Show filters
1,825 Total Results
Displaying 51-60 of 1,825
Sort by:
Attacker Value
Unknown

CVE-2023-34203

Disclosure Date: June 23, 2023 (last updated February 25, 2025)
In Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM or OEE role) could perform a URL injection attack to change identity or role membership, e.g., escalate to admin. This affects OpenEdge LTS before 11.7.16, 12.x before 12.2.12, and 12.3.x through 12.6.x before 12.7.
Attacker Value
Unknown

CVE-2023-32316

Disclosure Date: May 26, 2023 (last updated February 25, 2025)
CloudExplorer Lite is an open source cloud management tool. In affected versions users can add themselves to any organization in CloudExplorer Lite. This is due to a missing permission check on the user profile. It is recommended to upgrade the version to v1.1.0. There are no known workarounds for this vulnerability.
Attacker Value
Unknown

CVE-2023-32311

Disclosure Date: May 26, 2023 (last updated February 25, 2025)
CloudExplorer Lite is an open source cloud management platform. In CloudExplorer Lite prior to version 1.1.0 users organization/workspace permissions are not properly checked. This allows users to add themselves to any organization. This vulnerability has been fixed in v1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.
Attacker Value
Unknown

CVE-2023-2845

Disclosure Date: May 23, 2023 (last updated February 25, 2025)
Improper Access Control in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0.
Attacker Value
Unknown

CVE-2023-2844

Disclosure Date: May 23, 2023 (last updated February 25, 2025)
Authorization Bypass Through User-Controlled Key in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0.
Attacker Value
Unknown

CVE-2023-25953

Disclosure Date: May 23, 2023 (last updated February 25, 2025)
Code injection vulnerability in Drive Explorer for macOS versions 3.5.4 and earlier allows an attacker who can login to the client where the affected product is installed to inject arbitrary code while processing the product execution. Since a full disk access privilege is required to execute LINE WORKS Drive Explorer, the attacker may be able to read and/or write to arbitrary files without the access privileges.
Attacker Value
Unknown

CVE-2023-29443

Disclosure Date: April 26, 2023 (last updated February 24, 2025)
Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint.
Attacker Value
Unknown

CVE-2022-4944

Disclosure Date: April 22, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, has been found in kalcaddle KodExplorer up to 4.49. Affected by this issue is some unknown functionality. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.50 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-227000.
Attacker Value
Unknown

CVE-2023-1369

Disclosure Date: March 13, 2023 (last updated February 24, 2025)
A vulnerability was found in TG Soft Vir.IT eXplorer 9.4.86.0. It has been rated as problematic. This issue affects the function 0x82730088 in the library VIRAGTLT.sys of the component IoControlCode Handler. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 9.5 is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-222875.
Attacker Value
Unknown

CVE-2023-26601

Disclosure Date: March 06, 2023 (last updated February 24, 2025)
Zoho ManageEngine ServiceDesk Plus through 14104, Asset Explorer through 6987, ServiceDesk Plus MSP before 14000, and Support Center Plus before 14000 allow Denial-of-Service (DoS).