Show filters
393 Total Results
Displaying 81-90 of 393
Sort by:
Attacker Value
Unknown

CVE-2023-51074

Disclosure Date: December 27, 2023 (last updated February 25, 2025)
json-path v2.8.0 was discovered to contain a stack overflow via the Criteria.parse() method.
Attacker Value
Unknown

CVE-2023-5163

Disclosure Date: November 22, 2023 (last updated February 25, 2025)
The Weather Atlas Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'shortcode-weather-atlas' shortcode in versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2023-20521

Disclosure Date: November 14, 2023 (last updated February 25, 2025)
TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.
Attacker Value
Unknown

CVE-2022-23821

Disclosure Date: November 14, 2023 (last updated February 25, 2025)
Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.
Attacker Value
Unknown

CVE-2022-23820

Disclosure Date: November 14, 2023 (last updated February 25, 2025)
Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.
Attacker Value
Unknown

CVE-2023-46638

Disclosure Date: November 13, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Webcodin WCP OpenWeather plugin <= 2.5.0 versions.
Attacker Value
Unknown

CVE-2023-5789

Disclosure Date: October 26, 2023 (last updated February 25, 2025)
A vulnerability classified as problematic has been found in Dragon Path 707GR1 up to 20231022. Affected is an unknown function of the component Ping Diagnostics. The manipulation of the argument Host Address with the input >><img/src/onerror=alert(1)> leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-243594 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-45992

Disclosure Date: October 19, 2023 (last updated February 25, 2025)
A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthenticated attacker to execute persistent XSS and CSRF attacks against a user of the admin management interface. A successful attack, combined with a certain admin activity, could allow the attacker to gain full admin privileges on the exploited system.
Attacker Value
Unknown

CVE-2023-27315

Disclosure Date: October 12, 2023 (last updated February 25, 2025)
SnapGathers versions prior to 4.9 are susceptible to a vulnerability which could allow a local authenticated attacker to discover plaintext domain user credentials
Attacker Value
Unknown

CVE-2023-5366

Disclosure Date: October 06, 2023 (last updated February 25, 2025)
A flaw was found in Open vSwitch that allows ICMPv6 Neighbor Advertisement packets between virtual machines to bypass OpenFlow rules. This issue may allow a local attacker to create specially crafted packets with a modified or spoofed target IP address field that can redirect ICMPv6 traffic to arbitrary IP addresses.