Show filters
285 Total Results
Displaying 71-80 of 285
Sort by:
Attacker Value
Unknown
CVE-2023-36007
Disclosure Date: November 14, 2023 (last updated November 22, 2023)
Microsoft Send Customer Voice survey from Dynamics 365 Spoofing Vulnerability
0
Attacker Value
Unknown
CVE-2023-42543
Disclosure Date: November 07, 2023 (last updated November 15, 2023)
Improper verification of intent by broadcast receiver vulnerability in Bixby Voice prior to version 3.3.35.12 allows attackers to access arbitrary data with Bixby Voice privilege.
0
Attacker Value
Unknown
CVE-2023-5443
Disclosure Date: October 27, 2023 (last updated November 08, 2023)
Improper Protection for Outbound Error Messages and Alert Signals vulnerability in EDM Informatics E-invoice allows Account Footprinting.This issue affects E-invoice: before 2.1.
0
Attacker Value
Unknown
CVE-2023-46076
Disclosure Date: October 26, 2023 (last updated October 31, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in RedNao WooCommerce PDF Invoice Builder, Create invoices, packing slips and more plugin <= 1.2.102 versions.
0
Attacker Value
Unknown
CVE-2023-42808
Disclosure Date: October 04, 2023 (last updated October 11, 2023)
Common Voice is the web app for Mozilla Common Voice, a platform for collecting speech donations in order to create public domain datasets for training voice recognition-related tools. Version 1.88.2 is vulnerable to reflected Cross-Site Scripting given that user-controlled data flows to a path expression (path of a network request). This issue may lead to reflected Cross-Site Scripting (XSS) in the context of Common Voice’s server origin. As of time of publication, it is unknown whether any patches or workarounds exist.
0
Attacker Value
Unknown
CVE-2023-39285
Disclosure Date: September 14, 2023 (last updated October 08, 2023)
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 SP3 (22.24.5800.0) could allow an unauthenticated attacker to perform a Cross Site Request Forgery (CSRF) attack due to insufficient request validation. A successful exploit could allow an attacker to provide a modified URL, potentially enabling them to modify system configuration settings.
0
Attacker Value
Unknown
CVE-2023-4245
Disclosure Date: August 31, 2023 (last updated November 09, 2023)
The WooCommerce PDF Invoice Builder for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the GetInvoiceDetail function in versions up to, and including, 1.2.89. This makes it possible for subscribers to view arbitrary invoices provided they can guess the order id and invoice id.
0
Attacker Value
Unknown
CVE-2023-4161
Disclosure Date: August 31, 2023 (last updated November 09, 2023)
The WooCommerce PDF Invoice Builder for WordPress is vulnerable to Cross-Site Request Forgery due to a missing nonce check on the SaveCustomField function in versions up to, and including, 1.2.90. This makes it possible for unauthenticated attackers to create invoice fields provided they can trick an admin into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2023-4160
Disclosure Date: August 31, 2023 (last updated October 08, 2023)
The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 1.2.90 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
0
Attacker Value
Unknown
CVE-2023-3764
Disclosure Date: August 31, 2023 (last updated November 09, 2023)
The WooCommerce PDF Invoice Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.90. This is due to missing or incorrect nonce validation on the Save function. This makes it possible for unauthenticated attackers to make changes to invoices via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0