Show filters
1,341 Total Results
Displaying 91-100 of 1,341
Sort by:
Attacker Value
Unknown

CVE-2020-36727

Disclosure Date: June 07, 2023 (last updated October 08, 2023)
The Newsletter Manager plugin for WordPress is vulnerable to insecure deserialization in versions up to, and including, 1.5.1. This is due to unsanitized input from the 'customFieldsDetails' parameter being passed through a deserialization function. This potentially makes it possible for unauthenticated attackers to inject a serialized PHP object.
Attacker Value
Unknown

CVE-2023-2201

Disclosure Date: June 02, 2023 (last updated October 08, 2023)
The Web Directory Free for WordPress is vulnerable to SQL Injection via the ‘post_id’ parameter in versions up to, and including, 1.6.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers with contributor-level privileges to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Attacker Value
Unknown

CVE-2023-31921

Disclosure Date: May 12, 2023 (last updated October 08, 2023)
Jerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the ecma_big_uint_div_mod at jerry-core/ecma/operations/ecma-big-uint.c.
Attacker Value
Unknown

CVE-2023-31920

Disclosure Date: May 12, 2023 (last updated October 08, 2023)
Jerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the vm_loop at jerry-core/vm/vm.c.
Attacker Value
Unknown

CVE-2023-31919

Disclosure Date: May 12, 2023 (last updated October 08, 2023)
Jerryscript 3.0 (commit 05dbbd1) was discovered to contain an Assertion Failure via the jcontext_raise_exception at jerry-core/jcontext/jcontext.c.
Attacker Value
Unknown

CVE-2023-31918

Disclosure Date: May 12, 2023 (last updated October 08, 2023)
Jerryscript 3.0 (commit 1a2c047) was discovered to contain an Assertion Failure via the parser_parse_function_arguments at jerry-core/parser/js/js-parser.c.
Attacker Value
Unknown

CVE-2023-31916

Disclosure Date: May 12, 2023 (last updated October 08, 2023)
Jerryscript 3.0 (commit 1a2c047) was discovered to contain an Assertion Failure via the jmem_heap_finalize at jerry-core/jmem/jmem-heap.c.
Attacker Value
Unknown

CVE-2023-31914

Disclosure Date: May 12, 2023 (last updated October 08, 2023)
Jerryscript 3.0 (commit 05dbbd1) was discovered to contain out-of-memory issue in malloc.
Attacker Value
Unknown

CVE-2023-31913

Disclosure Date: May 12, 2023 (last updated October 08, 2023)
Jerryscript 3.0 *commit 1a2c047) was discovered to contain an Assertion Failure via the component parser_parse_class at jerry-core/parser/js/js-parser-expr.c.
Attacker Value
Unknown

CVE-2023-31910

Disclosure Date: May 10, 2023 (last updated October 08, 2023)
Jerryscript 3.0 (commit 05dbbd1) was discovered to contain a heap-buffer-overflow via the component parser_parse_function_statement at /jerry-core/parser/js/js-parser-statm.c.