CVE-2023-1702
Cross-site Scripting (XSS) – Generic in GitHub repository pimcore/pimcore prior to 10.5.20.
Source: CVE-2023-1702
CVE-2023-1702
Cross-site Scripting (XSS) – Generic in GitHub repository pimcore/pimcore prior to 10.5.20.
Source: CVE-2023-1702
CVE-2023-1703
Cross-site Scripting (XSS) – Generic in GitHub repository pimcore/pimcore prior to 10.5.20.
Source: CVE-2023-1703
CVE-2023-1704
Cross-site Scripting (XSS) – Stored in GitHub repository pimcore/pimcore prior to 10.5.20.
Source: CVE-2023-1704
CVE-2023-28892
Malwarebytes AdwCleaner 8.4.0 runs as Administrator and performs an insecure file delete operation on C:AdwCleanerLogsAdwCleaner_Debug.log in which the target location is user-controllable, allowing a non-admin user to escalate privileges to SYSTEM via a symbolic link.
Source: CVE-2023-28892
CVE-2023-1575
The Mega Main Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via some of its settings parameters in versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Source: CVE-2023-1575
CVE-2023-26982
Trudesk v1.2.6 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Add Tags parameter under the Create Ticket function.
Source: CVE-2023-26982
CVE-2023-1680
A vulnerability, which was classified as problematic, has been found in Xunrui CMS 4.61. This issue affects some unknown processing of the file /dayrui/My/View/main.html. The manipulation leads to information disclosure. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-224237 was assigned to this vulnerability.
Source: CVE-2023-1680
CVE-2023-1663
Coverity versions prior to 2023.3.2 are vulnerable to forced browsing, which exposes authenticated resources to unauthorized actors. The root cause of this vulnerability is an insecurely configured servlet mapping for the underlying Apache Tomcat server. As a result, the downloads directory and its contents are accessible. 5.9 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L/E:P/RL:O/RC:C)
Source: CVE-2023-1663
CVE-2023-23861
Cross-Site Request Forgery (CSRF) vulnerability in German Mesky GMAce plugin <= 1.5.2 versions.
Source: CVE-2023-23861
CVE-2022-48433
In JetBrains IntelliJ IDEA before 2023.1 the NTLM hash could leak through an API method used in the IntelliJ IDEA built-in web server.
Source: CVE-2022-48433