NA - CVE-2023-45880 - GibbonEdu Gibbon through version 25.0.0 allows...
GibbonEdu Gibbon through version 25.0.0 allows Directory Traversal via the report template builder. An attacker can create a new Asset Component. The templateFileDestination parameter can be set to...
NA - CVE-2023-45881 - GibbonEdu Gibbon through version 25.0.0 allows...
GibbonEdu Gibbon through version 25.0.0 allows /modules/Planner/resources_addQuick_ajaxProcess.php file upload with resultant XSS. The imageAsLinks parameter must be set to Y to return HTML code....
NA - CVE-2023-47609 - SQL injection vulnerability in OSS Calendar...
SQL injection vulnerability in OSS Calendar versions prior to v.2.0.3 allows a remote authenticated attacker to execute arbitrary code or obtain and/or alter the information stored in the database...
NA - CVE-2023-6109 - The YOP Poll plugin for WordPress is vulnerable...
The YOP Poll plugin for WordPress is vulnerable to a race condition in all versions up to, and including, 6.5.26. This is due to improper restrictions on the add() function. This makes it possible...
NA - CVE-2023-24585 - An out-of-bounds write vulnerability exists in...
An out-of-bounds write vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to memory corruption. An attacker can...
NA - CVE-2023-25181 - A heap-based buffer overflow vulnerability...
A heap-based buffer overflow vulnerability exists in the HTTP Server functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted set of network packets can lead to arbitrary code...
NA - CVE-2023-27882 - A heap-based buffer overflow vulnerability...
A heap-based buffer overflow vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution....
NA - CVE-2023-28379 - A memory corruption vulnerability exists in the...
A memory corruption vulnerability exists in the HTTP Server form boundary functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An...
NA - CVE-2023-28391 - A memory corruption vulnerability exists in the...
A memory corruption vulnerability exists in the HTTP Server header parsing functionality of Weston Embedded uC-HTTP v3.01.01. Specially crafted network packets can lead to code execution. An...
NA - CVE-2023-31247 - A memory corruption vulnerability exists in the...
A memory corruption vulnerability exists in the HTTP Server Host header parsing functionality of Weston Embedded uC-HTTP v3.01.01. A specially crafted network packet can lead to code execution. An...