Show filters
324 Total Results
Displaying 71-80 of 324
Sort by:
Attacker Value
Unknown
CVE-2023-30752
Disclosure Date: August 14, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Silvia Pfeiffer and Andrew Nimmo External Videos plugin <= 2.0.1 versions.
0
Attacker Value
Unknown
CVE-2023-32478
Disclosure Date: July 21, 2023 (last updated October 08, 2023)
Dell PowerStore versions prior to 3.5.0.1 contain an insertion of sensitive information into log file vulnerability. A high privileged malicious user could potentially exploit this vulnerability, leading to sensitive information disclosure.
0
Attacker Value
Unknown
CVE-2023-25055
Disclosure Date: June 15, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Videos plugin <= 2.6.1 versions.
0
Attacker Value
Unknown
CVE-2023-35042
Disclosure Date: June 12, 2023 (last updated November 08, 2023)
GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData within a wps:Execute request, as exploited in the wild in June 2023. NOTE: the vendor states that they are unable to reproduce this in any version.
0
Attacker Value
Unknown
CVE-2022-41987
Disclosure Date: May 25, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in LearningTimes BadgeOS plugin <= 3.7.1.6 versions.
0
Attacker Value
Unknown
CVE-2023-25394
Disclosure Date: May 17, 2023 (last updated October 08, 2023)
Videostream macOS app 0.5.0 and 0.4.3 has a Race Condition. The Updater privileged script attempts to update Videostream every 5 hours.
0
Attacker Value
Unknown
CVE-2023-24512
Disclosure Date: April 25, 2023 (last updated October 08, 2023)
On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to update arbitrary configurations in the switch. This situation occurs only when the Streaming Telemetry Agent (referred to as the TerminAttr agent) is enabled and gNMI access is configured on the agent. Note: This gNMI over the Streaming Telemetry Agent scenario is mostly commonly used when streaming to a 3rd party system and is not used by default when streaming to CloudVision
0
Attacker Value
Unknown
CVE-2023-24513
Disclosure Date: April 11, 2023 (last updated October 08, 2023)
On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the switch may eventually stop forwarding traffic.
0
Attacker Value
Unknown
CVE-2023-24511
Disclosure Date: April 11, 2023 (last updated October 08, 2023)
On affected platforms running Arista EOS with SNMP configured, a specially crafted packet can cause a memory leak in the snmpd process. This may result in the snmpd processing being terminated (causing SNMP requests to time out until snmpd is automatically restarted) and potential memory resource exhaustion for other processes on the switch. The vulnerability does not have any confidentiality or integrity impacts to the system.
0
Attacker Value
Unknown
CVE-2022-4927
Disclosure Date: March 05, 2023 (last updated October 20, 2023)
A vulnerability was found in ualbertalib NEOSDiscovery 1.0.70 and classified as problematic. This issue affects some unknown processing of the file app/views/bookmarks/_refworks.html.erb. The manipulation leads to use of web link to untrusted target with window.opener access. The attack may be initiated remotely. Upgrading to version 1.0.71 is able to address this issue. The patch is named abe9f57123e0c278ae190cd7402a623d66c51375. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-222287.
0