Show filters
563 Total Results
Displaying 91-100 of 563
Sort by:
Attacker Value
Unknown
CVE-2023-47801
Disclosure Date: November 13, 2023 (last updated November 21, 2023)
An issue was discovered in Click Studios Passwordstate before 9811. Existing users (Security Administrators) could use the System Wide API Key to read or delete private password records when specifically used with the PasswordHistory API endpoint. It is also possible to use the Copy/Move Password Record API Key to Copy/Move private password records.
0
Attacker Value
Unknown
CVE-2023-4218
Disclosure Date: November 09, 2023 (last updated November 25, 2023)
In Eclipse IDE versions < 2023-09 (4.29) some files with xml content are parsed vulnerable against all sorts of XXE attacks. The user just needs to open any evil project or update an open project with a vulnerable file (for example for review a foreign repository or patch).
0
Attacker Value
Unknown
CVE-2023-33481
Disclosure Date: November 07, 2023 (last updated November 15, 2023)
RemoteClinic 2.0 is vulnerable to a time-based blind SQL injection attack in the 'start' GET parameter of patients/index.php.
0
Attacker Value
Unknown
CVE-2023-33480
Disclosure Date: November 07, 2023 (last updated November 15, 2023)
RemoteClinic 2.0 contains a critical vulnerability chain that can be exploited by a remote attacker with low-privileged user credentials to create admin users, escalate privileges, and execute arbitrary code on the target system via a PHP shell. The vulnerabilities are caused by a lack of input validation and access control in the staff/register.php endpoint and the edit-my-profile.php page. By sending a series of specially crafted requests to the RemoteClinic application, an attacker can create admin users with more privileges than their own, upload a PHP file containing arbitrary code, and execute arbitrary commands via the PHP shell.
0
Attacker Value
Unknown
CVE-2023-33479
Disclosure Date: November 07, 2023 (last updated November 15, 2023)
RemoteClinic version 2.0 contains a SQL injection vulnerability in the /staff/edit.php file.
0
Attacker Value
Unknown
CVE-2023-33478
Disclosure Date: November 07, 2023 (last updated November 15, 2023)
RemoteClinic 2.0 has a SQL injection vulnerability in the ID parameter of /medicines/stocks.php.
0
Attacker Value
Unknown
CVE-2023-5082
Disclosure Date: November 06, 2023 (last updated November 15, 2023)
The History Log by click5 WordPress plugin before 1.0.13 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when using the Smash Balloon Social Photo Feed plugin alongside it.
0
Attacker Value
Unknown
CVE-2023-45827
Disclosure Date: November 06, 2023 (last updated November 15, 2023)
Dot diver is a lightweight, powerful, and dependency-free TypeScript utility library that provides types and functions to work with object paths in dot notation. In versions prior to 1.0.2 there is a Prototype Pollution vulnerability in the `setByPath` function which can leads to remote code execution (RCE). This issue has been addressed in commit `98daf567` which has been included in release 1.0.2. Users are advised to upgrade. There are no known workarounds to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-4043
Disclosure Date: November 03, 2023 (last updated November 14, 2023)
In Eclipse Parsson before versions 1.1.4 and 1.0.5, Parsing JSON from untrusted sources can lead malicious actors to exploit the fact that the built-in support for parsing numbers with large scale in Java has a number of edge cases where the input text of a number can lead to much larger processing time than one would expect.
To mitigate the risk, parsson put in place a size limit for the numbers as well as their scale.
0
Attacker Value
Unknown
CVE-2023-5763
Disclosure Date: November 03, 2023 (last updated November 14, 2023)
In Eclipse Glassfish 5 or 6, running with old versions of JDK (lower than 6u211, or < 7u201, or < 8u191), allows remote attackers to load malicious code on the server via access to insecure ORB listeners.
0