Show filters
14,890 Total Results
Displaying 81-90 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Very High
CVE-2023-2068
Disclosure Date: June 27, 2023 (last updated October 08, 2023)
The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is available to unauthenticated users.
2
Attacker Value
High
CVE-2023-33131
Disclosure Date: June 14, 2023 (last updated January 11, 2025)
Microsoft Outlook Remote Code Execution Vulnerability
2
Attacker Value
Very High
CVE-2022-37969
Disclosure Date: September 13, 2022 (last updated February 24, 2025)
Windows Common Log File System Driver Elevation of Privilege Vulnerability
2
Attacker Value
Unknown
CVE-2022-22047
Disclosure Date: July 12, 2022 (last updated February 24, 2025)
Windows Client Server Run-time Subsystem (CSRSS) Elevation of Privilege Vulnerability
3
Attacker Value
Very High
CVE-2021-42671
Disclosure Date: November 05, 2021 (last updated February 23, 2025)
An incorrect access control vulnerability exists in Sourcecodester Engineers Online Portal in PHP in nia_munoz_monitoring_system/admin/uploads. An attacker can leverage this vulnerability in order to bypass access controls and access all the files uploaded to the web server without the need of authentication or authorization.
2
Attacker Value
Very High
CVE-2021-42665
Disclosure Date: November 05, 2021 (last updated February 23, 2025)
An SQL Injection vulnerability exists in Sourcecodester Engineers Online Portal in PHP via the login form inside of index.php, which can allow an attacker to bypass authentication.
2
Attacker Value
Unknown
CVE-2021-36959
Disclosure Date: September 15, 2021 (last updated November 28, 2024)
Windows Authenticode Spoofing Vulnerability
3
Attacker Value
Low
CVE-2021-33331
Disclosure Date: August 03, 2021 (last updated February 23, 2025)
Open redirect vulnerability in the Notifications module in Liferay Portal 7.0.0 through 7.3.1, and Liferay DXP 7.0 before fix pack 94, 7.1 before fix pack 19 and 7.2 before fix pack 8, allows remote attackers to redirect users to arbitrary external URLs via the 'redirect' parameter.
2
Attacker Value
Low
CVE-2021-33326
Disclosure Date: August 03, 2021 (last updated February 23, 2025)
Cross-site scripting (XSS) vulnerability in the Frontend JS module in Liferay Portal 7.3.4 and earlier, and Liferay DXP 7.0 before fix pack 96, 7.1 before fix pack 20 and 7.2 before fix pack 9, allows remote attackers to inject arbitrary web script or HTML via the title of a modal window.
2
Attacker Value
High
CVE-2021-26899
Disclosure Date: March 11, 2021 (last updated November 28, 2024)
Windows UPnP Device Host Elevation of Privilege Vulnerability
2