Aggregator
Play
2 months 2 weeks ago
cohenido
Play
2 months 2 weeks ago
cohenido
Play
2 months 2 weeks ago
cohenido
CVE-2023-24816 | IPython up to 8.0.x on Windows set_term_title os command injection (GHSA-29gw-9793-fvw7)
2 months 2 weeks ago
A vulnerability was found in IPython up to 8.0.x on Windows. It has been rated as critical. Affected by this issue is the function set_term_title. The manipulation leads to os command injection.
This vulnerability is handled as CVE-2023-24816. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-23286 | Provide up to 14.4 Login Form Username cross site scripting (EDB-51264)
2 months 2 weeks ago
A vulnerability was found in Provide up to 14.4. It has been rated as problematic. This issue affects some unknown processing of the component Login Form. The manipulation of the argument Username leads to cross site scripting.
The identification of this vulnerability is CVE-2023-23286. The attack may be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2023-21794 | Microsoft Edge authentication spoofing
2 months 2 weeks ago
A vulnerability was found in Microsoft Edge. It has been classified as problematic. Affected is an unknown function. The manipulation leads to authentication bypass by spoofing.
This vulnerability is traded as CVE-2023-21794. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-0732 | SourceCodester Online Eyewear Shop 1.0 POST Request oews/classes/Users.php registration firstname/middlename/lastname/email/contact cross site scripting
2 months 2 weeks ago
A vulnerability has been found in SourceCodester Online Eyewear Shop 1.0 and classified as problematic. Affected by this vulnerability is the function registration of the file oews/classes/Users.php of the component POST Request Handler. The manipulation of the argument firstname/middlename/lastname/email/contact leads to cross site scripting.
This vulnerability is known as CVE-2023-0732. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2023-0621 | Horner Automation Cscape Envision RV 4.60 HMI File out-of-bounds (icsa-23-040-04)
2 months 2 weeks ago
A vulnerability was found in Horner Automation Cscape Envision RV 4.60. It has been rated as critical. Affected by this issue is some unknown functionality of the component HMI File Handler. The manipulation leads to out-of-bounds read.
This vulnerability is handled as CVE-2023-0621. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-23161 | Art Gallery Management System 1.0 Navigation Bar artname cross site scripting (EDB-51214)
2 months 2 weeks ago
A vulnerability has been found in Art Gallery Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Navigation Bar. The manipulation of the argument artname leads to cross site scripting.
This vulnerability is known as CVE-2023-23161. The attack can be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2023-0622 | Horner Automation Cscape Envision RV 4.60 HMI File Parser out-of-bounds write (icsa-23-040-04)
2 months 2 weeks ago
A vulnerability classified as critical has been found in Horner Automation Cscape Envision RV 4.60. This affects an unknown part of the component HMI File Parser. The manipulation leads to out-of-bounds write.
This vulnerability is uniquely identified as CVE-2023-0622. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-4830 | Paid Memberships Pro Plugin up to 2.9.8 on WordPress Shortcode Attribute cross site scripting
2 months 2 weeks ago
A vulnerability, which was classified as problematic, has been found in Paid Memberships Pro Plugin up to 2.9.8 on WordPress. This issue affects some unknown processing of the component Shortcode Attribute Handler. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2022-4830. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-0034 | JetWidgets for Elementor Plugin up to 1.0.13 on WordPress Shortcode Attribute cross site scripting
2 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in JetWidgets for Elementor Plugin up to 1.0.13 on WordPress. Affected is an unknown function of the component Shortcode Attribute Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2023-0034. It is possible to launch the attack remotely. There is no exploit available.
vuldb.com
CVE-2023-0623 | Horner Automation Cscape Envision RV 4.60 HMI File out-of-bounds write (icsa-23-040-04)
2 months 2 weeks ago
A vulnerability classified as critical was found in Horner Automation Cscape Envision RV 4.60. This vulnerability affects unknown code of the component HMI File Handler. The manipulation leads to out-of-bounds write.
This vulnerability was named CVE-2023-0623. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2022-48110 | CKSource CKEditor5 35.4.0 Widget cross site scripting (ID 170927 / EDB-51260)
2 months 2 weeks ago
A vulnerability was found in CKSource CKEditor5 35.4.0. It has been declared as problematic. This vulnerability affects unknown code of the component Widget. The manipulation leads to cross site scripting.
This vulnerability was named CVE-2022-48110. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2023-23529 | Apple iOS/iPadOS up to 16.3.0 WebKit type confusion (HT213635)
2 months 2 weeks ago
A vulnerability has been found in Apple iOS and iPadOS up to 16.3.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the component WebKit. The manipulation leads to type confusion.
This vulnerability is known as CVE-2023-23529. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Basic SQL Commands
2 months 2 weeks ago
Basic SQL Commands
Dark Web Informer - Cyber Threat Intelligence
CVE-2023-23529 | Apple macOS up to 13.2.0 WebKit type confusion (HT213633)
2 months 2 weeks ago
A vulnerability was found in Apple macOS up to 13.2.0. It has been declared as critical. This vulnerability affects unknown code of the component WebKit. The manipulation leads to type confusion.
This vulnerability was named CVE-2023-23529. The attack can be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2023-21716 | Microsoft Word wwlib Remote Code Execution
2 months 2 weeks ago
A vulnerability was found in Microsoft Word. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component wwlib. The manipulation leads to Remote Code Execution.
This vulnerability is known as CVE-2023-21716. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-0475 | HashiCorp go-getter up to 1.6.2/2.1.1 data amplification (Nessus ID 214662)
2 months 2 weeks ago
A vulnerability, which was classified as problematic, was found in HashiCorp go-getter up to 1.6.2/2.1.1. Affected is an unknown function. The manipulation leads to highly compressed data.
This vulnerability is traded as CVE-2023-0475. The attack needs to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com