Show filters
57 Total Results
Displaying 11-20 of 57
Sort by:
Attacker Value
Unknown

CVE-2023-36299

Disclosure Date: August 03, 2023 (last updated October 08, 2023)
A File Upload vulnerability in typecho v.1.2.1 allows a remote attacker to execute arbitrary code via the upload and options-general parameters in index.php.
Attacker Value
Unknown

CVE-2020-21038

Disclosure Date: May 08, 2023 (last updated October 08, 2023)
Open redirect vulnerability in typecho 1.1-17.10.30-release via the referer parameter to Login.php.
Attacker Value
Unknown

CVE-2023-30184

Disclosure Date: May 04, 2023 (last updated October 08, 2023)
A stored cross-site scripting (XSS) vulnerability in Typecho v1.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the url parameter at /index.php/archives/1/comment.
Attacker Value
Unknown

CVE-2023-27711

Disclosure Date: March 16, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via the Comment Manager /admin/manage-comments.php component.
Attacker Value
Unknown

CVE-2023-27131

Disclosure Date: March 16, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code viathe Post Editorparameter.
Attacker Value
Unknown

CVE-2023-27130

Disclosure Date: March 16, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via an arbitrarily supplied URL parameter.
Attacker Value
Unknown

CVE-2023-24114

Disclosure Date: February 22, 2023 (last updated October 08, 2023)
typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php.
Attacker Value
Unknown

CVE-2021-4124

Disclosure Date: December 16, 2021 (last updated October 07, 2023)
janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Attacker Value
Unknown

CVE-2021-4020

Disclosure Date: November 27, 2021 (last updated October 07, 2023)
janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Attacker Value
Unknown

CVE-2021-33578

Disclosure Date: July 13, 2021 (last updated November 28, 2024)
Echo ShareCare 8.15.5 is susceptible to SQL injection vulnerabilities when processing remote input from both authenticated and unauthenticated users, leading to the ability to bypass authentication, exfiltrate Structured Query Language (SQL) records, and manipulate data.