Show filters
1,868 Total Results
Displaying 51-60 of 1,868
Sort by:
Attacker Value
Unknown
CVE-2023-2795
Disclosure Date: June 27, 2023 (last updated October 08, 2023)
The CodeColorer WordPress plugin before 0.10.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2023-3423
Disclosure Date: June 27, 2023 (last updated October 08, 2023)
Weak Password Requirements in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v 1.2.0.
0
Attacker Value
Unknown
CVE-2023-34203
Disclosure Date: June 23, 2023 (last updated October 08, 2023)
In Progress OpenEdge OEM (OpenEdge Management) and OEE (OpenEdge Explorer) before 12.7, a remote user (who has any OEM or OEE role) could perform a URL injection attack to change identity or role membership, e.g., escalate to admin. This affects OpenEdge LTS before 11.7.16, 12.x before 12.2.12, and 12.3.x through 12.6.x before 12.7.
0
Attacker Value
Unknown
CVE-2023-32316
Disclosure Date: May 26, 2023 (last updated October 08, 2023)
CloudExplorer Lite is an open source cloud management tool. In affected versions users can add themselves to any organization in CloudExplorer Lite. This is due to a missing permission check on the user profile. It is recommended to upgrade the version to v1.1.0. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2023-32311
Disclosure Date: May 26, 2023 (last updated October 08, 2023)
CloudExplorer Lite is an open source cloud management platform. In CloudExplorer Lite prior to version 1.1.0 users organization/workspace permissions are not properly checked. This allows users to add themselves to any organization. This vulnerability has been fixed in v1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.
0
Attacker Value
Unknown
CVE-2023-2845
Disclosure Date: May 23, 2023 (last updated October 08, 2023)
Improper Access Control in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0.
0
Attacker Value
Unknown
CVE-2023-2844
Disclosure Date: May 23, 2023 (last updated October 08, 2023)
Authorization Bypass Through User-Controlled Key in GitHub repository cloudexplorer-dev/cloudexplorer-lite prior to v1.1.0.
0
Attacker Value
Unknown
CVE-2023-25953
Disclosure Date: May 23, 2023 (last updated October 08, 2023)
Code injection vulnerability in Drive Explorer for macOS versions 3.5.4 and earlier allows an attacker who can login to the client where the affected product is installed to inject arbitrary code while processing the product execution. Since a full disk access privilege is required to execute LINE WORKS Drive Explorer, the attacker may be able to read and/or write to arbitrary files without the access privileges.
0
Attacker Value
Unknown
CVE-2023-29657
Disclosure Date: May 12, 2023 (last updated October 08, 2023)
eXtplorer 2.1.15 is vulnerable to Insecure Permissions. File upload in file manager allows uploading zip file containing php pages with arbitrary code executions.
0
Attacker Value
Unknown
CVE-2023-29443
Disclosure Date: April 26, 2023 (last updated October 08, 2023)
Zoho ManageEngine ServiceDesk Plus before 14105, ServiceDesk Plus MSP before 14200, SupportCenter Plus before 14200, and AssetExplorer before 6989 allow SDAdmin attackers to conduct XXE attacks via a crafted server that sends malformed XML from a Reports integration API endpoint.
0