Show filters
55 Total Results
Displaying 11-20 of 55
Sort by:
Attacker Value
Unknown
CVE-2021-24988
Disclosure Date: December 27, 2021 (last updated February 23, 2025)
The WP RSS Aggregator WordPress plugin before 4.19.3 does not sanitise and escape data before outputting it in the System Info admin dashboard, which could lead to a Stored XSS issue due to the wprss_dismiss_addon_notice AJAX action missing authorisation and CSRF checks, allowing any authenticated users, such as subscriber to call it and set a malicious payload in the addon parameter.
0
Attacker Value
Unknown
CVE-2021-24768
Disclosure Date: November 29, 2021 (last updated February 23, 2025)
The WP RSS Aggregator WordPress plugin before 4.19.2 does not properly sanitise and escape the URL to Blacklist field, allowing malicious HTML to be inserted by high privilege users even when the unfiltered_html capability is disallowed, which could lead to Cross-Site Scripting issues.
0
Attacker Value
Unknown
CVE-2015-9319
Disclosure Date: August 20, 2019 (last updated November 27, 2024)
The gregs-high-performance-seo plugin before 1.6.2 for WordPress has XSS in the context of an old browser.
0
Attacker Value
Unknown
CVE-2018-10752
Disclosure Date: May 05, 2018 (last updated November 26, 2024)
The Tagregator plugin 0.6 for WordPress has stored XSS via the title field in an Add New action.
0
Attacker Value
Unknown
CVE-2016-9339
Disclosure Date: February 13, 2017 (last updated November 26, 2024)
An issue was discovered in INTERSCHALT Maritime Systems VDR G4e Versions 5.220 and prior. External input is used to construct paths to files and directories without properly neutralizing special elements within the pathname that could allow an attacker to read files on the system, a Path Traversal.
0
Attacker Value
Unknown
CVE-2015-4355
Disclosure Date: June 15, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in the Watchdog Aggregator module for Drupal allows remote attackers to hijack the authentication of administrators for requests that enable or disable monitoring sites via unspecified vectors.
0
Attacker Value
Unknown
CVE-2011-3328
Disclosure Date: January 17, 2012 (last updated October 04, 2023)
The png_handle_cHRM function in pngrutil.c in libpng 1.5.4, when color-correction support is enabled, allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a malformed PNG image containing a cHRM chunk associated with a certain zero value.
0
Attacker Value
Unknown
CVE-2009-3917
Disclosure Date: November 09, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the S5 Presentation Player module 6.x-1.x before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via an unspecified field that is copied to the HTML HEAD element.
0
Attacker Value
Unknown
CVE-2008-5144
Disclosure Date: November 18, 2008 (last updated October 04, 2023)
nvidia-cg-toolkit-installer in nvidia-cg-toolkit 2.0.0015 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/nvidia-cg-toolkit-manifest temporary file.
0
Attacker Value
Unknown
CVE-2008-3374
Disclosure Date: July 30, 2008 (last updated October 04, 2023)
SQL injection vulnerability in ajax.php in Gregarius 0.5.4 and earlier allows remote attackers to execute arbitrary SQL commands via the rsargs array parameter in an __exp__getFeedContent action.
0