Show filters
393 Total Results
Displaying 91-100 of 393
Sort by:
Attacker Value
Unknown
CVE-2023-27433
Disclosure Date: October 04, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in YAS Global Team Make Paths Relative allows Cross Site Request Forgery.This issue affects Make Paths Relative: from n/a through 1.3.0.
0
Attacker Value
Unknown
CVE-2023-3153
Disclosure Date: October 04, 2023 (last updated February 25, 2025)
A flaw was found in Open Virtual Network where the service monitor MAC does not properly rate limit. This issue could allow an attacker to cause a denial of service, including on deployments with CoPP enabled and properly configured.
0
Attacker Value
Unknown
CVE-2023-4944
Disclosure Date: September 14, 2023 (last updated October 08, 2023)
The Awesome Weather Widget for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'awesome-weather' shortcode in versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2023-21523
Disclosure Date: September 12, 2023 (last updated February 25, 2025)
A Stored Cross-site Scripting (XSS) vulnerability in the Management Console (User Management and Alerts) of BlackBerry AtHoc version 7.15 could allow an attacker to execute script commands in the context of the affected user account.
0
Attacker Value
Unknown
CVE-2023-21520
Disclosure Date: September 12, 2023 (last updated October 08, 2023)
A PII Enumeration via Credential Recovery in the Self Service (Credential Recovery) of BlackBerry AtHoc version 7.15 could allow an attacker to potentially associate a list of contact details with an AtHoc IWS organization.
0
Attacker Value
Unknown
CVE-2023-21522
Disclosure Date: September 12, 2023 (last updated February 25, 2025)
A Reflected Cross-site Scripting (XSS) vulnerability in the Management Console (Reports) of BlackBerry AtHoc version 7.15 could allow an attacker to potentially control a script that is executed in the victim's browser then they can execute script commands in the context of the affected user account.
0
Attacker Value
Unknown
CVE-2023-21521
Disclosure Date: September 12, 2023 (last updated February 25, 2025)
An SQL Injection vulnerability in the Management Console (Operator Audit Trail) of BlackBerry AtHoc version 7.15 could allow an attacker to potentially read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database, recover the content of a given file present on the DBMS file system and in some cases issue commands to the operating system.
0
Attacker Value
Unknown
CVE-2023-36328
Disclosure Date: September 01, 2023 (last updated February 25, 2025)
Integer Overflow vulnerability in mp_grow in libtom libtommath before commit beba892bc0d4e4ded4d667ab1d2a94f4d75109a9, allows attackers to execute arbitrary code and cause a denial of service (DoS).
0
Attacker Value
Unknown
CVE-2023-25471
Disclosure Date: August 30, 2023 (last updated February 25, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Webcodin WCP OpenWeather plugin <= 2.5.0 versions.
0
Attacker Value
Unknown
CVE-2023-39663
Disclosure Date: August 29, 2023 (last updated February 25, 2025)
Mathjax up to v2.7.9 was discovered to contain two Regular expression Denial of Service (ReDoS) vulnerabilities in MathJax.js via the components pattern and markdownPattern. NOTE: the vendor disputes this because the regular expressions are not applied to user input; thus, there is no risk.
0