Show filters
73 Total Results
Displaying 11-20 of 73
Sort by:
Attacker Value
Unknown

CVE-2023-36692

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Christian Kramer & Hendrik Thole WP-Cirrus plugin <= 0.6.11 versions.
Attacker Value
Unknown

CVE-2023-22898

Disclosure Date: January 10, 2023 (last updated February 24, 2025)
workers/extractor.py in Pandora (aka pandora-analysis/pandora) 1.3.0 allows a denial of service when an attacker submits a deeply nested ZIP archive (aka ZIP bomb).
Attacker Value
Unknown

CVE-2022-36038

Disclosure Date: September 06, 2022 (last updated February 24, 2025)
CircuitVerse is an open-source platform which allows users to construct digital logic circuits online. A remote code execution (RCE) vulnerability in CircuitVerse allows authenticated attackers to execute arbitrary code via specially crafted JSON payloads. This issue may lead to Remote Code Execution (RCE). A patch is available in commit number 7b3023a99499a7675f10f2c1d9effdf10c35fb6e. There are currently no known workarounds.
Attacker Value
Unknown

CVE-2022-1669

Disclosure Date: May 17, 2022 (last updated February 23, 2025)
A buffer overflow vulnerability has been detected in the firewall function of the device management web portal. The device runs a CGI binary (index.cgi) to offer a management web application. Once authenticated with valid credentials in this web portal, a potential attacker could submit any "Address" value and it would be copied to a second variable with a "strcpy" vulnerable function without checking its length. Because of this, it is possible to send a long address value to overflow the process stack, controlling the function return address.
Attacker Value
Unknown

CVE-2021-45470

Disclosure Date: December 23, 2021 (last updated February 23, 2025)
lib/DatabaseLayer.py in cve-search before 4.1.0 allows regular expression injection, which can lead to ReDoS (regular expression denial of service) or other impacts.
Attacker Value
Unknown

CVE-2021-26777

Disclosure Date: December 02, 2021 (last updated February 23, 2025)
Buffer overflow vulnerability in function SetFirewall in index.cgi in CIRCUTOR COMPACT DC-S BASIC smart metering concentrator Firwmare version CIR_CDC_v1.2.17, allows attackers to execute arbitrary code.
Attacker Value
Unknown

CVE-2021-24402

Disclosure Date: September 20, 2021 (last updated February 23, 2025)
The Orders functionality in the WP iCommerce WordPress plugin through 1.1.1 has an `order_id` parameter which is not sanitised, escaped or validated before inserting to a SQL statement, leading to SQL injection. The feature is available to low privilege users such as contributors
Attacker Value
Unknown

CVE-2021-36773

Disclosure Date: July 18, 2021 (last updated February 23, 2025)
uBlock Origin before 1.36.2 and nMatrix before 4.4.9 support an arbitrary depth of parameter nesting for strict blocking, which allows crafted web sites to cause a denial of service (unbounded recursion that can trigger memory consumption and a loss of all blocking functionality).
Attacker Value
Unknown

CVE-2021-33841

Disclosure Date: June 08, 2021 (last updated February 22, 2025)
SGE-PLC1000 device, in its 0.9.2b firmware version, does not handle some requests correctly, allowing a remote attacker to inject code into the operating system with maximum privileges.
Attacker Value
Unknown

CVE-2021-33842

Disclosure Date: June 08, 2021 (last updated February 22, 2025)
Improper Authentication vulnerability in the cookie parameter of Circutor SGE-PLC1000 firmware version 0.9.2b allows an attacker to perform operations as an authenticated user. In order to exploit this vulnerability, the attacker must be within the network where the device affected is located.