Show filters
27 Total Results
Displaying 11-20 of 27
Sort by:
Attacker Value
Unknown
CVE-2022-31830
Disclosure Date: June 09, 2022 (last updated October 07, 2023)
Kity Minder v1.3.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the init function at ImageCapture.class.php.
0
Attacker Value
Unknown
CVE-2021-37271
Disclosure Date: September 28, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exists in UEditor v1.4.3.3, which can be exploited by an attacker to obtain user cookie information.
0
Attacker Value
Unknown
CVE-2021-39227
Disclosure Date: September 17, 2021 (last updated February 23, 2025)
ZRender is a lightweight graphic library providing 2d draw for Apache ECharts. In versions prior to 5.2.1, using `merge` and `clone` helper methods in the `src/core/util.ts` module results in prototype pollution. It affects the popular data visualization library Apache ECharts, which uses and exports these two methods directly. The GitHub Security Advisory page for this vulnerability contains a proof of concept. This issue is patched in ZRender version 5.2.1. One workaround is available: Check if there is `__proto__` in the object keys. Omit it before using it as an parameter in these affected methods. Or in `echarts.util.merge` and `setOption` if project is using ECharts.
0
Attacker Value
Unknown
CVE-2020-22741
Disclosure Date: July 19, 2021 (last updated February 23, 2025)
An issue was discovered in Xuperchain 3.6.0 that allows for attackers to recover any arbitrary users' private key after obtaining the partial signature in multisignature.
0
Attacker Value
Unknown
CVE-2020-18145
Disclosure Date: July 14, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability in umeditor v1.2.3 via /public/common/umeditor/php/getcontent.php.
0
Attacker Value
Unknown
CVE-2018-0692
Disclosure Date: November 15, 2018 (last updated November 27, 2024)
Untrusted search path vulnerability in Baidu Browser Version 43.23.1000.500 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
0
Attacker Value
Unknown
CVE-2016-10697
Disclosure Date: June 04, 2018 (last updated November 26, 2024)
react-native-baidu-voice-synthesizer is a baidu voice speech synthesizer for react native. react-native-baidu-voice-synthesizer downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.
0
Attacker Value
Unknown
CVE-2018-6605
Disclosure Date: February 05, 2018 (last updated November 26, 2024)
SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHoverText, or getPathDetails request.
0
Attacker Value
Unknown
CVE-2017-14744
Disclosure Date: September 26, 2017 (last updated November 26, 2024)
UEditor 1.4.3.3 has XSS via the SRC attribute of an IFRAME element.
0
Attacker Value
Unknown
CVE-2017-2221
Disclosure Date: August 04, 2017 (last updated November 26, 2024)
Untrusted search path vulnerability in Installer of Baidu IME Ver3.6.1.6 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
0