Show filters
33 Total Results
Displaying 11-20 of 33
Sort by:
Attacker Value
Unknown

CVE-2022-0429

Disclosure Date: March 07, 2022 (last updated February 23, 2025)
The WP Cerber Security, Anti-spam & Malware Scan WordPress plugin before 8.9.6 does not sanitise the $url variable before using it in an attribute in the Activity tab in the plugins dashboard, leading to an unauthenticated stored Cross-Site Scripting vulnerability.
Attacker Value
Unknown

CVE-2021-37181

Disclosure Date: September 14, 2021 (last updated February 23, 2025)
A vulnerability has been identified in Cerberus DMS V4.0 (All versions), Cerberus DMS V4.1 (All versions), Cerberus DMS V4.2 (All versions), Cerberus DMS V5.0 (All versions < v5.0 QU1), Desigo CC Compact V4.0 (All versions), Desigo CC Compact V4.1 (All versions), Desigo CC Compact V4.2 (All versions), Desigo CC Compact V5.0 (All versions < V5.0 QU1), Desigo CC V4.0 (All versions), Desigo CC V4.1 (All versions), Desigo CC V4.2 (All versions), Desigo CC V5.0 (All versions < V5.0 QU1). The application deserialises untrusted data without sufficient validations, that could result in an arbitrary deserialization. This could allow an unauthenticated attacker to execute code in the affected system. The CCOM communication component used for Windows App / Click-Once and IE Web / XBAP client connectivity are affected by the vulnerability.
Attacker Value
Unknown

CVE-2021-37597

Disclosure Date: August 19, 2021 (last updated February 23, 2025)
WP Cerber before 8.9.3 allows MFA bypass via wordpress_logged_in_[hash] manipulation.
Attacker Value
Unknown

CVE-2021-37598

Disclosure Date: August 19, 2021 (last updated February 23, 2025)
WP Cerber before 8.9.3 allows bypass of /wp-json access control via a trailing ? character.
Attacker Value
Unknown

CVE-2016-10990

Disclosure Date: September 17, 2019 (last updated November 27, 2024)
The wp-cerber plugin before 2.7 for WordPress has XSS via the X-Forwarded-For HTTP header.
Attacker Value
Unknown

CVE-2018-13703

Disclosure Date: July 09, 2018 (last updated November 27, 2024)
The mintToken function of a smart contract implementation for CERB_Coin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
0
Attacker Value
Unknown

CVE-2017-6880

Disclosure Date: March 17, 2017 (last updated November 26, 2024)
Buffer overflow in Cerberus FTP Server 8.0.10.3 allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long MLST command.
0
Attacker Value
Unknown

CVE-2015-6545

Disclosure Date: September 03, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in ajax.php in Cerb before 7.0.4 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via a saveWorkerPeek action.
0
Attacker Value
Unknown

CVE-2012-4006

Disclosure Date: August 17, 2012 (last updated October 04, 2023)
The GREE application before 1.4.0, GREE Tanken Dorirando application before 1.0.7, GREE Tsurisuta application before 1.5.0, GREE Monpura application before 1.1.1, GREE Kaizokuoukoku Columbus application before 1.3.5, GREE haconiwa application before 1.1.0, GREE Seisen Cerberus application before 1.1.0, and KDDI&GREE GREE Market application before 2.1.2 for Android do not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application.
0
Attacker Value
Unknown

CVE-2008-6440

Disclosure Date: March 06, 2009 (last updated October 04, 2023)
Cerberus Helpdesk before 4.0 (Build 600) allows remote attackers to obtain sensitive information via direct requests for "controllers ... that aren't standard helpdesk pages," possibly involving the (1) /display and (2) /kb URIs.
0