Search CVE reports


Toggle filters

13851 – 13860 of 44107 results

Status is adjusted based on your filters.


CVE-2023-29455

Medium priority
Not affected

Reflected XSS attacks, also known as non-persistent attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script is activated through a link, which sends a request to a website with...

1 affected package

zabbix

Package 16.04 LTS
zabbix Not affected
Show less packages

CVE-2023-29454

Medium priority
Not affected

Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., in a database or server-side text files), and...

1 affected package

zabbix

Package 16.04 LTS
zabbix Not affected
Show less packages

CVE-2023-29452

Medium priority
Not affected

Currently, geomap configuration (Administration -> General -> Geographical maps) allows using HTML in the field “Attribution text” when selected “Other” Tile provider.

1 affected package

zabbix

Package 16.04 LTS
zabbix Not affected
Show less packages

CVE-2023-29451

Medium priority
Not affected

Specially crafted string can cause a buffer overrun in the JSON parser library leading to a crash of the Zabbix Server or a Zabbix Proxy.

1 affected package

zabbix

Package 16.04 LTS
zabbix Not affected
Show less packages

CVE-2023-29450

Medium priority
Not affected

JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data.

1 affected package

zabbix

Package 16.04 LTS
zabbix Not affected
Show less packages

CVE-2023-29449

Medium priority
Not affected

JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles (Admin...

1 affected package

zabbix

Package 16.04 LTS
zabbix Not affected
Show less packages

CVE-2023-38199

Medium priority
Needs evaluation

coreruleset (aka OWASP ModSecurity Core Rule Set) through 3.3.4 does not detect multiple Content-Type request headers on some platforms. This might allow attackers to bypass a WAF with a crafted payload, aka...

1 affected package

modsecurity-crs

Package 16.04 LTS
modsecurity-crs Needs evaluation
Show less packages

CVE-2023-3444

Medium priority
Ignored

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to...

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages

CVE-2023-3424

Medium priority
Ignored

An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. A Regular Expression Denial of...

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages

CVE-2023-3363

Medium priority
Ignored

An information disclosure issue in Gitlab CE/EE affecting all versions from 13.6 prior to 15.11.10, all versions from 16.0 prior to 16.0.6, all versions from 16.1 prior to 16.1.1, resulted in the Sidekiq log including webhook...

1 affected package

gitlab

Package 16.04 LTS
gitlab Ignored
Show less packages