Show filters
34 Total Results
Displaying 1-10 of 34
Sort by:
Attacker Value
Moderate

CVE-2021-25003

Disclosure Date: March 14, 2022 (last updated February 23, 2025)
The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE
Attacker Value
Unknown

CVE-2024-54271

Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Missing Authorization vulnerability in WPTaskForce WPCargo Track & Trace allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WPCargo Track & Trace: from n/a through 7.0.6.
0
Attacker Value
Unknown

CVE-2024-47849

Disclosure Date: October 05, 2024 (last updated October 17, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows SQL Injection.This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1.
Attacker Value
Unknown

CVE-2024-47847

Disclosure Date: October 05, 2024 (last updated October 17, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross-Site Scripting (XSS).This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1.
Attacker Value
Unknown

CVE-2024-47846

Disclosure Date: October 05, 2024 (last updated October 17, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in The Wikimedia Foundation Mediawiki - Cargo allows Cross Site Request Forgery.This issue affects Mediawiki - Cargo: from 3.6.X before 3.6.1.
Attacker Value
Unknown

CVE-2024-40754

Disclosure Date: September 10, 2024 (last updated September 10, 2024)
Heap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This issue affects Escargot: 4.0.0.
0
Attacker Value
Unknown

CVE-2024-32671

Disclosure Date: July 29, 2024 (last updated September 12, 2024)
Heap-based Buffer Overflow vulnerability in Samsung Open Source Escargot JavaScript engine allows Overflow Buffers.This issue affects Escargot: 4.0.0.
Attacker Value
Unknown

CVE-2024-32672

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
A Segmentation Fault issue discovered in Samsung Open Source Escargot JavaScript engine allows remote attackers to cause a denial of service via crafted input. This issue affects Escargot: 4.0.0.
0
Attacker Value
Unknown

CVE-2024-32669

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Improper Input Validation vulnerability in Samsung Open Source escargot JavaScript engine allows Overflow Buffers. However, it occurs in the test code and does not include in the release. This issue affects escargot: 4.0.0.
0
Attacker Value
Unknown

CVE-2023-41268

Disclosure Date: December 06, 2023 (last updated December 12, 2023)
Improper input validation vulnerability in Samsung Open Source Escargot allows stack overflow and segmentation fault. This issue affects Escargot: from 3.0.0 through 4.0.0.