Show filters
393 Total Results
Displaying 81-90 of 393
Sort by:
Attacker Value
Unknown
CVE-2023-51074
Disclosure Date: December 27, 2023 (last updated February 25, 2025)
json-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method.
0
Attacker Value
Unknown
CVE-2023-5163
Disclosure Date: November 22, 2023 (last updated February 25, 2025)
The Weather Atlas Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'shortcode-weather-atlas' shortcode in versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2023-20521
Disclosure Date: November 14, 2023 (last updated February 25, 2025)
TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.
0
Attacker Value
Unknown
CVE-2022-23821
Disclosure Date: November 14, 2023 (last updated February 25, 2025)
Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2022-23820
Disclosure Date: November 14, 2023 (last updated February 25, 2025)
Failure to validate the AMD SMM communication buffer
may allow an attacker to corrupt the SMRAM potentially leading to arbitrary
code execution.
0
Attacker Value
Unknown
CVE-2023-46638
Disclosure Date: November 13, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Webcodin WCP OpenWeather plugin <= 2.5.0 versions.
0
Attacker Value
Unknown
CVE-2023-5789
Disclosure Date: October 26, 2023 (last updated February 25, 2025)
A vulnerability classified as problematic has been found in Dragon Path 707GR1 up to 20231022. Affected is an unknown function of the component Ping Diagnostics. The manipulation of the argument Host Address with the input >><img/src/onerror=alert(1)> leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-243594 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-45992
Disclosure Date: October 19, 2023 (last updated February 25, 2025)
A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthenticated attacker to execute persistent XSS and CSRF attacks against a user of the admin management interface. A successful attack, combined with a certain admin activity, could allow the attacker to gain full admin privileges on the exploited system.
0
Attacker Value
Unknown
CVE-2023-27315
Disclosure Date: October 12, 2023 (last updated February 25, 2025)
SnapGathers versions prior to 4.9 are susceptible to a vulnerability
which could allow a local authenticated attacker to discover plaintext
domain user credentials
0
Attacker Value
Unknown
CVE-2023-5366
Disclosure Date: October 06, 2023 (last updated February 25, 2025)
A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses.
0