Security
Headlines
HeadlinesLatestCVEs

Source

CVE

CVE-2023-40656: QuickForm, by funcvar - Joomla Extension Directory

A reflected XSS vulnerability was discovered in the Quickform component for Joomla.

CVE
#xss#vulnerability
CVE-2023-40659: Easy Quick Contact - Joomla! Extension Directory

A reflected XSS vulnerability was discovered in the Easy Quick Contact module for Joomla.

CVE-2023-40628: eXtplorer - Joomla! Extension Directory

A reflected XSS vulnerability was discovered in the Extplorer component for Joomla.

CVE-2023-40657: JoomDOC - Joomla! Extension Directory

A reflected XSS vulnerability was discovered in the Joomdoc component for Joomla.

CVE-2023-40629: LMS Lite - Joomla! Extension Directory

SQLi vulnerability in LMS Lite component for Joomla.

CVE-2023-40627: LivingWord - Joomla! Extension Directory

A reflected XSS vulnerability was discovered in the LivingWord component for Joomla.

CVE-2023-1904: Security Advisory 2023-12

In affected versions of Octopus Server it is possible for the OpenID client secret to be logged in clear text during the configuration of Octopus Server.

CVE-2023-25643: Security Bulletin Details

There is a command injection vulnerability in some ZTE mobile internet products. Due to insufficient input validation of multiple network parameters, an authenticated attacker could use the vulnerability to execute arbitrary commands.

CVE-2023-25644: Security Bulletin Details

There is a denial of service vulnerability in some ZTE mobile internet products. Due to insufficient validation of Web interface parameter, an attacker could use the vulnerability to perform a denial of service attack.

CVE-2023-25650: Security Bulletin Details

There is an arbitrary file download vulnerability in ZXCLOUD iRAI. Since the backend does not escape special strings or restrict paths, an attacker with user permission could access the download interface by modifying the request parameter, causing arbitrary file downloads.