Show filters
545 Total Results
Displaying 71-80 of 545
Sort by:
Attacker Value
Unknown

CVE-2023-37881

Disclosure Date: September 12, 2023 (last updated February 25, 2025)
Weak access control in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0.
Attacker Value
Unknown

CVE-2023-37879

Disclosure Date: September 12, 2023 (last updated February 25, 2025)
Insecure storage of sensitive information in Wing FTP Server (User Web Client) allows information elicitation.This issue affects Wing FTP Server: <= 7.2.0.
Attacker Value
Unknown

CVE-2023-37878

Disclosure Date: September 12, 2023 (last updated February 25, 2025)
Insecure default permissions in Wing FTP Server (Admin Web Client) allows for privilege escalation.This issue affects Wing FTP Server: <= 7.2.0.
Attacker Value
Unknown

CVE-2023-37875

Disclosure Date: September 12, 2023 (last updated February 25, 2025)
Improper encoding or escaping of output in Wing FTP Server (User Web Client) allows Cross-Site Scripting (XSS).This issue affects Wing FTP Server: <= 7.2.0.
Attacker Value
Unknown

CVE-2023-33466

Disclosure Date: June 29, 2023 (last updated February 25, 2025)
Orthanc before 1.12.0 allows authenticated users with access to the Orthanc API to overwrite arbitrary files on the file system, and in specific deployment scenarios allows the attacker to overwrite the configuration, which can be exploited to trigger Remote Code Execution (RCE).
Attacker Value
Unknown

CVE-2023-35042

Disclosure Date: June 12, 2023 (last updated November 08, 2023)
GeoServer 2, in some configurations, allows remote attackers to execute arbitrary code via java.lang.Runtime.getRuntime().exec in wps:LiteralData within a wps:Execute request, as exploited in the wild in June 2023. NOTE: the vendor states that they are unable to reproduce this in any version.
Attacker Value
Unknown

CVE-2020-36710

Disclosure Date: June 07, 2023 (last updated February 25, 2025)
The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are set to hide the login page making it possible for unauthenticated attackers to brute force credentials on sites in versions up to, and including, 1.5.4.2.
Attacker Value
Unknown

CVE-2018-25087

Disclosure Date: June 06, 2023 (last updated February 25, 2025)
A vulnerability classified as problematic was found in Arborator Server. This vulnerability affects the function start of the file project.cgi. The manipulation of the argument project leads to denial of service. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The patch is identified as cdbdbcbd491db65e9d697ab4365605fdfab1a604. It is recommended to apply a patch to fix this issue. VDB-230662 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2017-20185

Disclosure Date: June 06, 2023 (last updated February 25, 2025)
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Fuzzy SWMP. It has been rated as problematic. This issue affects some unknown processing of the file swmp.php of the component GET Parameter Handler. The manipulation of the argument theme leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The identifier of the patch is 792bcab637cb8c3bd251d8fc8771512c5329a93e. It is recommended to apply a patch to fix this issue. The identifier VDB-230669 was assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Attacker Value
Unknown

CVE-2021-45345

Disclosure Date: May 10, 2023 (last updated February 24, 2025)
Buffer Overflow vulnerability found in En3rgy WebcamServer v.0.5.2 allows a remote attacker to cause a denial of service via the WebcamServer.exe file.