Show filters
51 Total Results
Displaying 11-20 of 51
Sort by:
Attacker Value
Unknown
CVE-2023-4944
Disclosure Date: September 14, 2023 (last updated October 08, 2023)
The Awesome Weather Widget for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'awesome-weather' shortcode in versions up to, and including, 3.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2023-25471
Disclosure Date: August 30, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Webcodin WCP OpenWeather plugin <= 2.5.0 versions.
0
Attacker Value
Unknown
CVE-2023-25478
Disclosure Date: July 10, 2023 (last updated October 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Jason Rouet Weather Station plugin <= 3.8.12 versions.
0
Attacker Value
Unknown
CVE-2023-29745
Disclosure Date: May 31, 2023 (last updated October 08, 2023)
An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attack by manipulating the database.
0
Attacker Value
Unknown
CVE-2023-29742
Disclosure Date: May 31, 2023 (last updated October 08, 2023)
An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a code execution attack by manipulating the database.
0
Attacker Value
Unknown
CVE-2023-29743
Disclosure Date: May 30, 2023 (last updated October 08, 2023)
An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attack by manipulating the database.
0
Attacker Value
Unknown
CVE-2023-29741
Disclosure Date: May 30, 2023 (last updated October 08, 2023)
An issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause an escalation of privileges attack by manipulating the database.
0
Attacker Value
Unknown
CVE-2022-45291
Disclosure Date: April 25, 2023 (last updated October 08, 2023)
PWS Personal Weather Station Dashboard (PWS_Dashboard) LTS December 2020 (2012_lts) allows remote code execution by injecting PHP code into settings.php. Attacks can use the PWS_printfile.php, PWS_frame_text.php, PWS_listfile.php, PWS_winter.php, and PWS_easyweathersetup.php endpoints. A contributing factor is a hardcoded login password of support, which is not documented. (This is not the same as the documented setup password, which is 12345.) The issue was fixed in late 2022.
0
Attacker Value
Unknown
CVE-2022-47179
Disclosure Date: February 28, 2023 (last updated November 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Uwe Jacobs OWM Weather plugin <= 5.6.11 leads to post duplication as a draft.
0
Attacker Value
Unknown
CVE-2023-0360
Disclosure Date: February 13, 2023 (last updated October 08, 2023)
The Location Weather WordPress plugin before 1.3.4 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
0