‼ CVE-2023-5351 ‼
📖 Read
via "National Vulnerability Database".
Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm prior to 7.14.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-39923 ‼
📖 Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in RadiusTheme The Post Grid plugin <=Â 7.2.7 versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-4098 ‼
📖 Read
via "National Vulnerability Database".
It has been identified that the web application does not correctly filter input parameters, allowing SQL injections, DoS or information disclosure. As a prerequisite, it is necessary to log into the application.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-32792 ‼
📖 Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in NXLog Manager 5.6.5633 version. This vulnerability allows an attacker to eliminate roles within the platform by sending a specifically crafted query to the server. The vulnerability is based on the absence of proper validation of the origin of incoming requests.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-40210 ‼
📖 Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Sean Barton (Tortoise IT) SB Child List plugin <=Â 4.5 versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-40202 ‼
📖 Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Hannes Etzelstorfer // codemiq WP HTML Mail plugin <=Â 3.4.1 versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-5353 ‼
📖 Read
via "National Vulnerability Database".
Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-40212 ‼
📖 Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Product Attachment for WooCommerce plugin <=Â 2.1.8 versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-4101 ‼
📖 Read
via "National Vulnerability Database".
The QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary to log into the application.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-4102 ‼
📖 Read
via "National Vulnerability Database".
QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary to log into the application.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-5350 ‼
📖 Read
via "National Vulnerability Database".
SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-39159 ‼
📖 Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Fraud Prevention For Woocommerce plugin <=Â 2.1.5 versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-4103 ‼
📖 Read
via "National Vulnerability Database".
QSige statistics are affected by a remote SQLi vulnerability. It has been identified that the web application does not correctly filter input parameters, allowing SQL injections, DoS or information disclosure. As a prerequisite, it is necessary to log into the application.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-40198 ‼
📖 Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Antsanchez Easy Cookie Law plugin <=Â 3.1 versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-4100 ‼
📖 Read
via "National Vulnerability Database".
Allows an attacker to perform XSS attacks stored on certain resources. Exploiting this vulnerability can lead to a DoS condition, among other actions.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-32671 ‼
📖 Read
via "National Vulnerability Database".
A stored XSS vulnerability has been found on BuddyBoss Platform affecting version 2.2.9. This vulnerability allows an attacker to store a malicious javascript payload via POST request when sending an invitation.📖 Read
via "National Vulnerability Database".
👍1
‼ CVE-2023-4886 ‼
📖 Read
via "National Vulnerability Database".
A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain passwords to candlepin's keystore and truststore, were found to be world readable.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-32091 ‼
📖 Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in POEditor plugin <=Â 0.9.4 versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-40558 ‼
📖 Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in eMarket Design YouTube Video Gallery by YouTube Showcase plugin <=Â 3.3.5 versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-2544 ‼
📖 Read
via "National Vulnerability Database".
Authorization bypass vulnerability in UPV PEIX, affecting the component "pdf_curri_new.php". Through a POST request, an authenticated user could change the ID parameter to retrieve all the stored information of other registered users.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-4884 ‼
📖 Read
via "National Vulnerability Database".
An attacker could send an HTTP request to an Open5GS endpoint and retrieve the information stored on the device due to the lack of Authentication.📖 Read
via "National Vulnerability Database".