CVE-2023-20575 |
Description:
A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SEV VM potentially resulting in a leak of sensitive information.
CVSS: LOW (0.0) EPSS Score: 0.06%
November 28th, 2024 (5 months ago)
|
CVE-2023-2032 |
Description: The Custom 404 Pro WordPress plugin before 3.8.1 does not properly sanitize database inputs, leading to multiple SQL Injection vulnerabilities.
CVSS: LOW (0.0) EPSS Score: 0.21%
November 28th, 2024 (5 months ago)
|
CVE-2023-1891 |
Description: The Accordion & FAQ WordPress plugin before 1.9.9 does not escape various generated URLs, before outputting them in attributes when some notices are displayed, leading to Reflected Cross-Site Scripting
CVSS: LOW (0.0) EPSS Score: 0.07%
November 28th, 2024 (5 months ago)
|
CVE-2023-1783 |
Description: OrangeScrum version 2.0.11 allows an external attacker to remotely obtain AWS instance credentials. This is possible because the application does not properly validate the HTML content to be converted to PDF.
CVSS: MEDIUM (6.5) EPSS Score: 0.11%
November 28th, 2024 (5 months ago)
|
CVE-2023-1724 |
Description: Faveo Helpdesk Enterprise version 6.0.1 allows an attacker with agent permissions to perform privilege escalation on the application. This occurs because the application is vulnerable to stored XSS.
CVSS: HIGH (7.3) EPSS Score: 0.08%
November 28th, 2024 (5 months ago)
|
CVE-2023-1722 |
Description: Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does not correctly validate the thumbnails of the classes uploaded by the administrators.
CVSS: CRITICAL (9.1) EPSS Score: 0.23%
November 28th, 2024 (5 months ago)
|
CVE-2023-1721 |
Description: Yoga Class Registration System version 1.0 allows an administrator to execute commands on the server. This is possible because the application does not correctly validate the thumbnails of the classes uploaded by the administrators.
CVSS: CRITICAL (9.1) EPSS Score: 0.21%
November 28th, 2024 (5 months ago)
|
CVE-2023-1695 |
|
CVE-2023-1166 |
Description: The USM-Premium WordPress plugin before 16.3 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).
CVSS: LOW (0.0) EPSS Score: 0.06%
November 28th, 2024 (5 months ago)
|
CVE-2023-0873 |
Description: The Kanban Boards for WordPress plugin before 2.5.21 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
CVSS: LOW (0.0) EPSS Score: 0.06%
November 28th, 2024 (5 months ago)
|