Show filters
545 Total Results
Displaying 91-100 of 545
Sort by:
Attacker Value
Unknown
CVE-2023-0879
Disclosure Date: February 17, 2023 (last updated February 24, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.12.
0
Attacker Value
Unknown
CVE-2022-40016
Disclosure Date: February 15, 2023 (last updated February 24, 2025)
Use After Free (UAF) vulnerability in ireader media-server before commit 3e0f63f1d3553f75c7d4eb32fa7c7a1976a9ff84 in librtmp, allows attackers to cause a denial of service.
0
Attacker Value
Unknown
CVE-2023-0810
Disclosure Date: February 13, 2023 (last updated February 24, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.11.
0
Attacker Value
Unknown
CVE-2023-0748
Disclosure Date: February 08, 2023 (last updated February 24, 2025)
Open Redirect in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.
0
Attacker Value
Unknown
CVE-2023-0747
Disclosure Date: February 08, 2023 (last updated February 24, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.
0
Attacker Value
Unknown
CVE-2022-28923
Disclosure Date: February 06, 2023 (last updated February 24, 2025)
Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs.
0
Attacker Value
Unknown
CVE-2022-32984
Disclosure Date: January 31, 2023 (last updated October 08, 2023)
BTCPay Server 1.3.0 through 1.5.3 allows a remote attacker to obtain sensitive information when a public Point of Sale app is exposed. The sensitive information, found in the HTML source code, includes the xpub of the store. Also, if the store isn't using the internal lightning node, the credentials of a lightning node are exposed.
0
Attacker Value
Unknown
CVE-2023-0493
Disclosure Date: January 26, 2023 (last updated February 24, 2025)
Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5.
0
Attacker Value
Unknown
CVE-2022-25847
Disclosure Date: January 26, 2023 (last updated February 24, 2025)
All versions of the package serve-lite are vulnerable to Cross-site Scripting (XSS) because when it detects a request to a directory, it renders a file listing of all of its contents with links that include the actual file names without any sanitization or output encoding.
0
Attacker Value
Unknown
CVE-2022-21192
Disclosure Date: January 26, 2023 (last updated February 24, 2025)
All versions of the package serve-lite are vulnerable to Directory Traversal due to missing input sanitization or other checks and protections employed to the req.url passed as-is to path.join().
0