Show filters
455 Total Results
Displaying 81-90 of 455
Sort by:
Attacker Value
Unknown

CVE-2023-32726

Disclosure Date: December 18, 2023 (last updated December 23, 2023)
The vulnerability is caused by improper check for check if RDLENGTH does not overflow the buffer in response from DNS server.
Attacker Value
Unknown

CVE-2023-32725

Disclosure Date: December 18, 2023 (last updated December 23, 2023)
The website configured in the URL widget will receive a session cookie when testing or executing scheduled reports. The received session cookie can then be used to access the frontend as the particular user.
Attacker Value
Unknown

CVE-2023-49769

Disclosure Date: December 17, 2023 (last updated December 20, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.4.
Attacker Value
Unknown

CVE-2023-47548

Disclosure Date: December 07, 2023 (last updated December 14, 2023)
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in SoftLab Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site.This issue affects Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site: from n/a through 1.3.2.
Attacker Value
Unknown

CVE-2023-48841

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Appointment Scheduler 3.0 is vulnerable to CSV Injection via a Language > Labels > Export action.
Attacker Value
Unknown

CVE-2023-48840

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
A lack of rate limiting in pjActionAjaxSend in Appointment Scheduler 3.0 allows attackers to cause resource exhaustion.
Attacker Value
Unknown

CVE-2023-48839

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Appointment Scheduler 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.
Attacker Value
Unknown

CVE-2023-48838

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Appointment Scheduler 3.0 is vulnerable to Multiple HTML Injection issues via the SMS API Key or Default Country Code.
Attacker Value
Unknown

CVE-2023-48837

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Car Rental Script 3.0 is vulnerable to Multiple HTML Injection issues via SMS API Key or Default Country Code.
Attacker Value
Unknown

CVE-2023-48836

Disclosure Date: December 07, 2023 (last updated December 09, 2023)
Car Rental Script 3.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the name, plugin_sms_api_key, plugin_sms_country_code, calendar_id, title, country name, or customer_name parameter.