‼ CVE-2023-33899 ‼
📖 Read
via "National Vulnerability Database".
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-33885 ‼
📖 Read
via "National Vulnerability Database".
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-3168 ‼
📖 Read
via "National Vulnerability Database".
The WP Reroute Email plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.4.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-30922 ‼
📖 Read
via "National Vulnerability Database".
In messaging service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-2869 ‼
📖 Read
via "National Vulnerability Database".
The WP-Members Membership plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability check on the do_field_reorder function in versions up to, and including, 3.4.7.3. This makes it possible for authenticated attackers with subscriber-level access to reorder form elements on login forms.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-4422 ‼
📖 Read
via "National Vulnerability Database".
The POST SMTP Mailer plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.0.20. This is due to missing or incorrect nonce validation on the handleCsvExport() function. This makes it possible for unauthenticated attackers to trigger a CSV export via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-30938 ‼
📖 Read
via "National Vulnerability Database".
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-2762 ‼
📖 Read
via "National Vulnerability Database".
A Use-After-Free vulnerability in SLDPRT file reading procedure exists in SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted SLDPRT file.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-33905 ‼
📖 Read
via "National Vulnerability Database".
In iwnpi server, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with System execution privileges needed.📖 Read
via "National Vulnerability Database".
‼ CVE-2021-4421 ‼
📖 Read
via "National Vulnerability Database".
The Advanced Popups plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the metabox_popup_save() function. This makes it possible for unauthenticated attackers to save meta tags via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-36760 ‼
📖 Read
via "National Vulnerability Database".
The Ocean Extra plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.6.5]. This is due to missing or incorrect nonce validation on the add_core_extensions_bundle_validation() function. This makes it possible for unauthenticated attackers to validate extension bundles via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.📖 Read
via "National Vulnerability Database".
‼ CVE-2020-36757 ‼
📖 Read
via "National Vulnerability Database".
The WP Hotel Booking plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.1. This is due to missing or incorrect nonce validation on the admin_add_order_item() function. This makes it possible for unauthenticated attackers to add an order item via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-33900 ‼
📖 Read
via "National Vulnerability Database".
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-33890 ‼
📖 Read
via "National Vulnerability Database".
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-3092 ‼
📖 Read
via "National Vulnerability Database".
The SMTP Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.2.16 due to insufficient input sanitization and output escaping when the 'Save Data SendMail' feature is enabled. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-30932 ‼
📖 Read
via "National Vulnerability Database".
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-30926 ‼
📖 Read
via "National Vulnerability Database".
In opm service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-33886 ‼
📖 Read
via "National Vulnerability Database".
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-30928 ‼
📖 Read
via "National Vulnerability Database".
In telephony service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-3106 ‼
📖 Read
via "National Vulnerability Database".
A NULL pointer dereference vulnerability was found in netlink_dump. This issue can occur when the Netlink socket receives the message(sendmsg) for the XFRM_MSG_GETSA, XFRM_MSG_GETPOLICY type message, and the DUMP flag is set and can cause a denial of service or possibly another unspecified impact. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although it is unlikely.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-3135 ‼
📖 Read
via "National Vulnerability Database".
The Mailtree Log Mail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an email subject in versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.📖 Read
via "National Vulnerability Database".