Show filters
27 Total Results
Displaying 11-20 of 27
Sort by:
Attacker Value
Unknown
CVE-2023-0609
Disclosure Date: February 01, 2023 (last updated October 08, 2023)
Improper Authorization in GitHub repository wallabag/wallabag prior to 2.5.3.
0
Attacker Value
Unknown
CVE-2023-22333
Disclosure Date: January 30, 2023 (last updated October 08, 2023)
Cross-site scripting vulnerability in EasyMail 2.00.130 and earlier allows a remote unauthenticated attacker to inject an arbitrary script.
0
Attacker Value
Unknown
CVE-2022-25842
Disclosure Date: May 01, 2022 (last updated February 23, 2025)
All versions of package com.alibaba.oneagent:one-java-agent-plugin are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) using a specially crafted archive that holds directory traversal filenames (e.g. ../../evil.exe). The attacker can overwrite executable files and either invoke them remotely or wait for the system or user to call them, thus achieving remote command execution on the victim’s machine.
0
Attacker Value
Unknown
CVE-2021-37786
Disclosure Date: September 27, 2021 (last updated February 23, 2025)
Certain Federal Office of Information Technology Systems and Telecommunication FOITT products are affected by improper handling of exceptional conditions. This affects COVID Certificate App IOS 2.2.0 and below affected, patch in progress and COVID Certificate Check App IOS 2.2.0 and below affected, patch in progress. A denial of service (physically proximate) could be caused by scanning a crafted QR code.
0
Attacker Value
Unknown
CVE-2019-8421
Disclosure Date: February 17, 2019 (last updated November 27, 2024)
upload/protected/modules/admini/views/post/index.php in BageCMS through 3.1.4 allows SQL Injection via the title or titleAlias parameter.
0
Attacker Value
Unknown
CVE-2018-19560
Disclosure Date: November 26, 2018 (last updated November 27, 2024)
BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account.
0
Attacker Value
Unknown
CVE-2018-19104
Disclosure Date: November 08, 2018 (last updated November 27, 2024)
In BageCMS 3.1.3, upload/index.php has a CSRF vulnerability that can be used to upload arbitrary files and get server privileges.
0
Attacker Value
Unknown
CVE-2018-18257
Disclosure Date: October 11, 2018 (last updated November 27, 2024)
An issue was discovered in BageCMS 3.1.3. An attacker can delete any files and folders on the web server via an index.php?r=admini/template/batch&command=deleteFile&fileName= or index.php?r=admini/template/batch&command=deleteFolder&folderName=../ directory traversal URI.
0
Attacker Value
Unknown
CVE-2018-18258
Disclosure Date: October 11, 2018 (last updated November 27, 2024)
An issue was discovered in BageCMS 3.1.3. The attacker can execute arbitrary PHP code on the web server and can read any file on the web server via an index.php?r=admini/template/updateTpl&filename= URI.
0
Attacker Value
Unknown
CVE-2018-11352
Disclosure Date: September 21, 2018 (last updated November 27, 2024)
The Wallabag application 2.2.3 to 2.3.2 is affected by one cross-site scripting (XSS) vulnerability that is stored within the configuration page. This vulnerability enables the execution of a JavaScript payload each time an administrator visits the configuration page. The vulnerability can be exploited with authentication and used to target administrators and steal their sessions.
0