Show filters
13,174 Total Results
Displaying 931-940 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2023-46230

Disclosure Date: January 30, 2024 (last updated February 06, 2024)
In Splunk Add-on Builder versions below 4.1.4, the app writes sensitive information to internal log files.
Attacker Value
Unknown

CVE-2023-5372

Disclosure Date: January 30, 2024 (last updated February 06, 2024)
The post-authentication command injection vulnerability in Zyxel NAS326 firmware versions through V5.21(AAZF.15)C0 and NAS542 firmware versions through V5.21(ABAG.12)C0 could allow an authenticated attacker with administrator privileges to execute some operating system (OS) commands by sending a crafted query parameter attached to the URL of an affected device’s web management interface.
Attacker Value
Unknown

CVE-2024-1022

Disclosure Date: January 29, 2024 (last updated February 06, 2024)
A vulnerability, which was classified as problematic, was found in CodeAstro Simple Student Result Management System 5.6. This affects an unknown part of the file /add_classes.php of the component Add Class Page. The manipulation of the argument Class Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252291.
Attacker Value
Unknown

CVE-2023-49038

Disclosure Date: January 29, 2024 (last updated February 07, 2024)
Command injection in the ping utility on Buffalo LS210D 1.78-0.03 allows a remote authenticated attacker to inject arbitrary commands onto the NAS as root.
Attacker Value
Unknown

CVE-2024-24140

Disclosure Date: January 29, 2024 (last updated February 03, 2024)
Sourcecodester Daily Habit Tracker App 1.0 allows SQL Injection via the parameter 'tracker.'
Attacker Value
Unknown

CVE-2024-24139

Disclosure Date: January 29, 2024 (last updated February 03, 2024)
Sourcecodester Login System with Email Verification 1.0 allows SQL Injection via the 'user' parameter.
Attacker Value
Unknown

CVE-2024-24134

Disclosure Date: January 29, 2024 (last updated February 22, 2024)
Sourcecodester Online Food Menu 1.0 is vulnerable to Cross Site Scripting (XSS) via the 'Menu Name' and 'Description' fields in the Update Menu section.
Attacker Value
Unknown

CVE-2023-40551

Disclosure Date: January 29, 2024 (last updated April 29, 2024)
A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive data during the system's boot phase.
Attacker Value
Unknown

CVE-2024-1008

Disclosure Date: January 29, 2024 (last updated February 01, 2024)
A vulnerability was found in SourceCodester Employee Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file edit-photo.php of the component Profile Page. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-252277 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2024-1007

Disclosure Date: January 29, 2024 (last updated February 01, 2024)
A vulnerability was found in SourceCodester Employee Management System 1.0. It has been classified as critical. Affected is an unknown function of the file edit_profile.php. The manipulation of the argument txtfullname leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252276.