Show filters
30 Total Results
Displaying 1-10 of 30
Sort by:
Attacker Value
Unknown

CVE-2025-26604

Disclosure Date: February 18, 2025 (last updated February 19, 2025)
Discord-Bot-Framework-Kernel is a Discord bot framework built with interactions.py, featuring modular extension management and secure execution. Because of the nature of arbitrary user-submited code execution, this allows user to execute potentially malicious code to perform damage or extract sensitive information. By loading the module containing the following code and run the command, the bot token can be extracted. Then the attacker can load a blocking module to sabotage the bot (DDoS attack) and the token can be used to make the fake bot act as the real one. If the bot has very high privilege, the attacker basically has full control before the user kicks the bot. Any Discord user that hosts Discord-Bot-Framework-Kernel before commit f0d9e70841a0e3170b88c4f8d562018ccd8e8b14 is affected. Users are advised to upgrade. Users unable to upgrade may attempt to limit their discord bot's access via configuration options.
0
Attacker Value
Unknown

CVE-2023-2675

Disclosure Date: November 07, 2023 (last updated November 14, 2023)
Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 2023.Q1.1223.
Attacker Value
Unknown

CVE-2023-1665

Disclosure Date: March 27, 2023 (last updated October 08, 2023)
Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 0.0.0.
Attacker Value
Unknown

CVE-2023-0028

Disclosure Date: January 01, 2023 (last updated November 01, 2023)
Cross-site Scripting (XSS) - Stored in GitHub repository linagora/twake prior to 2023.Q1.1200+.
Attacker Value
Unknown

CVE-2020-25605

Disclosure Date: February 17, 2021 (last updated February 22, 2025)
Cleartext transmission of sensitive information in Agora Video SDK prior to 3.1 allows a remote attacker to obtain access to audio and video of any ongoing Agora video call through observation of cleartext network traffic.
Attacker Value
Unknown

CVE-2019-1010205

Disclosure Date: July 23, 2019 (last updated November 27, 2024)
LINAGORA hublin latest (commit 72ead897082403126bf8df9264e70f0a9de247ff) is affected by: Directory Traversal. The impact is: The vulnerability allows an attacker to access any file (with a fixed extension) on the server. The component is: A web-view renderer; details here: https://lgtm.com/projects/g/linagora/hublin/snapshot/af9f1ce253b4ee923ff8da8f9d908d02a8e95b7f/files/backend/webserver/views.js?sort=name&dir=ASC&mode=heatmap&showExcluded=false#xb24eb0101d2aec21:1. The attack vector is: Attacker sends a specially crafted HTTP request.
0
Attacker Value
Unknown

CVE-2017-6560

Disclosure Date: March 09, 2017 (last updated November 26, 2024)
XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=misc&action=[XSS]&editObjId=[XSS] attack.
0
Attacker Value
Unknown

CVE-2017-6562

Disclosure Date: March 09, 2017 (last updated November 26, 2024)
XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=file&targetObjId=fileFolder-2&targetObjIdChild=[XSS] attack.
0
Attacker Value
Unknown

CVE-2017-6559

Disclosure Date: March 09, 2017 (last updated November 26, 2024)
XSS in Agora-Project 3.2.2 exists with an index.php?disconnect=1&msgNotif[]=[XSS] attack.
0
Attacker Value
Unknown

CVE-2017-6561

Disclosure Date: March 09, 2017 (last updated November 26, 2024)
XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=object&action=[XSS] attack.
0