‼ CVE-2023-4098 ‼
📖 Read
via "National Vulnerability Database".
It has been identified that the web application does not correctly filter input parameters, allowing SQL injections, DoS or information disclosure. As a prerequisite, it is necessary to log into the application.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-32792 ‼
📖 Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in NXLog Manager 5.6.5633 version. This vulnerability allows an attacker to eliminate roles within the platform by sending a specifically crafted query to the server. The vulnerability is based on the absence of proper validation of the origin of incoming requests.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-40210 ‼
📖 Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Sean Barton (Tortoise IT) SB Child List plugin <=Â 4.5 versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-40202 ‼
📖 Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Hannes Etzelstorfer // codemiq WP HTML Mail plugin <=Â 3.4.1 versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-5353 ‼
📖 Read
via "National Vulnerability Database".
Improper Access Control in GitHub repository salesagility/suitecrm prior to 7.14.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-40212 ‼
📖 Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Product Attachment for WooCommerce plugin <=Â 2.1.8 versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-4101 ‼
📖 Read
via "National Vulnerability Database".
The QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary to log into the application.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-4102 ‼
📖 Read
via "National Vulnerability Database".
QSige login SSO does not have an access control mechanism to verify whether the user requesting a resource has sufficient permissions to do so. As a prerequisite, it is necessary to log into the application.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-5350 ‼
📖 Read
via "National Vulnerability Database".
SQL Injection in GitHub repository salesagility/suitecrm prior to 7.14.1.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-39159 ‼
📖 Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in theDotstore Fraud Prevention For Woocommerce plugin <=Â 2.1.5 versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-4103 ‼
📖 Read
via "National Vulnerability Database".
QSige statistics are affected by a remote SQLi vulnerability. It has been identified that the web application does not correctly filter input parameters, allowing SQL injections, DoS or information disclosure. As a prerequisite, it is necessary to log into the application.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-40198 ‼
📖 Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Antsanchez Easy Cookie Law plugin <=Â 3.1 versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-4100 ‼
📖 Read
via "National Vulnerability Database".
Allows an attacker to perform XSS attacks stored on certain resources. Exploiting this vulnerability can lead to a DoS condition, among other actions.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-32671 ‼
📖 Read
via "National Vulnerability Database".
A stored XSS vulnerability has been found on BuddyBoss Platform affecting version 2.2.9. This vulnerability allows an attacker to store a malicious javascript payload via POST request when sending an invitation.📖 Read
via "National Vulnerability Database".
👍1
‼ CVE-2023-4886 ‼
📖 Read
via "National Vulnerability Database".
A sensitive information exposure vulnerability was found in foreman. Contents of tomcat's server.xml file, which contain passwords to candlepin's keystore and truststore, were found to be world readable.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-32091 ‼
📖 Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in POEditor plugin <=Â 0.9.4 versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-40558 ‼
📖 Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in eMarket Design YouTube Video Gallery by YouTube Showcase plugin <=Â 3.3.5 versions.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-2544 ‼
📖 Read
via "National Vulnerability Database".
Authorization bypass vulnerability in UPV PEIX, affecting the component "pdf_curri_new.php". Through a POST request, an authenticated user could change the ID parameter to retrieve all the stored information of other registered users.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-4884 ‼
📖 Read
via "National Vulnerability Database".
An attacker could send an HTTP request to an Open5GS endpoint and retrieve the information stored on the device due to the lack of Authentication.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-4929 ‼
📖 Read
via "National Vulnerability Database".
All firmware versions of the NPort 5000 Series are affected by an improper validation of integrity check vulnerability. This vulnerability results from insufficient checks on firmware updates or upgrades, potentially allowing malicious users to manipulate the firmware and gain control of devices.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-41244 ‼
📖 Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Buildfail Localize Remote Images plugin <=Â 1.0.9 versions.📖 Read
via "National Vulnerability Database".