageEngine Active Directory 360 versions 4315 and below, ADAudit Plus 7202 and below, ADManager Plus 7200 and below, Asset Explorer 6993 and below and 7xxx 7002 and below, Cloud Security Plus 4161 and below, Data Security Plus 6110 and below, Eventlog Analyzer 12301 and below, Exchange Reporter Plus 5709 and below, Log360 5315 and below, Log360 UEBA 4045 and below, M365 Manager Plus 4529 and below, M365 Security Plus 4529 and below, Recovery Manager Plus 6061 and below, ServiceDesk Plus 14204 and below and 143xx 14302 and below, ServiceDesk Plus MSP 14300 and below, SharePoint Manager Plus 4402 and below, and Support Center Plus 14300 and below are vulnerable to 2FA bypass via a few TOTP authenticators. Note: A valid pair of username and password is required to leverage this vulnerability.
0
Attacker Value
Unknown
CVE-2023-39519
Disclosure Date: August 24, 2023 (last updated October 08, 2023)
Cloud Explorer Lite is an open source cloud management platform. Prior to version 1.4.0, there is a risk of sensitive information leakage in the user information acquisition of CloudExplorer Lite. The vulnerability has been fixed in version 1.4.0.
0
Attacker Value
Unknown
CVE-2023-39910
Disclosure Date: August 09, 2023 (last updated October 08, 2023)
The cryptocurrency wallet entropy seeding mechanism used in Libbitcoin Explorer 3.0.0 through 3.6.0 is weak, aka the Milk Sad issue. The use of an mt19937 Mersenne Twister PRNG restricts the internal entropy to 32 bits regardless of settings. This allows remote attackers to recover any wallet private keys generated from "bx seed" entropy output and steal funds. (Affected users need to move funds to a secure new cryptocurrency wallet.) NOTE: the vendor's position is that there was sufficient documentation advising against "bx seed" but others disagree. NOTE: this was exploited in the wild in June and July 2023.
0
Attacker Value
Unknown
CVE-2023-38692
Disclosure Date: August 04, 2023 (last updated October 08, 2023)
CloudExplorer Lite is an open source, lightweight cloud management platform. Versions prior to 1.3.1 contain a command injection vulnerability in the installation function in module management. The vulnerability has been fixed in v1.3.1. There are no known workarounds aside from upgrading.
0
Attacker Value
Unknown
CVE-2023-3784
Disclosure Date: July 20, 2023 (last updated October 08, 2023)
A vulnerability was found in Dooblou WiFi File Explorer 1.13.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument search/order/download/mode leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235051.
0
Attacker Value
Unknown
CVE-2023-37153
Disclosure Date: July 10, 2023 (last updated October 08, 2023)
KodExplorer 4.51 contains a Cross-Site Scripting (XSS) vulnerability in the Description box of the Light App creation feature. An attacker can exploit this vulnerability by injecting XSS syntax into the Description field.
0
Attacker Value
Unknown
CVE-2023-34240
Disclosure Date: June 27, 2023 (last updated October 08, 2023)
Cloudexplorer-lite is an open source cloud software stack. Weak passwords can be easily guessed and are an easy target for brute force attacks. This can lead to an authentication system failure and compromise system security. Versions of cloudexplorer-lite prior to 1.2.0 did not enforce strong passwords. This vulnerability has been fixed in version 1.2.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.
0