Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown

CVE-2023-27704

Disclosure Date: April 12, 2023 (last updated October 08, 2023)
Void Tools Everything lower than v1.4.1.1022 was discovered to contain a Regular Expression Denial of Service (ReDoS).
Attacker Value
Unknown

CVE-2021-20784

Disclosure Date: July 14, 2021 (last updated February 23, 2025)
HTTP header injection vulnerability in Everything version 1.0, 1.1, and 1.2 except the Lite version may allow a remote attacker to inject an arbitrary script or alter the website that uses the product.
Attacker Value
Unknown

CVE-2020-24567

Disclosure Date: August 21, 2020 (last updated November 08, 2023)
voidtools Everything before 1.4.1 Beta Nightly 2020-08-18 allows privilege escalation via a Trojan horse urlmon.dll file in the installation directory. NOTE: this is only relevant if low-privileged users can write to the installation directory, which may be considered a site-specific configuration error
Attacker Value
Unknown

CVE-2016-10917

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The search-everything plugin before 8.1.6 for WordPress has SQL injection related to empty search strings, a different vulnerability than CVE-2014-2316.
0
Attacker Value
Unknown

CVE-2017-18571

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The search-everything plugin before 8.1.7 for WordPress has SQL injection related to WordPress 4.7.x, a different vulnerability than CVE-2014-2316.
0
Attacker Value
Unknown

CVE-2014-3843

Disclosure Date: May 22, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the Search Everything plugin before 8.1.1 for WordPress allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
0
Attacker Value
Unknown

CVE-2014-2316

Disclosure Date: March 09, 2014 (last updated October 05, 2023)
SQL injection vulnerability in se_search_default in the Search Everything plugin before 7.0.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the s parameter to index.php. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2008-0724

Disclosure Date: February 12, 2008 (last updated October 04, 2023)
The Everything Development Engine in The Everything Development System Pre-1.0 and earlier stores passwords in cleartext in a database, which makes it easier for context-dependent attackers to obtain access to user accounts.
0
Attacker Value
Unknown

CVE-2008-0675

Disclosure Date: February 12, 2008 (last updated October 04, 2023)
SQL injection vulnerability in cms/index.pl in The Everything Development Engine in The Everything Development System Pre-1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the node_id parameter.
0
Attacker Value
Unknown

CVE-2001-1483

Disclosure Date: December 31, 2001 (last updated February 22, 2025)
One-Time Passwords In Everything (a.k.a OPIE) 2.32 and 2.4 allows remote attackers to determine the existence of user accounts by printing random passphrases if the user account does not exist and static passphrases if the user account does exist.
0