βΌ CVE-2023-45374 βΌ
π Read
via "National Vulnerability Database".
An issue was discovered in the SportsTeams extension for MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It does not check for the anti-CSRF edit token in Special:SportsTeamsManager and Special:UpdateFavoriteTeams.π Read
via "National Vulnerability Database".
βΌ CVE-2023-39854 βΌ
π Read
via "National Vulnerability Database".
The web interface of ATX Ucrypt through 3.5 allows authenticated users (or attackers using default credentials for the admin, master, or user account) to include files via a URL in the /hydra/view/get_cc_url url parameter. There can be resultant SSRF.π Read
via "National Vulnerability Database".
π¦Ώ Upgrade to Microsoft Windows 11 Home for Just $30 Through 10/15 π¦Ώ
π Read
via "Tech Republic".
You can now upgrade up to five computers to Microsoft Windows 11 Home for one low price and get a new sleek interface, advanced tools and enhanced security.π Read
via "Tech Republic".
TechRepublic
Upgrade to Microsoft Windows 11 Home for Just $10
You can now upgrade up to five computers to Microsoft Windows 11 Home for one low price and get a new sleek interface, advanced tools and enhanced security.
βΌ CVE-2023-44236 βΌ
π Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Devnath verma WP Captcha plugin <=Γ 2.0.0 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-5331 βΌ
π Read
via "National Vulnerability Database".
Mattermost fails to properly check the creator of an attached file when adding the file to a draft post,Γ potentially exposing unauthorized file information.π Read
via "National Vulnerability Database".
βΌ CVE-2023-44473 βΌ
π Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Michael Tran Table of Contents Plus plugin <=Γ 2302 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-5330 βΌ
π Read
via "National Vulnerability Database".
Mattermost fails toΓ enforce a limit for the size of the cache entry for OpenGraph data allowing an attacker to send a specially crafted request to the /api/v4/opengraph filling the cache and turning the server unavailable.π Read
via "National Vulnerability Database".
βΌ CVE-2023-45613 βΌ
π Read
via "National Vulnerability Database".
In JetBrains Ktor before 2.3.5 server certificates were not verifiedπ Read
via "National Vulnerability Database".
βΌ CVE-2023-5333 βΌ
π Read
via "National Vulnerability Database".
Mattermost fails to deduplicate input IDs allowing aΓ simple user to cause the application to consume excessive resources and possibly crash by sending a specially crafted request to /api/v4/users/ids with multiple identical IDs.π Read
via "National Vulnerability Database".
βΌ CVE-2023-44238 βΌ
π Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Joakim Ling Remove slug from custom post type plugin <=Γ 1.0.3 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-44240 βΌ
π Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Peter Butler Timthumb Vulnerability Scanner plugin <=Γ 1.54 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-44237 βΌ
π Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Moriyan Jay WP Site Protector plugin <=Γ 2.0 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-44993 βΌ
π Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in QuantumCloud AI ChatBot plugin <=Γ 4.7.8 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-45612 βΌ
π Read
via "National Vulnerability Database".
In JetBrains Ktor before 2.3.5 default configuration of ContentNegotiation with XML format was vulnerable to XXEπ Read
via "National Vulnerability Database".
βΌ CVE-2023-44246 βΌ
π Read
via "National Vulnerability Database".
Cross-Site Request Forgery (CSRF) vulnerability in Matias s Shockingly Simple Favicon plugin <=Γ 1.8.2 versions.π Read
via "National Vulnerability Database".
βΌ CVE-2023-43700 βΌ
π Read
via "National Vulnerability Database".
Missing Authorization in RDT400 in SICK APU allows an unprivileged remote attacker to modify data via HTTP requests that no not require authentication.π Read
via "National Vulnerability Database".
βΌ CVE-2023-43697 βΌ
π Read
via "National Vulnerability Database".
Modification of Assumed-Immutable Data (MAID) in RDT400 in SICK APU allows anunprivileged remote attacker to make the site unable to load necessary strings via changing file pathsusing HTTP requests.π Read
via "National Vulnerability Database".
βΌ CVE-2023-43698 βΌ
π Read
via "National Vulnerability Database".
Improper Neutralization of Input During Web Page Generation (Γ’β¬β’Cross-site ScriptingΓ’β¬β’) in RDT400 in SICK APU allows an unprivileged remote attacker to run arbitrary code in the clientsbrowser via injecting code into the website.π Read
via "National Vulnerability Database".
βΌ CVE-2023-43696 βΌ
π Read
via "National Vulnerability Database".
Improper Access Control in SICK APU allows an unprivileged remote attacker todownload as well as upload arbitrary files via anonymous access to the FTP server.π Read
via "National Vulnerability Database".
βΌ CVE-2023-5100 βΌ
π Read
via "National Vulnerability Database".
Cleartext Transmission of Sensitive Information in RDT400 in SICK APU allows anunprivileged remote attacker to retrieve potentially sensitive information via intercepting network trafficthat is not encrypted.π Read
via "National Vulnerability Database".
βΌ CVE-2023-43699 βΌ
π Read
via "National Vulnerability Database".
Improper Restriction of Excessive Authentication Attempts in RDT400 in SICK APUallows an unprivileged remote attacker to guess the password via trial-and-error as the login attemptsare not limited.π Read
via "National Vulnerability Database".