Show filters
324 Total Results
Displaying 71-80 of 324
Sort by:
Attacker Value
Unknown

CVE-2023-30752

Disclosure Date: August 14, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Silvia Pfeiffer and Andrew Nimmo External Videos plugin <= 2.0.1 versions.
Attacker Value
Unknown

CVE-2023-32478

Disclosure Date: July 21, 2023 (last updated October 08, 2023)
Dell PowerStore versions prior to 3.5.0.1 contain an insertion of sensitive information into log file vulnerability. A high privileged malicious user could potentially exploit this vulnerability, leading to sensitive information disclosure.
Attacker Value
Unknown

CVE-2023-25055

Disclosure Date: June 15, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Videos plugin <= 2.6.1 versions.
Attacker Value
Unknown

CVE-2023-35042

Disclosure Date: June 12, 2023 (last updated November 08, 2023)
GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData within a wps:Execute request, as exploited in the wild in June 2023. NOTE: the vendor states that they are unable to reproduce this in any version.
Attacker Value
Unknown

CVE-2022-41987

Disclosure Date: May 25, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in LearningTimes BadgeOS plugin <= 3.7.1.6 versions.
Attacker Value
Unknown

CVE-2023-25394

Disclosure Date: May 17, 2023 (last updated October 08, 2023)
Videostream macOS app 0.5.0 and 0.4.3 has a Race Condition. The Updater privileged script attempts to update Videostream every 5 hours.
Attacker Value
Unknown

CVE-2023-24512

Disclosure Date: April 25, 2023 (last updated October 08, 2023)
On affected platforms running Arista EOS, an authorized attacker with permissions to perform gNMI requests could craft a request allowing it to update arbitrary configurations in the switch. This situation occurs only when the Streaming Telemetry Agent (referred to as the TerminAttr agent) is enabled and gNMI access is configured on the agent. Note: This gNMI over the Streaming Telemetry Agent scenario is mostly commonly used when streaming to a 3rd party system and is not used by default when streaming to CloudVision
Attacker Value
Unknown

CVE-2023-24513

Disclosure Date: April 11, 2023 (last updated October 08, 2023)
On affected platforms running Arista CloudEOS an issue in the Software Forwarding Engine (Sfe) can lead to a potential denial of service attack by sending malformed packets to the switch. This causes a leak of packet buffers and if enough malformed packets are received, the switch may eventually stop forwarding traffic.
Attacker Value
Unknown

CVE-2023-24511

Disclosure Date: April 11, 2023 (last updated October 08, 2023)
On affected platforms running Arista EOS with SNMP configured, a specially crafted packet can cause a memory leak in the snmpd process. This may result in the snmpd processing being terminated (causing SNMP requests to time out until snmpd is automatically restarted) and potential memory resource exhaustion for other processes on the switch. The vulnerability does not have any confidentiality or integrity impacts to the system.
Attacker Value
Unknown

CVE-2022-4927

Disclosure Date: March 05, 2023 (last updated October 20, 2023)
A vulnerability was found in ualbertalib NEOSDiscovery 1.0.70 and classified as problematic. This issue affects some unknown processing of the file app/views/bookmarks/_refworks.html.erb. The manipulation leads to use of web link to untrusted target with window.opener access. The attack may be initiated remotely. Upgrading to version 1.0.71 is able to address this issue. The patch is named abe9f57123e0c278ae190cd7402a623d66c51375. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-222287.