Show filters
111 Total Results
Displaying 91-100 of 111
Sort by:
Attacker Value
Unknown

CVE-2023-23862

Disclosure Date: May 09, 2023 (last updated October 08, 2023)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Gopi Ramasamy Vertical scroll recent post plugin <= 14.0 versions.
Attacker Value
Unknown

CVE-2023-29008

Disclosure Date: April 06, 2023 (last updated November 08, 2023)
The SvelteKit framework offers developers an option to create simple REST APIs. This is done by defining a `+server.js` file, containing endpoint handlers for different HTTP methods. SvelteKit provides out-of-the-box cross-site request forgery (CSRF) protection to its users. The protection is implemented at `kit/src/runtime/server/respond.js`. While the implementation does a sufficient job of mitigating common CSRF attacks, the protection can be bypassed in versions prior to 1.15.2 by simply specifying an upper-cased `Content-Type` header value. The browser will not send uppercase characters, but this check does not block all expected CORS requests. If abused, this issue will allow malicious requests to be submitted from third-party domains, which can allow execution of operations within the context of the victim's session, and in extreme scenarios can lead to unauthorized access to users’ accounts. This may lead to all POST operations requiring authentication being allowed in the f…
Attacker Value
Unknown

CVE-2022-4934

Disclosure Date: April 04, 2023 (last updated October 08, 2023)
A post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4 allows administrators to execute arbitrary code.
Attacker Value
Unknown

CVE-2022-3711

Disclosure Date: December 01, 2022 (last updated October 08, 2023)
A post-auth read-only SQL injection vulnerability allows users to read non-sensitive configuration database contents in the User Portal of Sophos Firewall releases older than version 19.5 GA.
Attacker Value
Unknown

CVE-2022-3710

Disclosure Date: December 01, 2022 (last updated October 08, 2023)
A post-auth read-only SQL injection vulnerability allows API clients to read non-sensitive configuration database contents in the API controller of Sophos Firewall releases older than version 19.5 GA.
Attacker Value
Unknown

CVE-2022-3696

Disclosure Date: December 01, 2022 (last updated October 08, 2023)
A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases older than version 19.5 GA.
Attacker Value
Unknown

CVE-2022-36786

Disclosure Date: November 17, 2022 (last updated October 26, 2023)
DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will run with ROOT permissions on the router.
Attacker Value
Unknown

CVE-2022-31127

Disclosure Date: July 06, 2022 (last updated October 07, 2023)
NextAuth.js is a complete open source authentication solution for Next.js applications. An attacker can pass a compromised input to the e-mail [signin endpoint](https://next-auth.js.org/getting-started/rest-api#post-apiauthsigninprovider) that contains some malicious HTML, tricking the e-mail server to send it to the user, so they can perform a phishing attack. Eg.: `balazs@email.com, <a href="http://attacker.com">Before signing in, claim your money!</a>`. This was previously sent to `balazs@email.com`, and the content of the email containing a link to the attacker's site was rendered in the HTML. This has been remedied in the following releases, by simply not rendering that e-mail in the HTML, since it should be obvious to the receiver what e-mail they used: next-auth v3 users before version 3.29.8 are impacted. (We recommend upgrading to v4, as v3 is considered unmaintained. next-auth v4 users before version 4.9.0 are impacted. If for some reason you cannot upgrade, the workaround r…
Attacker Value
Unknown

CVE-2022-0386

Disclosure Date: March 22, 2022 (last updated October 07, 2023)
A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code in Sophos UTM before version 9.710.
Attacker Value
Unknown

CVE-2021-37925

Disclosure Date: September 22, 2021 (last updated October 07, 2023)
Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability.