Show filters
255 Total Results
Displaying 81-90 of 255
Sort by:
Attacker Value
Unknown

CVE-2023-49344

Disclosure Date: December 14, 2023 (last updated December 21, 2023)
Temporary data passed between application components by Budgie Extras Window Shuffler applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file to present false information to users or deny access to the application and panel.
Attacker Value
Unknown

CVE-2023-49343

Disclosure Date: December 14, 2023 (last updated December 21, 2023)
Temporary data passed between application components by Budgie Extras Dropby applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file to present false information to users or deny access to the application and panel.
Attacker Value
Unknown

CVE-2023-49342

Disclosure Date: December 14, 2023 (last updated December 21, 2023)
Temporary data passed between application components by Budgie Extras Clockworks applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file to present false information to users or deny access to the application and panel.
Attacker Value
Unknown

CVE-2023-50368

Disclosure Date: December 14, 2023 (last updated December 19, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta Shortcodes and extra features for Phlox theme allows Stored XSS.This issue affects Shortcodes and extra features for Phlox theme: from n/a through 2.15.2.
Attacker Value
Unknown

CVE-2023-5764

Disclosure Date: December 12, 2023 (last updated April 25, 2024)
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating injection when supplying templating data.
Attacker Value
Unknown

CVE-2023-47815

Disclosure Date: November 22, 2023 (last updated November 29, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Venutius BP Profile Shortcodes Extra plugin <= 2.5.2 versions.
Attacker Value
Unknown

CVE-2023-47825

Disclosure Date: November 22, 2023 (last updated November 29, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in TienCOP WP EXtra plugin <= 6.4 versions.
Attacker Value
Unknown

CVE-2023-5314

Disclosure Date: November 22, 2023 (last updated November 28, 2023)
The WP EXtra plugin for WordPress is vulnerable to unauthorized access to restricted functionality due to a missing capability check on the 'test-email' section of the register() function in versions up to, and including, 6.2. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to send emails with arbitrary content to arbitrary locations from the affected site's mail server.
Attacker Value
Unknown

CVE-2023-5341

Disclosure Date: November 19, 2023 (last updated April 25, 2024)
A heap use-after-free flaw was found in coders/bmp.c in ImageMagick.
Attacker Value
Unknown

CVE-2023-47658

Disclosure Date: November 14, 2023 (last updated November 18, 2023)
Auth. (ShopManager+) Stored Cross-Site Scripting (XSS) vulnerability in actpro Extra Product Options for WooCommerce plugin <= 3.0.3 versions.