βΌ CVE-2023-3708 βΌ
π Read
via "National Vulnerability Database".
Several themes for WordPress by DeoThemes are vulnerable to Reflected Cross-Site Scripting via breadcrumbs in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.π Read
via "National Vulnerability Database".
βΌ CVE-2023-38429 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/connection.c in ksmbd has an off-by-one error in memory allocation (because of ksmbd_smb2_check_message) that may lead to out-of-bounds access.π Read
via "National Vulnerability Database".
βΌ CVE-2023-3459 βΌ
π Read
via "National Vulnerability Database".
The Export and Import Users and Customers plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'hf_update_customer' function called via an AJAX action in versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with shop manager-level permissions to change user passwords and potentially take over administrator accounts.π Read
via "National Vulnerability Database".
βΌ CVE-2020-36695 βΌ
π Read
via "National Vulnerability Database".
Incorrect Default Permissions vulnerability in Hitachi Device Manager on Linux (Device Manager Server component), Hitachi Tiered Storage Manager on Linux, Hitachi Replication Manager on Linux, Hitachi Tuning Manager on Linux (Hitachi Tuning Manager server, Hitachi Tuning Manager - Agent for RAID, Hitachi Tuning Manager - Agent for NAS components), Hitachi Compute Systems Manager on Linux allows File Manipulation.This issue affects Hitachi Device Manager: before 8.8.5-02; Hitachi Tiered Storage Manager: before 8.8.5-02; Hitachi Replication Manager: before 8.8.5-02; Hitachi Tuning Manager: before 8.8.5-02; Hitachi Compute Systems Manager: before 8.8.3-08.π Read
via "National Vulnerability Database".
βΌ CVE-2023-31998 βΌ
π Read
via "National Vulnerability Database".
A heap overflow vulnerability found in EdgeRouters and Aircubes allows a malicious actor to interrupt UPnP service to said devices.π Read
via "National Vulnerability Database".
π’ Warning issued over βincompleteβ fix for Adobe ColdFusion vulnerability π’
π Read
via "ITPro".
An incomplete fix for a vulnerability disclosure could be placing users at risk, researchers warned π Read
via "ITPro".
ITPro
Warning issued over βincompleteβ fix for Adobe ColdFusion vulnerability
An incomplete fix for a vulnerability disclosure could be placing users at risk, researchers warned
βΌ CVE-2022-46857 βΌ
π Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in SiteAlert plugin <=Γ 1.9.7 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-25482 βΌ
π Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Mike Martel WP Tiles plugin <=Γ 1.1.2 versions.π Read
via "National Vulnerability Database".
β€1
βΌ CVE-2023-3743 βΌ
π Read
via "National Vulnerability Database".
Ap Page Builder, in versions lower than 1.7.8.2, could allow a remote attacker to send a specially crafted SQL query to the product_one_img parameter to retrieve the information stored in the database.π Read
via "National Vulnerability Database".
βΌ CVE-2023-37973 βΌ
π Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in David Pokorny Replace Word plugin <=Γ 2.1 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2018-25088 βΌ
π Read
via "National Vulnerability Database".
A vulnerability, which was classified as critical, was found in Blue Yonder postgraas_server up to 2.0.0b2. Affected is the function _create_pg_connection/create_postgres_db of the file postgraas_server/backends/postgres_cluster/postgres_cluster_driver.py of the component PostgreSQL Backend Handler. The manipulation leads to sql injection. Upgrading to version 2.0.0 is able to address this issue. The patch is identified as 7cd8d016edc74a78af0d81c948bfafbcc93c937c. It is recommended to upgrade the affected component. VDB-234246 is the identifier assigned to this vulnerability.π Read
via "National Vulnerability Database".
βΌ CVE-2023-23660 βΌ
π Read
via "National Vulnerability Database".
Auth. (subscriber+) SQL Injection (SQLi) vulnerability in MainWP MainWP Maintenance Extension plugin <=Γ 4.1.1 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-25473 βΌ
π Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Miro Mannino Flickr Justified Gallery plugin <=Γ 3.5 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-37386 βΌ
π Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Media Library Helper plugin <=Γ 1.2.0 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-38326 βΌ
π Read
via "National Vulnerability Database".
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none.π Read
via "National Vulnerability Database".
βΌ CVE-2023-37387 βΌ
π Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme Classified Listing plugin <=Γ 2.4.5 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-25475 βΌ
π Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Vladimir Prelovac Smart YouTube PRO plugin <=Γ 4.3 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-37892 βΌ
π Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Kemal YAZICI - PluginPress Shortcode IMDB plugin <=Γ 6.0.8 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-25036 βΌ
π Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in akhlesh-nagar, a.Ankit Social Media Icons Widget plugin <=Γ 1.6 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2022-47169 βΌ
π Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in StaxWP Visibility Logic for Elementor plugin <=Γ 2.3.4 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2022-45828 βΌ
π Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in NooTheme Noo Timetable plugin <=Γ 2.1.3 versions.π Read
via "National Vulnerability Database".