‼ CVE-2023-2242 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability has been found in SourceCodester Online Computer and Laptop Store 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component GET Parameter Handler. The manipulation of the argument c/s leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-227227.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-2239 ‼
📖 Read
via "National Vulnerability Database".
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository microweber/microweber prior to 1.3.4.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-2245 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in hansunCMS 1.4.3. It has been declared as critical. This vulnerability affects unknown code of the file /ueditor/net/controller.ashx?action=catchimage. The manipulation leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-227230 is the identifier assigned to this vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-2244 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been classified as critical. This affects an unknown part of the file /admin/orders/update_status.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-227229 was assigned to this vulnerability.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-44582 ‼
📖 Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Apptivo Apptivo Business Site CRM plugin <=Â 3.0.12 versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-44631 ‼
📖 Read
via "National Vulnerability Database".
Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in 1app Technologies, Inc 1app Business Forms plugin <=Â 1.0.0 versions.📖 Read
via "National Vulnerability Database".
👍1
‼ CVE-2023-23879 ‼
📖 Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Nicolas Zeh PHP Execution plugin <=Â 1.0.0 versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-45074 ‼
📖 Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Paramveer Singh for Arete IT Private Limited Activity Reactions For Buddypress plugin <=Â 1.0.22 versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2022-45080 ‼
📖 Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in KrishaWeb Add Multiple Marker plugin <=Â 1.2 versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-22686 ‼
📖 Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in TriniTronic Nice PayPal Button Lite plugin <=Â 1.3.5 versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-2246 ‼
📖 Read
via "National Vulnerability Database".
A vulnerability has been found in SourceCodester Online Pizza Ordering System 1.0 and classified as critical. This vulnerability affects unknown code of the file admin/ajax.php?action=save_settings. The manipulation of the argument img leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-227236.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-31043 ‼
📖 Read
via "National Vulnerability Database".
EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and redacting was configured with edb_filter_log.redact_password_commands. The fixed versions are 10.23.33, 11.18.29, 12.13.17, 13.9.13, and 14.6.0.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-23753 ‼
📖 Read
via "National Vulnerability Database".
The 'Visforms Base Package for Joomla 3' extension is vulnerable to SQL Injection as concatenation is used to construct an SQL Query. An attacker can interact with the database and could be able to read, modify and delete data on it.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-31061 ‼
📖 Read
via "National Vulnerability Database".
Repetier Server through 1.4.10 does not have CSRF protection.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-31060 ‼
📖 Read
via "National Vulnerability Database".
Repetier Server through 1.4.10 executes as SYSTEM. This can be leveraged in conjunction with CVE-2023-31059 for full compromise.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-31059 ‼
📖 Read
via "National Vulnerability Database".
Repetier Server through 1.4.10 allows ..%5c directory traversal for reading files that contain credentials, as demonstrated by connectionLost.php.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-31056 ‼
📖 Read
via "National Vulnerability Database".
CloverDX before 5.17.3 writes passwords to the audit log in certain situations, if the audit log is enabled and single sign-on is not employed. The fixed versions are 5.15.4, 5.16.2, 5.17.3, and 6.0.x.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25131 ‼
📖 Read
via "National Vulnerability Database".
Use of default password vulnerability in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 64bit v4.8.6 and earlier, PowerPanel Business Management for Linux 32bit v4.8.6 and earlier, PowerPanel Business Management for Linux 64bit v4.8.6 and earlier, PowerPanel Business Local/Remote for MacOS v4.8.6 and earlier, and PowerPanel Business Management for MacOS v4.8.6 and earlier allows remote attackers to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not ask the user to change the 'admin' password.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25132 ‼
📖 Read
via "National Vulnerability Database".
Unrestricted upload of file with dangerous type vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 64bit v4.8.6 and earlier, PowerPanel Business Management for Linux 32bit v4.8.6 and earlier, PowerPanel Business Management for Linux 64bit v4.8.6 and earlier, PowerPanel Business Local/Remote for MacOS v4.8.6 and earlier, and PowerPanel Business Management for MacOS v4.8.6 and earlier allows remote attackers to execute operation system commands via unspecified vectors.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-25133 ‼
📖 Read
via "National Vulnerability Database".
Improper privilege management vulnerability in default.cmd file in PowerPanel Business Local/Remote for Windows v4.8.6 and earlier, PowerPanel Business Management for Windows v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 32bit v4.8.6 and earlier, PowerPanel Business Local/Remote for Linux 64bit v4.8.6 and earlier, PowerPanel Business Management for Linux 32bit v4.8.6 and earlier, PowerPanel Business Management for Linux 64bit v4.8.6 and earlier, PowerPanel Business Local/Remote for MacOS v4.8.6 and earlier, and PowerPanel Business Management for MacOS v4.8.6 and earlier allows remote attackers to execute operation system commands via unspecified vectors.📖 Read
via "National Vulnerability Database".
🕴 Zimperium Launches Unified Mobile Security Platform for Threat Detection, Visibility, and Response 🕴
📖 Read
via "Dark Reading".
Integrated platform enables enterprises to seamlessly execute their mobile-first security strategy.📖 Read
via "Dark Reading".
Dark Reading
Zimperium Launches Unified Mobile Security Platform for Threat Detection, Visibility, and Response
Integrated platform enables enterprises to seamlessly execute their mobile-first security strategy.