Show filters
356 Total Results
Displaying 71-80 of 356
Sort by:
Attacker Value
Unknown
CVE-2023-30124
Disclosure Date: May 18, 2023 (last updated October 08, 2023)
LavaLite v9.0.0 is vulnerable to Cross Site Scripting (XSS).
0
Attacker Value
Unknown
CVE-2023-27238
Disclosure Date: May 12, 2023 (last updated October 08, 2023)
LavaLite CMS v 9.0.0 was discovered to be vulnerable to web cache poisoning.
0
Attacker Value
Unknown
CVE-2023-27237
Disclosure Date: May 12, 2023 (last updated October 08, 2023)
LavaLite CMS v 9.0.0 was discovered to be vulnerable to a host header injection attack.
0
Attacker Value
Unknown
CVE-2021-31239
Disclosure Date: May 09, 2023 (last updated October 08, 2023)
An issue found in SQLite SQLite3 v.3.35.4 that allows a remote attacker to cause a denial of service via the appendvfs.c function.
0
Attacker Value
Unknown
CVE-2023-27844
Disclosure Date: April 17, 2023 (last updated October 08, 2023)
SQL injection vulnerability found in PrestaShopleurlrewrite v.1.0 and before allow a remote attacker to gain privileges via the Dispatcher::getController component.
0
Attacker Value
Unknown
CVE-2023-24678
Disclosure Date: March 17, 2023 (last updated October 08, 2023)
A vulnerability in Centralite Pearl Thermostat 0x04075010 allows attackers to cause a Denial of Service (DoS) via a crafted Zigbee message.
0
Attacker Value
Unknown
CVE-2023-26104
Disclosure Date: February 25, 2023 (last updated October 08, 2023)
All versions of the package lite-web-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse.
0
Attacker Value
Unknown
CVE-2022-23535
Disclosure Date: February 24, 2023 (last updated November 08, 2023)
LiteDB is a small, fast and lightweight .NET NoSQL embedded database. Versions prior to 5.0.13 are subject to Deserialization of Untrusted Data. LiteDB uses a special field in JSON documents to cast different types from `BsonDocument` to POCO classes. When instances of an object are not the same of class, `BsonMapper` use a special field `_type` string info with full class name with assembly to be loaded and fit into your model. If your end-user can send to your app a plain JSON string, deserialization can load an unsafe object to fit into your model. This issue is patched in version 5.0.13 with some basic fixes to avoid this, but is not 100% guaranteed when using `Object` type. The next major version will contain an allow-list to select what kind of Assembly can be loaded. Workarounds are detailed in the vendor advisory.
0
Attacker Value
Unknown
CVE-2023-25578
Disclosure Date: February 15, 2023 (last updated November 08, 2023)
Starlite is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 1.5.2, the request body parsing in `starlite` allows a potentially unauthenticated attacker to consume a large amount of CPU time and RAM. The multipart body parser processes an unlimited number of file parts and an unlimited number of field parts. This is a remote, potentially unauthenticated Denial of Service vulnerability. This vulnerability affects applications with a request handler that accepts a `Body(media_type=RequestEncodingType.MULTI_PART)`. The large amount of CPU time required for processing requests can block all available worker processes and significantly delay or slow down the processing of legitimate user requests. The large amount of RAM accumulated while processing requests can lead to Out-Of-Memory kills. Complete DoS is achievable by sending many concurrent multipart requests in a loop. Version 1.51.2 contains a patch for this issue.
0
Attacker Value
Unknown
CVE-2022-3891
Disclosure Date: February 13, 2023 (last updated October 08, 2023)
The WP FullCalendar WordPress plugin before 1.5 does not ensure that the post retrieved via an AJAX action is public and can be accessed by the user making the request, allowing unauthenticated attackers to get the content of arbitrary posts, including draft/private as well as password-protected ones.
0