Show filters
27 Total Results
Displaying 11-20 of 27
Sort by:
Attacker Value
Unknown

CVE-2023-0609

Disclosure Date: February 01, 2023 (last updated October 08, 2023)
Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.
Attacker Value
Unknown

CVE-2023-22333

Disclosure Date: January 30, 2023 (last updated October 08, 2023)
Cross-site scripting vulnerability in EasyMail 2.00.130 and earlier allows a remote unauthenticated attacker to inject an arbitrary script.
Attacker Value
Unknown

CVE-2022-25842

Disclosure Date: May 01, 2022 (last updated February 23, 2025)
All versions of package com.alibaba.oneagent:one-java-agent-plugin are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) using a specially crafted archive that holds directory traversal filenames (e.g. ../../evil.exe). The attacker can overwrite executable files and either invoke them remotely or wait for the system or user to call them, thus achieving remote command execution on the victim’s machine.
Attacker Value
Unknown

CVE-2021-37786

Disclosure Date: September 27, 2021 (last updated February 23, 2025)
Certain Federal Office of Information Technology Systems and Telecommunication FOITT products are affected by improper handling of exceptional conditions. This affects COVID Certificate App IOS 2.2.0 and below affected, patch in progress and COVID Certificate Check App IOS 2.2.0 and below affected, patch in progress. A denial of service (physically proximate) could be caused by scanning a crafted QR code.
Attacker Value
Unknown

CVE-2019-8421

Disclosure Date: February 17, 2019 (last updated November 27, 2024)
upload/protected/modules/admini/views/post/index.php in BageCMS through 3.1.4 allows SQL Injection via the title or titleAlias parameter.
0
Attacker Value
Unknown

CVE-2018-19560

Disclosure Date: November 26, 2018 (last updated November 27, 2024)
BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account.
0
Attacker Value
Unknown

CVE-2018-19104

Disclosure Date: November 08, 2018 (last updated November 27, 2024)
In BageCMS 3.1.3, upload/index.php has a CSRF vulnerability that can be used to upload arbitrary files and get server privileges.
0
Attacker Value
Unknown

CVE-2018-18257

Disclosure Date: October 11, 2018 (last updated November 27, 2024)
An issue was discovered in BageCMS 3.1.3. An attacker can delete any files and folders on the web server via an index.php?r=admini/template/batch&command=deleteFile&fileName= or index.php?r=admini/template/batch&command=deleteFolder&folderName=../ directory traversal URI.
0
Attacker Value
Unknown

CVE-2018-18258

Disclosure Date: October 11, 2018 (last updated November 27, 2024)
An issue was discovered in BageCMS 3.1.3. The attacker can execute arbitrary PHP code on the web server and can read any file on the web server via an index.php?r=admini/template/updateTpl&filename= URI.
0
Attacker Value
Unknown

CVE-2018-11352

Disclosure Date: September 21, 2018 (last updated November 27, 2024)
The Wallabag application 2.2.3 to 2.3.2 is affected by one cross-site scripting (XSS) vulnerability that is stored within the configuration page. This vulnerability enables the execution of a JavaScript payload each time an administrator visits the configuration page. The vulnerability can be exploited with authentication and used to target administrators and steal their sessions.
0