Show filters
22 Total Results
Displaying 11-20 of 22
Sort by:
Attacker Value
Unknown
CVE-2022-32167
Disclosure Date: September 20, 2022 (last updated October 08, 2023)
Cloudreve versions v1.0.0 through v3.5.3 are vulnerable to Stored Cross-Site Scripting (XSS), via the file upload functionality. A low privileged user will be able to share a file with an admin user, which could lead to privilege escalation.
0
Attacker Value
Unknown
CVE-2022-35161
Disclosure Date: August 03, 2022 (last updated October 08, 2023)
GVRET Stable Release as of Aug 15, 2015 was discovered to contain a buffer overflow via the handleConfigCmd function at SerialConsole.cpp.
0
Attacker Value
Unknown
CVE-2022-1512
Disclosure Date: May 16, 2022 (last updated October 07, 2023)
The ScrollReveal.js Effects WordPress plugin through 1.2 does not sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
0
Attacker Value
Unknown
CVE-2022-0776
Disclosure Date: March 01, 2022 (last updated October 07, 2023)
Cross-site Scripting (XSS) - DOM in GitHub repository hakimel/reveal.js prior to 4.3.0.
0
Attacker Value
Unknown
CVE-2021-24333
Disclosure Date: June 01, 2021 (last updated February 22, 2025)
The Content Copy Protection & Prevent Image Save WordPress plugin through 1.3 does not check for CSRF when saving its settings, not perform any validation and sanitisation on them, allowing attackers to make a logged in administrator set arbitrary XSS payloads in them.
0
Attacker Value
Unknown
CVE-2020-23982
Disclosure Date: August 27, 2020 (last updated February 22, 2025)
DesignMasterEvents Conference management 1.0.0 has cross site scripting via the 'certificate.php'
0
Attacker Value
Unknown
CVE-2020-23980
Disclosure Date: August 27, 2020 (last updated February 22, 2025)
DesignMasterEvents Conference management 1.0.0 allows SQL Injection via the username field on the administrator login page.
0
Attacker Value
Unknown
CVE-2020-8127
Disclosure Date: February 28, 2020 (last updated February 21, 2025)
Insufficient validation in cross-origin communication (postMessage) in reveal.js version 3.9.1 and earlier allow attackers to perform cross-site scripting attacks.
0
Attacker Value
Unknown
CVE-2019-15486
Disclosure Date: August 23, 2019 (last updated November 27, 2024)
django-js-reverse (aka Django JS Reverse) before 0.9.1 has XSS via js_reverse_inline.
0
Attacker Value
Unknown
CVE-2018-13579
Disclosure Date: July 09, 2018 (last updated November 27, 2024)
The mintToken function of a smart contract implementation for ForeverCoin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
0