Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Unknown
CVE-2024-35772
Disclosure Date: June 21, 2024 (last updated June 25, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in presscustomizr Hueman.This issue affects Hueman: from n/a through 3.7.24.
0
Attacker Value
Unknown
CVE-2024-2133
Disclosure Date: March 03, 2024 (last updated March 03, 2024)
A vulnerability, which was classified as problematic, was found in Bdtask Isshue Multi Store eCommerce Shopping Cart Solution 4.0. This affects an unknown part of the file /dashboard/Cinvoice/manage_invoice of the component Manage Sale Page. The manipulation of the argument Title leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-255495.
0
Attacker Value
Unknown
CVE-2020-36753
Disclosure Date: October 20, 2023 (last updated October 28, 2023)
The Hueman theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.6.3. This is due to missing or incorrect nonce validation on the save_meta_box() function. This makes it possible for unauthenticated attackers to save metabox data via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2023-42189
Disclosure Date: October 10, 2023 (last updated February 16, 2024)
Insecure Permissions vulnerability in Connectivity Standards Alliance Matter Official SDK v.1.1.0.0 , Nanoleaf Light strip v.3.5.10, Govee LED Strip v.3.00.42, switchBot Hub2 v.1.0-0.8, Phillips hue hub v.1.59.1959097030, and yeelight smart lamp v.1.12.69 allows a remote attacker to cause a denial of service via a crafted script to the KeySetRemove function.
0
Attacker Value
Unknown
CVE-2021-26504
Disclosure Date: August 11, 2023 (last updated October 08, 2023)
Directory Traversal vulnerability in Foddy node-red-contrib-huemagic version 3.0.0, allows remote attackers to gain sensitive information via crafted request in res.sendFile API in hue-magic.js.
0
Attacker Value
Unknown
CVE-2023-29566
Disclosure Date: April 24, 2023 (last updated October 08, 2023)
huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.
0
Attacker Value
Unknown
CVE-2022-4784
Disclosure Date: February 21, 2023 (last updated February 24, 2025)
The Hueman Addons WordPress plugin through 2.3.3 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
0
Attacker Value
Unknown
CVE-2021-32481
Disclosure Date: November 08, 2021 (last updated February 23, 2025)
Cloudera Hue 4.6.0 allows XSS via the type parameter.
0
Attacker Value
Unknown
CVE-2021-29994
Disclosure Date: November 08, 2021 (last updated February 23, 2025)
Cloudera Hue 4.6.0 allows XSS.
0
Attacker Value
Unknown
CVE-2021-25864
Disclosure Date: January 26, 2021 (last updated February 22, 2025)
node-red-contrib-huemagic 3.0.0 is affected by hue/assets/..%2F Directory Traversal.in the res.sendFile API, used in file hue-magic.js, to fetch an arbitrary file.
0