CVE-2023-34597

A vulnerability in Fibaro Motion Sensor firmware v3.4 allows attackers to cause a Denial of Service (DoS) via a crafted Z-Wave message.Read More ...

Continue Reading
CVE-2023-35098

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in John Brien WordPress NextGen GalleryView plugin Read More ...

Continue Reading
CVE-2023-35097

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Internet Marketing Dojo WP Affiliate Links plugin Read More ...

Continue Reading
CVE-2023-3325

The CMS Commander plugin for WordPress is vulnerable to authorization bypass due to the use of an insufficiently unique cryptographic signature on the 'cmsc_add_site' function in versions up to, and i ...

Continue Reading

CVSS3 - HIGH

CVSS2 - MEDIUM

CVE-2023-35884

Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in EventPrime plugin Read More ...

Continue Reading
CVE-2023-26427

Default permissions for a properties file were too permissive. Local system users could read potentially sensitive information. We updated the default permissions for noreply.properties set during pac ...

Continue Reading
CVE-2023-26434

When adding an external mail account, processing of POP3 "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue POP3 service could trigger requests that lead to e ...

Continue Reading
CVE-2023-26433

When adding an external mail account, processing of IMAP "capabilities" responses are not limited to plausible sizes. Attacker with access to a rogue IMAP service could trigger requests that lead to e ...

Continue Reading

Back to Main

Subscribe for the latest news: