Show filters
545 Total Results
Displaying 91-100 of 545
Sort by:
Attacker Value
Unknown

CVE-2023-0879

Disclosure Date: February 17, 2023 (last updated February 24, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.12.
Attacker Value
Unknown

CVE-2022-40016

Disclosure Date: February 15, 2023 (last updated February 24, 2025)
Use After Free (UAF) vulnerability in ireader media-server before commit 3e0f63f1d3553f75c7d4eb32fa7c7a1976a9ff84 in librtmp, allows attackers to cause a denial of service.
Attacker Value
Unknown

CVE-2023-0810

Disclosure Date: February 13, 2023 (last updated February 24, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.11.
Attacker Value
Unknown

CVE-2023-0748

Disclosure Date: February 08, 2023 (last updated February 24, 2025)
Open Redirect in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.
Attacker Value
Unknown

CVE-2023-0747

Disclosure Date: February 08, 2023 (last updated February 24, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository btcpayserver/btcpayserver prior to 1.7.6.
Attacker Value
Unknown

CVE-2022-28923

Disclosure Date: February 06, 2023 (last updated February 24, 2025)
Caddy v2.4.6 was discovered to contain an open redirection vulnerability which allows attackers to redirect users to phishing websites via crafted URLs.
Attacker Value
Unknown

CVE-2022-32984

Disclosure Date: January 31, 2023 (last updated October 08, 2023)
BTCPay Server 1.3.0 through 1.5.3 allows a remote attacker to obtain sensitive information when a public Point of Sale app is exposed. The sensitive information, found in the HTML source code, includes the xpub of the store. Also, if the store isn't using the internal lightning node, the credentials of a lightning node are exposed.
Attacker Value
Unknown

CVE-2023-0493

Disclosure Date: January 26, 2023 (last updated February 24, 2025)
Improper Neutralization of Equivalent Special Elements in GitHub repository btcpayserver/btcpayserver prior to 1.7.5.
Attacker Value
Unknown

CVE-2022-25847

Disclosure Date: January 26, 2023 (last updated February 24, 2025)
All versions of the package serve-lite are vulnerable to Cross-site Scripting (XSS) because when it detects a request to a directory, it renders a file listing of all of its contents with links that include the actual file names without any sanitization or output encoding.
Attacker Value
Unknown

CVE-2022-21192

Disclosure Date: January 26, 2023 (last updated February 24, 2025)
All versions of the package serve-lite are vulnerable to Directory Traversal due to missing input sanitization or other checks and protections employed to the req.url passed as-is to path.join().