CVE-2023-2480
Missing access permissions checks in M-Files Client before 23.5.12598.0 allows elevation of privilege via UI extension applications
Source: CVE-2023-2480
CVE-2023-2480
Missing access permissions checks in M-Files Client before 23.5.12598.0 allows elevation of privilege via UI extension applications
Source: CVE-2023-2480
CVE-2023-33355
IceCMS v1.0.0 has Insecure Permissions. There is unauthorized access to the API, resulting in the disclosure of sensitive information.
Source: CVE-2023-33355
CVE-2023-2851
** UNSUPPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability in AGT Tech Ceppatron allows Command Line Execution through SQL Injection, SQL Injection.This issue affects all versions of the sofware also EOS when CVE-ID assigned.
Source: CVE-2023-2851
CVE-2023-0459
Copy_from_user on 64-bit versions of the Linux kernel does not implement the __uaccess_begin_nospec allowing a user to bypass the "access_ok" check and pass a kernel pointer to copy_from_user(). This would allow an attacker to leak information. We recommend upgrading beyond commit 74e19ef0ff8061ef55957c3abd71614ef0f42f47
Source: CVE-2023-0459
CVE-2023-22504
Affected versions of Atlassian Confluence Server allow remote attackers who have read permissions to a page, but not write permissions, to upload attachments via a Broken Access Control vulnerability in the attachments feature.
The affected versions are before version 7.19.9.
This vulnerability was discovered by Rojan Rijal of the Tinder Security Engineering Team.
Source: CVE-2023-22504
CVE-2023-2888
A vulnerability, which was classified as problematic, was found in PHPOK 6.4.100. This affects an unknown part of the file /admin.php?c=upload&f=zip&_noCache=0.1683794968. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The identifier VDB-229953 was assigned to this vulnerability.
Source: CVE-2023-2888
CVE-2022-47174
Cross-Site Request Forgery (CSRF) vulnerability in WordPress Performance Team Performance Lab plugin <=Â 2.2.0 versions.
Source: CVE-2022-47174
CVE-2022-45366
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Jason Crouse, VeronaLabs Slimstat Analytics plugin <=Â 5.0.4 versions.
Source: CVE-2022-45366
CVE-2022-47144
Cross-Site Request Forgery (CSRF) vulnerability in Plugincraft Mediamatic – Media Library Folders plugin <= 2.8.1 versions.
Source: CVE-2022-47144
CVE-2022-46856
Cross-Site Request Forgery (CSRF) vulnerability in ORION Woocommerce Products Designer plugin <=Â 4.3.3 versions.
Source: CVE-2022-46856