Show filters
461 Total Results
Displaying 71-80 of 461
Sort by:
Attacker Value
Unknown

CVE-2017-20184

Disclosure Date: May 04, 2023 (last updated February 24, 2025)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Carlo Gavazzi Powersoft up to version 2.1.1.1 allows an unauthenticated, remote attacker to download any file from the affected device.
Attacker Value
Unknown

CVE-2023-29637

Disclosure Date: May 01, 2023 (last updated February 24, 2025)
Cross Site Scripting (XSS) vulnerability in Qbian61 forum-java, allows attackers to inject arbitrary web script or HTML via editing the article content in the "article editor" page.
Attacker Value
Unknown

CVE-2023-1587

Disclosure Date: April 19, 2023 (last updated February 24, 2025)
Avast and AVG Antivirus for Windows were susceptible to a NULL pointer dereference issue via RPC-interface. The issue was fixed with Avast and AVG Antivirus version 22.11
Attacker Value
Unknown

CVE-2023-1586

Disclosure Date: April 19, 2023 (last updated February 24, 2025)
Avast and AVG Antivirus for Windows were susceptible to a Time-of-check/Time-of-use (TOCTOU) vulnerability in the restore process leading to arbitrary file creation. The issue was fixed with Avast and AVG Antivirus version 22.11
Attacker Value
Unknown

CVE-2023-1585

Disclosure Date: April 19, 2023 (last updated February 24, 2025)
Avast and AVG Antivirus for Windows were susceptible to a Time-of-check/Time-of-use (TOCTOU) vulnerability in the Quarantine process, leading to arbitrary file/directory deletion. The issue was fixed with Avast and AVG Antivirus version 22.11 and virus definitions from 14 February 2023 or later.
Attacker Value
Unknown

CVE-2023-26919

Disclosure Date: April 10, 2023 (last updated February 24, 2025)
delight-nashorn-sandbox 0.2.4 and 0.2.5 is vulnerable to sandbox escape. When allowExitFunctions is set to false, the loadWithNewGlobal function can be used to invoke the exit and quit methods to exit the Java process.
Attacker Value
Unknown

CVE-2023-25059

Disclosure Date: April 07, 2023 (last updated February 24, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in avalex GmbH avalex – Automatically secure legal texts plugin <= 3.0.3 versions.
Attacker Value
Unknown

CVE-2022-30350

Disclosure Date: March 30, 2023 (last updated February 24, 2025)
Avanquest Software RAD PDF (PDFEscape Online) 3.19.2.2 is vulnerable to Information Leak / Disclosure. The PDFEscape Online tool provides users with a "white out" functionality for redacting images, text, and other graphics from a PDF document. However, this mechanism does not remove underlying text or PDF object specification information from the PDF. As a result, for example, redacted text may be copy-pasted by a PDF reader.
Attacker Value
Unknown

CVE-2023-28867

Disclosure Date: March 27, 2023 (last updated February 24, 2025)
In GraphQL Java (aka graphql-java) before 20.1, an attacker can send a crafted GraphQL query that causes stack consumption. The fixed versions are 20.1, 19.4, 18.4, 17.5, and 0.0.0-2023-03-20T01-49-44-80e3135.
Attacker Value
Unknown

CVE-2023-23328

Disclosure Date: March 10, 2023 (last updated February 24, 2025)
A File Upload vulnerability exists in AvantFAX 3.3.7. An authenticated user can bypass PHP file type validation in FileUpload.php by uploading a specially crafted PHP file.