NA - CVE-2023-42325 - Cross Site Scripting (XSS) vulnerability in...
Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the status_logs_filter_dynamic.php page.
NA - CVE-2023-42327 - Cross Site Scripting (XSS) vulnerability in...
Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page.
NA - CVE-2023-6006 - This vulnerability allows local attackers to...
This vulnerability allows local attackers to escalate privileges on affected installations of PaperCut NG. An attacker must first obtain the ability to execute low-privileged code on the target...
NA - CVE-2023-42326 - An issue in Netgate pfSense v.2.7.0 allows a...
An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components.
NA - CVE-2023-43900 - Insecure Direct Object References (IDOR) in...
Insecure Direct Object References (IDOR) in EMSigner v2.8.7 allow attackers to gain unauthorized access to application content and view sensitive data of other users via manipulation of the...
NA - CVE-2023-43901 - Incorrect access control in the AdHoc User...
Incorrect access control in the AdHoc User creation form of EMSigner v2.8.7 allows unauthenticated attackers to arbitrarily modify usernames and privileges by using the email address of a...
NA - CVE-2023-43902 - Incorrect access control in the Forgot Your...
Incorrect access control in the Forgot Your Password function of EMSigner v2.8.7 allows unauthenticated attackers to access accounts of all registered users, including those with administrator...