Show filters
86 Total Results
Displaying 11-20 of 86
Sort by:
Attacker Value
Unknown
CVE-2023-4933
Disclosure Date: October 16, 2023 (last updated February 17, 2024)
The WP Job Openings WordPress plugin before 3.4.3 does not block listing the contents of the directories where it stores attachments to job applications, allowing unauthenticated visitors to list and download private attachments if the autoindex feature of the web server is enabled.
0
Attacker Value
Unknown
CVE-2023-23707
Disclosure Date: March 23, 2023 (last updated November 08, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Unrestricted Upload of File with Dangerous Type vulnerability in Awsm Innovations Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files allows Stored XSS via upload of SVG and HTML files. This issue affects Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin <= 2.7.1 versions.
0
Attacker Value
Unknown
CVE-2022-46391
Disclosure Date: December 04, 2022 (last updated October 08, 2023)
AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.
0
Attacker Value
Unknown
CVE-2021-37746
Disclosure Date: July 30, 2021 (last updated November 08, 2023)
textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click.
0
Attacker Value
Unknown
CVE-2018-25017
Disclosure Date: July 01, 2021 (last updated November 29, 2024)
RawSpeed (aka librawspeed) 3.1 has a heap-based buffer overflow in TableLookUp::setTable.
0
Attacker Value
Unknown
CVE-2020-35657
Disclosure Date: December 23, 2020 (last updated November 28, 2024)
Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of UploadTheme to upload a theme ZIP archive containing a .php file that is able to execute OS commands. NOTE: this is unrelated to the JAWS (aka Job Access With Speech) product.
0
Attacker Value
Unknown
CVE-2020-35656
Disclosure Date: December 23, 2020 (last updated November 28, 2024)
Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of admin.php?reqGadget=Components&reqAction=InstallGadget&comp=FileBrowser and admin.php?reqGadget=FileBrowser&reqAction=Files to upload a .php file. NOTE: this is unrelated to the JAWS (aka Job Access With Speech) product.
0
Attacker Value
Unknown
CVE-2020-35176
Disclosure Date: December 12, 2020 (last updated November 08, 2023)
In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501 and CVE-2020-29600.
0
Attacker Value
Unknown
CVE-2020-29600
Disclosure Date: December 07, 2020 (last updated November 08, 2023)
In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501.
0
Attacker Value
Unknown
CVE-2020-24379
Disclosure Date: September 09, 2020 (last updated November 28, 2024)
WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.
0