Show filters
119 topics marked with the following tags:
Displaying 71-80 of 119
Sort by:
Attacker Value
Moderate
CVE-2023-23396
Disclosure Date: March 14, 2023 (last updated May 29, 2024)
Microsoft Excel Denial of Service Vulnerability
2
Attacker Value
Moderate
CVE-2021-38603
Disclosure Date: August 12, 2021 (last updated November 28, 2024)
PluXML 5.8.7 allows core/admin/profil.php stored XSS via the Information field.
1
Attacker Value
Moderate
CVE-2023-36745
Disclosure Date: September 12, 2023 (last updated January 11, 2025)
Microsoft Exchange Server Remote Code Execution Vulnerability
3
Attacker Value
High
CVE-2023-33145
Disclosure Date: June 14, 2023 (last updated January 11, 2025)
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
2
Attacker Value
Moderate
CVE-2022-0342
Disclosure Date: March 28, 2022 (last updated October 07, 2023)
An authentication bypass vulnerability in the CGI program of Zyxel USG/ZyWALL series firmware versions 4.20 through 4.70, USG FLEX series firmware versions 4.50 through 5.20, ATP series firmware versions 4.32 through 5.20, VPN series firmware versions 4.30 through 5.20, and NSG series firmware versions V1.20 through V1.33 Patch 4, which could allow an attacker to bypass the web authentication and obtain administrative access of the device.
6
Attacker Value
Unknown
CVE-2021-30617
Disclosure Date: September 03, 2021 (last updated November 08, 2023)
Chromium: CVE-2021-30617 Policy bypass in Blink
1
Attacker Value
High
CVE-2019-15954: Total.js CMS 12 Widget Remote Code Execution
Disclosure Date: September 05, 2019 (last updated March 06, 2020)
Total.js is a Node.js Framework for building e-commerce applications, REST services, real-time apps, or apps for Internet of Things (IoT), etc. Total.js CMS is a Content Management System (application) that is part of the Total.js framework. A commercial version is also available, and can be seen used world-wide.
In Total.js CMS, a user with admin permission may be able to create a widget, and extend CMS functionalities for visitors. However, this can also be abused to upload JavaScript code that will be evaluated server side. As a result, it is possible to embed malicious JavaScript in the new widget, and gain remote code execution.
0
Attacker Value
High
CVE-2023-33131
Disclosure Date: June 14, 2023 (last updated January 11, 2025)
Microsoft Outlook Remote Code Execution Vulnerability
2
Attacker Value
High
CVE-2020-28949
Disclosure Date: November 19, 2020 (last updated November 08, 2023)
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.
1
Attacker Value
Very High
CVE-nu11-20-100121
Last updated October 01, 2021
## Description of vulnerability:
The id=2 parameter from view_vacancy app on page, appears to be vulnerable to SQL Injection - Stealing the Password Hashes attacks.
The payloads 19424269' or '1309'='1309 and 39476597' or '2917'='2923 were each submitted in the id parameter.
These two requests resulted in different responses, indicating that the input is being incorporated into a SQL query in an unsafe way.
1