Show filters
324 Total Results
Displaying 81-90 of 324
Sort by:
Attacker Value
Unknown

CVE-2023-0331

Disclosure Date: February 27, 2023 (last updated October 08, 2023)
The Correos Oficial WordPress plugin through 1.2.0.2 does not have an authorization check user input validation when generating a file path, allowing unauthenticated attackers to download arbitrary files from the server.
Attacker Value
Unknown

CVE-2023-25157

Disclosure Date: February 21, 2023 (last updated November 08, 2023)
GeoServer is an open source software server written in Java that allows users to share and edit geospatial data. GeoServer includes support for the OGC Filter expression language and the OGC Common Query Language (CQL) as part of the Web Feature Service (WFS) and Web Map Service (WMS) protocols. CQL is also supported through the Web Coverage Service (WCS) protocol for ImageMosaic coverages. Users are advised to upgrade to either version 2.21.4, or version 2.22.2 to resolve this issue. Users unable to upgrade should disable the PostGIS Datastore *encode functions* setting to mitigate ``strEndsWith``, ``strStartsWith`` and ``PropertyIsLike `` misuse and enable the PostGIS DataStore *preparedStatements* setting to mitigate the ``FeatureId`` misuse.
Attacker Value
Unknown

CVE-2023-24509

Disclosure Date: February 14, 2023 (last updated October 08, 2023)
On affected modular platforms running Arista EOS equipped with both redundant supervisor modules and having the redundancy protocol configured with RPR or SSO, an existing unprivileged user can login to the standby supervisor as a root user, leading to a privilege escalation. Valid user credentials are required in order to exploit this vulnerability.
Attacker Value
Unknown

CVE-2022-46650

Disclosure Date: February 10, 2023 (last updated October 08, 2023)
Acemanager in ALEOS before version 4.16 allows a user with valid credentials to reconfigure the device to expose the ACEManager credentials on the pre-login status page.
Attacker Value
Unknown

CVE-2022-46649

Disclosure Date: February 10, 2023 (last updated October 08, 2023)
Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to execute arbitrary shell commands on the device.
Attacker Value
Unknown

CVE-2022-41620

Disclosure Date: February 08, 2023 (last updated November 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in SeoSamba for WordPress Webmasters plugin <= 1.0.5 versions.
Attacker Value
Unknown

CVE-2022-47873

Disclosure Date: January 31, 2023 (last updated October 08, 2023)
Netcad KEOS 1.0 is vulnerable to XML External Entity (XXE) resulting in SSRF with XXE (remote).
Attacker Value
Unknown

CVE-2023-0452

Disclosure Date: January 26, 2023 (last updated October 08, 2023)
Econolite EOS versions prior to 3.2.23 use a weak hash algorithm for encrypting privileged user credentials. A configuration file that is accessible without authentication uses MD5 hashes for encrypting credentials, including those of administrators and technicians.
Attacker Value
Unknown

CVE-2023-0451

Disclosure Date: January 26, 2023 (last updated October 08, 2023)
Econolite EOS versions prior to 3.2.23 lack a password requirement for gaining “READONLY” access to log files and certain database and configuration files. One such file contains tables with MD5 hashes and usernames for all defined users in the control software, including administrators and technicians.
Attacker Value
Unknown

CVE-2022-46639

Disclosure Date: January 23, 2023 (last updated October 08, 2023)
A vulnerability in the descarga_etiqueta.php component of Correos Prestashop 1.7.x allows attackers to execute a directory traversal.