Show filters
727 Total Results
Displaying 91-100 of 727
Sort by:
Attacker Value
Unknown

CVE-2023-43353

Disclosure Date: October 20, 2023 (last updated October 25, 2023)
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the extra parameter in the news menu component.
Attacker Value
Unknown

CVE-2023-45394

Disclosure Date: October 20, 2023 (last updated October 31, 2023)
Stored Cross-Site Scripting (XSS) vulnerability in the Company field in the "Request a Quote" Section of Small CRM v3.0 allows an attacker to store and execute malicious javascript code in the Admin panel which leads to Admin account takeover.
Attacker Value
Unknown

CVE-2023-43359

Disclosure Date: October 19, 2023 (last updated October 31, 2023)
Cross Site Scripting vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to execute arbitrary code via a crafted script to the Page Specific Metadata and Smarty data parameters in the Content Manager Menu component.
Attacker Value
Unknown

CVE-2023-5587

Disclosure Date: October 15, 2023 (last updated November 06, 2023)
A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /vm/admin/doctors.php of the component Parameter Handler. The manipulation of the argument search leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-242186 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-45852

Disclosure Date: October 14, 2023 (last updated October 19, 2023)
In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute arbitrary commands via shell metacharacters in the ipaddr params JSON data for the put method.
Attacker Value
Unknown

CVE-2015-10125

Disclosure Date: October 05, 2023 (last updated October 12, 2023)
A vulnerability classified as problematic has been found in WP Ultimate CSV Importer Plugin 3.7.2 on WordPress. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 3.7.3 is able to address this issue. The identifier of the patch is 13c30af721d3f989caac72dd0f56cf0dc40fad7e. It is recommended to upgrade the affected component. The identifier VDB-241317 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-44075

Disclosure Date: October 04, 2023 (last updated October 09, 2023)
Cross Site Scripting vulnerability in Small CRM in PHP v.3.0 allows a remote attacker to execute arbitrary code via a crafted payload to the Address parameter.
Attacker Value
Unknown

CVE-2015-10124

Disclosure Date: October 02, 2023 (last updated October 09, 2023)
A vulnerability was found in Most Popular Posts Widget Plugin up to 0.8 on WordPress. It has been classified as critical. Affected is the function add_views/show_views of the file functions.php. The manipulation leads to sql injection. It is possible to launch the attack remotely. Upgrading to version 0.9 is able to address this issue. The patch is identified as a99667d11ac8d320006909387b100e9a8b5c12e1. It is recommended to upgrade the affected component. VDB-241026 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-41661

Disclosure Date: September 29, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in PressPage Entertainment Inc. Smarty for WordPress plugin <= 3.1.35 versions.
Attacker Value
Unknown

CVE-2023-43872

Disclosure Date: September 28, 2023 (last updated October 31, 2023)
A File upload vulnerability in CMSmadesimple v.2.2.18 allows a local attacker to upload a pdf file with hidden Cross Site Scripting (XSS).