Show filters
191 Total Results
Displaying 71-80 of 191
Sort by:
Attacker Value
Unknown
CVE-2023-6618
Disclosure Date: December 08, 2023 (last updated February 25, 2025)
A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file index.php. The manipulation of the argument page leads to file inclusion. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-247255.
0
Attacker Value
Unknown
CVE-2023-6617
Disclosure Date: December 08, 2023 (last updated February 25, 2025)
A vulnerability was found in SourceCodester Simple Student Attendance System 1.0. It has been classified as critical. Affected is an unknown function of the file attendance.php. The manipulation of the argument class_id leads to sql injection. The exploit has been disclosed to the public and may be used. VDB-247254 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-6616
Disclosure Date: December 08, 2023 (last updated February 25, 2025)
A vulnerability was found in SourceCodester Simple Student Attendance System 1.0 and classified as problematic. This issue affects some unknown processing of the file index.php. The manipulation of the argument page leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-247253 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-39342
Disclosure Date: August 08, 2023 (last updated February 25, 2025)
Dangerzone is software for converting potentially dangerous PDFs, office documents, or images to safe PDFs. The Dangerzone CLI (`dangerzone-cli` command) logs output from the container where the file sanitization takes place, to the user's terminal. Prior to version 0.4.2, if the container is compromised and can return attacker-controlled strings, then the attacker may be able to spoof messages in the user's terminal or change the window title. Besides logging output from containers, it also logs the names of the files it sanitizes. If these files contain ANSI escape sequences, then the same issue applies. Dangerzone is predominantly a GUI application, so this issue should leave most of our users unaffected. Nevertheless, we always suggest updating to the newest version. This issue is fixed in Dangerzone 0.4.2.
0
Attacker Value
Unknown
CVE-2023-38942
Disclosure Date: August 03, 2023 (last updated February 25, 2025)
Dango-Translator v4.5.5 was discovered to contain a remote command execution (RCE) vulnerability via the component app/config/cloud_config.json.
0
Attacker Value
Unknown
CVE-2023-0763
Disclosure Date: May 15, 2023 (last updated February 24, 2025)
The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Holidays, which could allow attackers to make logged in admins delete arbitrary holidays via a CSRF attack
0
Attacker Value
Unknown
CVE-2023-0762
Disclosure Date: May 15, 2023 (last updated October 08, 2023)
The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting designations, which could allow attackers to make logged in admins delete arbitrary designations via a CSRF attack
0
Attacker Value
Unknown
CVE-2023-0761
Disclosure Date: May 15, 2023 (last updated October 08, 2023)
The Clock In Portal- Staff & Attendance Management WordPress plugin through 2.1 does not have CSRF check when deleting Staff members, which could allow attackers to make logged in admins delete arbitrary Staff via a CSRF attack
0
Attacker Value
Unknown
CVE-2023-26268
Disclosure Date: May 02, 2023 (last updated February 24, 2025)
Design documents with matching document IDs, from databases on the same cluster, may share a mutable Javascript environment when using these design document functions:
* validate_doc_update
* list
* filter
* filter views (using view functions as filters)
* rewrite
* update
This doesn't affect map/reduce or search (Dreyfus) index functions.
Users are recommended to upgrade to a version that is no longer affected by this issue (Apache CouchDB 3.3.2 or 3.2.3).
Workaround: Avoid using design documents from untrusted sources which may attempt to cache or store data in the Javascript environment.
0
Attacker Value
Unknown
CVE-2022-30260
Disclosure Date: December 26, 2022 (last updated February 24, 2025)
Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signature). This affects versions before 14.3 of DeltaV M-series, DeltaV S-series, DeltaV P-series, DeltaV SIS, and DeltaV CIOC/EIOC/WIOC IO cards.
0