Show filters
27 Total Results
Displaying 11-20 of 27
Sort by:
Attacker Value
Unknown

CVE-2022-31830

Disclosure Date: June 09, 2022 (last updated October 07, 2023)
Kity Minder v1.3.5 was discovered to contain a Server-Side Request Forgery (SSRF) via the init function at ImageCapture.class.php.
Attacker Value
Unknown

CVE-2021-37271

Disclosure Date: September 28, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exists in UEditor v1.4.3.3, which can be exploited by an attacker to obtain user cookie information.
Attacker Value
Unknown

CVE-2021-39227

Disclosure Date: September 17, 2021 (last updated February 23, 2025)
ZRender is a lightweight graphic library providing 2d draw for Apache ECharts. In versions prior to 5.2.1, using `merge` and `clone` helper methods in the `src/core/util.ts` module results in prototype pollution. It affects the popular data visualization library Apache ECharts, which uses and exports these two methods directly. The GitHub Security Advisory page for this vulnerability contains a proof of concept. This issue is patched in ZRender version 5.2.1. One workaround is available: Check if there is `__proto__` in the object keys. Omit it before using it as an parameter in these affected methods. Or in `echarts.util.merge` and `setOption` if project is using ECharts.
Attacker Value
Unknown

CVE-2020-22741

Disclosure Date: July 19, 2021 (last updated February 23, 2025)
An issue was discovered in Xuperchain 3.6.0 that allows for attackers to recover any arbitrary users' private key after obtaining the partial signature in multisignature.
Attacker Value
Unknown

CVE-2020-18145

Disclosure Date: July 14, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability in umeditor v1.2.3 via /public/common/umeditor/php/getcontent.php.
Attacker Value
Unknown

CVE-2018-0692

Disclosure Date: November 15, 2018 (last updated November 27, 2024)
Untrusted search path vulnerability in Baidu Browser Version 43.23.1000.500 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
0
Attacker Value
Unknown

CVE-2016-10697

Disclosure Date: June 04, 2018 (last updated November 26, 2024)
react-native-baidu-voice-synthesizer is a baidu voice speech synthesizer for react native. react-native-baidu-voice-synthesizer downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.
0
Attacker Value
Unknown

CVE-2018-6605

Disclosure Date: February 05, 2018 (last updated November 26, 2024)
SQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails, getPlacemarkHoverText, getPathHoverText, or getPathDetails request.
0
Attacker Value
Unknown

CVE-2017-14744

Disclosure Date: September 26, 2017 (last updated November 26, 2024)
UEditor 1.4.3.3 has XSS via the SRC attribute of an IFRAME element.
0
Attacker Value
Unknown

CVE-2017-2221

Disclosure Date: August 04, 2017 (last updated November 26, 2024)
Untrusted search path vulnerability in Installer of Baidu IME Ver3.6.1.6 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
0