โผ CVE-2023-2951 โผ
๐ Read
via "National Vulnerability Database".
A vulnerability classified as critical has been found in code-projects Bus Dispatch and Information System 1.0. Affected is an unknown function of the file delete_bus.php. The manipulation of the argument busid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-230112.๐ Read
via "National Vulnerability Database".
๐1
โผ CVE-2014-125101 โผ
๐ Read
via "National Vulnerability Database".
A vulnerability classified as critical has been found in Portfolio Gallery Plugin up to 1.1.8 on WordPress. This affects an unknown part. The manipulation leads to sql injection. It is possible to initiate the attack remotely. Upgrading to version 1.1.9 is able to address this issue. The name of the patch is 58ed88243e17df766036f4857041edaf358076d3. It is recommended to upgrade the affected component. The identifier VDB-230085 was assigned to this vulnerability.๐ Read
via "National Vulnerability Database".
๐2๐ฅ1
โผ CVE-2023-33216 โผ
๐ Read
via "National Vulnerability Database".
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in gVectors Team WooDiscuz รขโฌโ WooCommerce Comments woodiscuz-woocommerce-comments allows Stored XSS.This issue affects WooDiscuz รขโฌโ WooCommerce Comments: from n/a through 2.2.9.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-33315 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Stephen Darlington, Wandle Software Limited Smart App Banner plugin <=ร 1.1.2 versions.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-32800 โผ
๐ Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in One Rank Math SEO PRO plugin <=ร 3.0.35 versions.๐ Read
via "National Vulnerability Database".
โค1
โผ CVE-2023-33926 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Easy Google Maps plugin <=ร 1.11.7 versions.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-31873 โผ
๐ Read
via "National Vulnerability Database".
Gin 0.7.4 allows execution of arbitrary code when a crafted file is opened, e.g., via require('child_process').๐ Read
via "National Vulnerability Database".
โค1
โผ CVE-2023-32763 โผ
๐ Read
via "National Vulnerability Database".
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. When a SVG file with an image inside it is rendered, a QTextLayout buffer overflow can be triggered.๐ Read
via "National Vulnerability Database".
โค1
โผ CVE-2023-29380 โผ
๐ Read
via "National Vulnerability Database".
Warpinator before 1.6.0 allows remote file deletion via directory traversal in top_dir_basenames.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-45372 โผ
๐ Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Codeixer Product Gallery Slider for WooCommerce plugin <=ร 2.2.8 versions.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-2954 โผ
๐ Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository liangliangyy/djangoblog prior to master.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-2955 โผ
๐ Read
via "National Vulnerability Database".
A vulnerability, which was classified as critical, was found in SourceCodester Students Online Internship Timesheet System 1.0. Affected is an unknown function of the file rendered_report.php of the component GET Parameter Handler. The manipulation of the argument sid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-230142 is the identifier assigned to this vulnerability.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-2808 โผ
๐ Read
via "National Vulnerability Database".
Mattermost fails to normalize UTF confusable characters when determining if a preview should be generated for a hyperlink, allowing an attacker to trigger link preview on a disallowed domain using a specially crafted link.๐ Read
via "National Vulnerability Database".
๐ด Top Cyberattacks Revealed in New Threat Intelligence Report ๐ด
๐ Read
via "Dark Reading".
New report provides actionable intelligence about attacks, threat actors, and campaigns.๐ Read
via "Dark Reading".
Dark Reading
Top Cyberattacks Revealed in New Threat Intelligence Report
New report provides actionable intelligence about attacks, threat actors, and campaigns.
โค1๐1
โผ CVE-2023-27613 โผ
๐ Read
via "National Vulnerability Database".
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in MonitorClick Forms Ada รขโฌโ Form Builder plugin <=ร 1.0 versions.๐ Read
via "National Vulnerability Database".
โผ CVE-2023-2962 โผ
๐ Read
via "National Vulnerability Database".
A vulnerability, which was classified as critical, has been found in SourceCodester Faculty Evaluation System 1.0. Affected by this issue is some unknown functionality of the file index.php?page=edit_user. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-230150 is the identifier assigned to this vulnerability.๐ Read
via "National Vulnerability Database".
๐1
โผ CVE-2022-32696 โผ
๐ Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-32711 โผ
๐ Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-32735 โผ
๐ Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-32722 โผ
๐ Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.๐ Read
via "National Vulnerability Database".
โผ CVE-2022-32677 โผ
๐ Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2022. Notes: none.๐ Read
via "National Vulnerability Database".