Show filters
400 Total Results
Displaying 51-60 of 400
Sort by:
Attacker Value
Unknown

CVE-2023-43643

Disclosure Date: October 09, 2023 (last updated October 14, 2023)
AntiSamy is a library for performing fast, configurable cleansing of HTML coming from untrusted sources. Prior to version 1.7.4, there is a potential for a mutation XSS (mXSS) vulnerability in AntiSamy caused by flawed parsing of the HTML being sanitized. To be subject to this vulnerability the `preserveComments` directive must be enabled in your policy file and also allow for certain tags at the same time. As a result, certain crafty inputs can result in elements in comment tags being interpreted as executable when using AntiSamy's sanitized output. This issue has been patched in AntiSamy 1.7.4 and later.
Attacker Value
Unknown

CVE-2023-44860

Disclosure Date: October 06, 2023 (last updated October 12, 2023)
An issue in NETIS SYSTEMS N3Mv2 v.1.0.1.865 allows a remote attacker to cause a denial of service via the authorization component in the HTTP request.
Attacker Value
Unknown

CVE-2023-43893

Disclosure Date: October 02, 2023 (last updated October 09, 2023)
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the wakeup_mac parameter in the Wake-On-LAN (WoL) function. This vulnerability is exploited via a crafted payload.
Attacker Value
Unknown

CVE-2023-43892

Disclosure Date: October 02, 2023 (last updated October 09, 2023)
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the Hostname parameter within the WAN settings. This vulnerability is exploited via a crafted payload.
Attacker Value
Unknown

CVE-2023-43891

Disclosure Date: October 02, 2023 (last updated October 09, 2023)
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the Changing Username and Password function. This vulnerability is exploited via a crafted payload.
Attacker Value
Unknown

CVE-2023-43890

Disclosure Date: October 02, 2023 (last updated October 09, 2023)
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the diagnostic tools page. This vulnerability is exploited via a crafted HTTP request.
Attacker Value
Unknown

CVE-2023-43134

Disclosure Date: September 20, 2023 (last updated October 08, 2023)
There is an unauthorized access vulnerability in Netis 360RAC1200 v1.3.4517, which allows attackers to obtain sensitive information of the device without authentication, obtain user tokens, and ultimately log in to the device backend management.
Attacker Value
Unknown

CVE-2023-5062

Disclosure Date: September 20, 2023 (last updated October 08, 2023)
The WordPress Charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wp_charts' shortcode in versions up to, and including, 0.7.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2023-42336

Disclosure Date: September 16, 2023 (last updated October 08, 2023)
An issue in NETIS SYSTEMS WF2409Ev4 v.1.0.1.705 allows a remote attacker to execute arbitrary code and obtain sensitive information via the password parameter in the /etc/shadow.sample component.
Attacker Value
Unknown

CVE-2023-38829

Disclosure Date: September 11, 2023 (last updated October 08, 2023)
An issue in NETIS SYSTEMS WF2409E v.3.6.42541 allows a remote attacker to execute arbitrary code via the ping and traceroute functions of the diagnostic tools component in the admin management interface.