‼️CVE-2023-7166‼️
📖 Read more
Via "National Vulnerability Database"
A vulnerability classified as problematic has been found in NovelPlus up to 4.2.0. This affects an unknown part of the file userupdateUserInfo of the component HTTP POST Request Handler. The manipulation of the argument nickName leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is c62da9bb3a9b3603014d0edb436146512631100d. It is recommended to apply a patch to fix this issue. The identifier VDB249201 was assigned to this vulnerability.📖 Read more
Via "National Vulnerability Database"
‼️CVE-2022-44589‼️
📖 Read more
Via "National Vulnerability Database"
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in miniOrange miniOrange's Google Authenticator WordPress Two Factor Authentication 2FA , Two Factor, OTP SMS and Email Passwordless login.This issue affects miniOrange's Google Authenticator WordPress Two Factor Authentication 2FA , Two Factor, OTP SMS and Email Passwordless login from na through 5.6.1. 📖 Read more
Via "National Vulnerability Database"
‼️CVE-2023-28786‼️
📖 Read more
Via "National Vulnerability Database"
URL Redirection to Untrusted Site 'Open Redirect' vulnerability in SolidWP Solid Security Password, Two Factor Authentication, and Brute Force Protection.This issue affects Solid Security Password, Two Factor Authentication, and Brute Force Protection from na through 8.1.4. 📖 Read more
Via "National Vulnerability Database"
‼️CVE-2023-31095‼️
📖 Read more
Via "National Vulnerability Database"
URL Redirection to Untrusted Site 'Open Redirect' vulnerability in CRM Perks Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms.This issue affects Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms from na through 1.2.8. 📖 Read more
Via "National Vulnerability Database"
‼️CVE-2023-31229‼️
📖 Read more
Via "National Vulnerability Database"
URL Redirection to Untrusted Site 'Open Redirect' vulnerability in WP Directory Kit.This issue affects WP Directory Kit from na through 1.1.9. 📖 Read more
Via "National Vulnerability Database"
‼️CVE-2023-31237‼️
📖 Read more
Via "National Vulnerability Database"
URL Redirection to Untrusted Site 'Open Redirect' vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager from na through 3.3.9. 📖 Read more
Via "National Vulnerability Database"
‼️CVE-2023-32101‼️
📖 Read more
Via "National Vulnerability Database"
URL Redirection to Untrusted Site 'Open Redirect' vulnerability in Pexle Chris Library Viewer.This issue affects Library Viewer from na through 2.0.6. 📖 Read more
Via "National Vulnerability Database"
‼️CVE-2023-32517‼️
📖 Read more
Via "National Vulnerability Database"
URL Redirection to Untrusted Site 'Open Redirect' vulnerability in PluginOps MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder.This issue affects MailChimp Subscribe Form, Optin Builder, PopUp Builder, Form Builder from na through 4.0.9.3. 📖 Read more
Via "National Vulnerability Database"
‼️CVE-2023-49830‼️
📖 Read more
Via "National Vulnerability Database"
Improper Control of Generation of Code 'Code Injection' vulnerability in Brainstorm Force Astra Pro.This issue affects Astra Pro from na through 4.3.1. 📖 Read more
Via "National Vulnerability Database"
‼️CVE-2023-4462‼️
📖 Read more
Via "National Vulnerability Database"
A vulnerability classified as problematic has been found in Poly CCX 400, CCX 600, Trio 8800 and Trio C60. This affects an unknown part of the component Web Configuration Application. The manipulation leads to insufficiently random values. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB249255.📖 Read more
Via "National Vulnerability Database"
‼️CVE-2023-4463‼️
📖 Read more
Via "National Vulnerability Database"
A vulnerability classified as problematic was found in Poly CCX 400, CCX 600, Trio 8800 and Trio C60. This vulnerability affects unknown code of the component HTTP Header Handler. The manipulation of the argument Cookie leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB249256.📖 Read more
Via "National Vulnerability Database"
‼️CVE-2023-4464‼️
📖 Read more
Via "National Vulnerability Database"
A vulnerability, which was classified as critical, has been found in Poly CCX 400, CCX 600, Trio 8800 and Trio C60. This issue affects some unknown processing of the component Diagnostic Telnet Mode. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The identifier VDB249257 was assigned to this vulnerability.📖 Read more
