Show filters
86 Total Results
Displaying 11-20 of 86
Sort by:
Attacker Value
Unknown

CVE-2023-4933

Disclosure Date: October 16, 2023 (last updated February 17, 2024)
The WP Job Openings WordPress plugin before 3.4.3 does not block listing the contents of the directories where it stores attachments to job applications, allowing unauthenticated visitors to list and download private attachments if the autoindex feature of the web server is enabled.
Attacker Value
Unknown

CVE-2023-23707

Disclosure Date: March 23, 2023 (last updated November 08, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Unrestricted Upload of File with Dangerous Type vulnerability in Awsm Innovations Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files allows Stored XSS via upload of SVG and HTML files. This issue affects Embed Any Document – Embed PDF, Word, PowerPoint and Excel Files plugin <= 2.7.1 versions.
Attacker Value
Unknown

CVE-2022-46391

Disclosure Date: December 04, 2022 (last updated October 08, 2023)
AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.
Attacker Value
Unknown

CVE-2021-37746

Disclosure Date: July 30, 2021 (last updated November 08, 2023)
textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click.
Attacker Value
Unknown

CVE-2018-25017

Disclosure Date: July 01, 2021 (last updated November 29, 2024)
RawSpeed (aka librawspeed) 3.1 has a heap-based buffer overflow in TableLookUp::setTable.
Attacker Value
Unknown

CVE-2020-35657

Disclosure Date: December 23, 2020 (last updated November 28, 2024)
Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of UploadTheme to upload a theme ZIP archive containing a .php file that is able to execute OS commands. NOTE: this is unrelated to the JAWS (aka Job Access With Speech) product.
Attacker Value
Unknown

CVE-2020-35656

Disclosure Date: December 23, 2020 (last updated November 28, 2024)
Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of admin.php?reqGadget=Components&reqAction=InstallGadget&comp=FileBrowser and admin.php?reqGadget=FileBrowser&reqAction=Files to upload a .php file. NOTE: this is unrelated to the JAWS (aka Job Access With Speech) product.
Attacker Value
Unknown

CVE-2020-35176

Disclosure Date: December 12, 2020 (last updated November 08, 2023)
In AWStats through 7.8, cgi-bin/awstats.pl?config= accepts a partial absolute pathname (omitting the initial /etc), even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501 and CVE-2020-29600.
Attacker Value
Unknown

CVE-2020-29600

Disclosure Date: December 07, 2020 (last updated November 08, 2023)
In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501.
Attacker Value
Unknown

CVE-2020-24379

Disclosure Date: September 09, 2020 (last updated November 28, 2024)
WebDAV implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to XXE injection.