Show filters
570 Total Results
Displaying 81-90 of 570
Sort by:
Attacker Value
Unknown

CVE-2023-23721

Disclosure Date: March 20, 2023 (last updated February 24, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in David Gwyer Admin Log plugin <= 1.50 versions.
Attacker Value
Unknown

CVE-2023-26951

Disclosure Date: March 16, 2023 (last updated February 24, 2025)
onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Member List module.
Attacker Value
Unknown

CVE-2023-24774

Disclosure Date: March 10, 2023 (last updated February 24, 2025)
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php.
Attacker Value
Unknown

CVE-2023-26957

Disclosure Date: March 09, 2023 (last updated February 24, 2025)
onekeyadmin v1.3.9 was discovered to contain an arbitrary file delete vulnerability via the component \admin\controller\plugins.
Attacker Value
Unknown

CVE-2023-26948

Disclosure Date: March 09, 2023 (last updated February 24, 2025)
onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/file/download.
Attacker Value
Unknown

CVE-2023-24777

Disclosure Date: March 08, 2023 (last updated February 24, 2025)
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/list.
Attacker Value
Unknown

CVE-2023-24782

Disclosure Date: March 08, 2023 (last updated February 24, 2025)
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/edit.
Attacker Value
Unknown

CVE-2023-26956

Disclosure Date: March 08, 2023 (last updated February 24, 2025)
onekeyadmin v1.3.9 was discovered to contain an arbitrary file read vulnerability via the component /admin1/curd/code.
Attacker Value
Unknown

CVE-2023-24773

Disclosure Date: March 08, 2023 (last updated February 24, 2025)
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/list.
Attacker Value
Unknown

CVE-2023-26952

Disclosure Date: March 08, 2023 (last updated February 24, 2025)
onekeyadmin v1.3.9 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Menu module.