Via "National Vulnerability Database"
‼️CVE-2023-4465‼️
📖 Read more
Via "National Vulnerability Database"
A vulnerability, which was classified as problematic, was found in Poly CCX 400, CCX 600, Trio 8800 and Trio C60. Affected is an unknown function of the component Configuration File Import. The manipulation of the argument device.auth.localAdminPassword leads to unverified password change. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB249258 is the identifier assigned to this vulnerability.📖 Read more
Via "National Vulnerability Database"
‼️CVE-2023-4466‼️
📖 Read more
Via "National Vulnerability Database"
A vulnerability has been found in Poly CCX 400, CCX 600, Trio 8800 and Trio C60 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Web Interface. The manipulation leads to protection mechanism failure. The attack can be launched remotely. The vendor explains that they do not regard this as a vulnerability as this is a feature that they offer to their customers who have a variety of environmental needs that are met through different firmware builds. To avoid potential rollback attacks, they remove vulnerable builds from the public servers as a remediation effort. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB249259.📖 Read more
Via "National Vulnerability Database"
‼️CVE-2023-4467‼️
📖 Read more
Via "National Vulnerability Database"
A vulnerability was found in Poly Trio 8800 7.2.6.0019 and classified as critical. Affected by this issue is some unknown functionality of the component Test Automation Mode. The manipulation leads to backdoor. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB249260.📖 Read more
Via "National Vulnerability Database"
‼️CVE-2023-4468‼️
📖 Read more
Via "National Vulnerability Database"
A vulnerability was found in Poly Trio 8800 and Trio C60. It has been classified as problematic. This affects an unknown part of the component Poly Lens Management Cloud Registration. The manipulation leads to missing authorization. It is possible to launch the attack on the physical device. The exploit has been disclosed to the public and may be used. The identifier VDB249261 was assigned to this vulnerability.📖 Read more
Via "National Vulnerability Database"
‼️CVE-2023-51420‼️
📖 Read more
Via "National Vulnerability Database"
Improper Control of Generation of Code 'Code Injection' vulnerability in Soft8Soft LLC Verge3D Publishing and ECommerce.This issue affects Verge3D Publishing and ECommerce from na through 4.5.2. 📖 Read more
Via "National Vulnerability Database"
‼️CVE-2023-7104‼️
📖 Read more
Via "National Vulnerability Database"
A vulnerability was found in SQLite SQLite3 up to 3.43.0 and classified as critical. This issue affects the function sessionReadRecord of the file extsessionsqlite3session.c of the component make alltest Handler. The manipulation leads to heapbased buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB248999.📖 Read more
Via "National Vulnerability Database"
‼️CVE-2023-50896‼️
📖 Read more
Via "National Vulnerability Database"
Improper Neutralization of Input During Web Page Generation 'Crosssite Scripting' vulnerability in weForms weForms Easy Drag Drop Contact Form Builder For WordPress allows Stored XSS.This issue affects weForms Easy Drag Drop Contact Form Builder For WordPress from na through 1.6.17. 📖 Read more
Via "National Vulnerability Database"
‼️CVE-2023-50901‼️
📖 Read more
Via "National Vulnerability Database"
Improper Neutralization of Input During Web Page Generation 'Crosssite Scripting' vulnerability in HasThemes HT Mega Absolute Addons For Elementor allows Reflected XSS.This issue affects HT Mega Absolute Addons For Elementor from na through 2.3.8. 📖 Read more
Via "National Vulnerability Database"
‼️CVE-2023-51361‼️
📖 Read more
Via "National Vulnerability Database"
Improper Neutralization of Input During Web Page Generation 'Crosssite Scripting' vulnerability in Ginger Plugins Sticky Chat Widget Click to chat, SMS, Email, Messages, Call Button, Live Chat and Live Support Button allows Stored XSS.This issue affects Sticky Chat Widget Click to chat, SMS, Email, Messages, Call Button, Live Chat and Live Support Button from na through 1.1.8. 📖 Read more
Via "National Vulnerability Database"