Show filters
22 Total Results
Displaying 1-10 of 22
Sort by:
Attacker Value
Unknown
CVE-2024-42939
Disclosure Date: August 21, 2024 (last updated August 31, 2024)
A cross-site scripting (XSS) vulnerability in the component /index/index.html of YZNCMS v1.4.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the configured remarks text field.
0
Attacker Value
Unknown
CVE-2023-43233
Disclosure Date: September 27, 2023 (last updated October 08, 2023)
A stored cross-site scripting (XSS) vulnerability in the cms/content/edit component of YZNCMS v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the title parameter.
0
Attacker Value
Unknown
CVE-2023-37131
Disclosure Date: July 06, 2023 (last updated October 08, 2023)
A Cross-Site Request Forgery (CSRF) in the component /public/admin/profile/update.html of YznCMS v1.1.0 allows attackers to arbitrarily change the Administrator password via a crafted POST request.
0
Attacker Value
Unknown
CVE-2020-29577
Disclosure Date: December 08, 2020 (last updated February 22, 2025)
The official znc docker images before 1.7.1-slim contain a blank password for a root user. Systems using the znc docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password.
0
Attacker Value
Unknown
CVE-2020-13775
Disclosure Date: June 02, 2020 (last updated February 21, 2025)
ZNC 1.8.0 up to 1.8.1-rc1 allows authenticated users to trigger an application crash (with a NULL pointer dereference) if echo-message is not enabled and there is no network.
0
Attacker Value
Unknown
CVE-2019-15914
Disclosure Date: December 20, 2019 (last updated November 27, 2024)
An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Attackers can use the ZigBee trust center rejoin procedure to perform mutiple denial of service attacks.
0
Attacker Value
Unknown
CVE-2019-15913
Disclosure Date: December 20, 2019 (last updated November 27, 2024)
An issue was discovered on Xiaomi DGNWG03LM, ZNCZ03LM, MCCGQ01LM, WSDCGQ01LM, RTCGQ01LM devices. Because of insecure key transport in ZigBee communication, causing attackers to gain sensitive information and denial of service attack, take over smart home devices, and tamper with messages.
0
Attacker Value
Unknown
CVE-2010-2488
Disclosure Date: November 12, 2019 (last updated November 27, 2024)
NULL pointer dereference vulnerability in ZNC before 0.092 caused by traffic stats when there are unauthenticated connections.
0
Attacker Value
Unknown
CVE-2019-12816
Disclosure Date: June 15, 2019 (last updated November 08, 2023)
Modules.cpp in ZNC before 1.7.4-rc1 allows remote authenticated non-admin users to escalate privileges and execute arbitrary code by loading a module with a crafted name.
0
Attacker Value
Unknown
CVE-2019-9917
Disclosure Date: March 27, 2019 (last updated November 08, 2023)
ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding.
0