Show filters
41 Total Results
Displaying 1-10 of 41
Sort by:
Attacker Value
Very High
CVE-2019-7256
Disclosure Date: July 02, 2019 (last updated August 14, 2024)
Linear eMerge E3-Series devices allow Command Injections.
2
Attacker Value
Very High
CVE-2019-7252
Disclosure Date: July 02, 2019 (last updated November 27, 2024)
Linear eMerge E3-Series devices have Default Credentials.
1
Attacker Value
Unknown
CVE-2024-13709
Disclosure Date: January 25, 2025 (last updated January 25, 2025)
The Linear plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.1. This is due to missing or incorrect nonce validation on the 'linear-debug'. This makes it possible for unauthenticated attackers to reset the plugin's cache via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2025-22793
Disclosure Date: January 15, 2025 (last updated January 16, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bold Bold pagos en linea allows DOM-Based XSS.This issue affects Bold pagos en linea: from n/a through 3.1.0.
0
Attacker Value
Unknown
CVE-2024-12496
Disclosure Date: January 09, 2025 (last updated January 09, 2025)
The Linear plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linear_block_buy_commissions' shortcode in all versions up to, and including, 2.7.12 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-52426
Disclosure Date: November 18, 2024 (last updated November 21, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Linear Oy Linear linear allows DOM-Based XSS.This issue affects Linear: from n/a through 2.7.11.
0
Attacker Value
Unknown
CVE-2022-42710
Disclosure Date: January 03, 2023 (last updated February 24, 2025)
Nice (formerly Nortek) Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e devices are vulnerable to Stored Cross-Site Scripting (XSS).
0
Attacker Value
Unknown
CVE-2022-38627
Disclosure Date: January 03, 2023 (last updated February 24, 2025)
Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a SQL injection vulnerability via the idt parameter.
0
Attacker Value
Unknown
CVE-2022-46381
Disclosure Date: December 13, 2022 (last updated February 24, 2025)
Certain Linear eMerge E3-Series devices are vulnerable to XSS via the type parameter (e.g., to the badging/badge_template_v0.php component). This affects 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e.
0
Attacker Value
Unknown
CVE-2022-38628
Disclosure Date: December 13, 2022 (last updated February 24, 2025)
Nortek Linear eMerge E3-Series 0.32-08f, 0.32-07p, 0.32-07e, 0.32-09c, 0.32-09b, 0.32-09a, and 0.32-08e were discovered to contain a cross-site scripting (XSS) vulnerability which is chained with a local session fixation. This vulnerability allows attackers to escalate privileges via unspecified vectors.
0