Show filters
727 Total Results
Displaying 81-90 of 727
Sort by:
Attacker Value
Unknown

CVE-2023-43352

Disclosure Date: October 26, 2023 (last updated November 08, 2023)
An issue in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted payload to the Content Manager Menu component.
Attacker Value
Unknown

CVE-2023-46069

Disclosure Date: October 25, 2023 (last updated November 02, 2023)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Osmansorkar Ajax Archive Calendar plugin <= 2.6.7 versions.
Attacker Value
Unknown

CVE-2023-43360

Disclosure Date: October 25, 2023 (last updated October 31, 2023)
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Top Directory parameter in the File Picker Menu component.
Attacker Value
Unknown

CVE-2023-43358

Disclosure Date: October 23, 2023 (last updated October 30, 2023)
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title parameter in the News Menu component.
Attacker Value
Unknown

CVE-2023-5702

Disclosure Date: October 23, 2023 (last updated November 02, 2023)
A vulnerability was found in Viessmann Vitogate 300 up to 2.1.3.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /cgi-bin/. The manipulation leads to direct request. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-243140. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2023-4939

Disclosure Date: October 21, 2023 (last updated November 01, 2023)
The SALESmanago plugin for WordPress is vulnerable to Log Injection in versions up to, and including, 3.2.4. This is due to the use of a weak authentication token for the /wp-json/salesmanago/v1/callbackApiV3 API endpoint which is simply a SHA1 hash of the site URL and client ID found in the page source of the website. This makes it possible for unauthenticated attackers to inject arbitrary content into the log files, and when combined with another vulnerability this could have significant consequences.
Attacker Value
Unknown

CVE-2023-43357

Disclosure Date: October 20, 2023 (last updated October 25, 2023)
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Title parameter in the Manage Shortcuts component.
Attacker Value
Unknown

CVE-2023-43356

Disclosure Date: October 20, 2023 (last updated October 25, 2023)
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Global Meatadata parameter in the Global Settings Menu component.
Attacker Value
Unknown

CVE-2023-43355

Disclosure Date: October 20, 2023 (last updated October 25, 2023)
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the password and password again parameters in the My Preferences - Add user component.
Attacker Value
Unknown

CVE-2023-43354

Disclosure Date: October 20, 2023 (last updated October 25, 2023)
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Profiles parameter in the Extensions -MicroTiny WYSIWYG editor component.