Show filters
97 Total Results
Displaying 11-20 of 97
Sort by:
Attacker Value
Unknown
CVE-2024-21764
Disclosure Date: February 02, 2024 (last updated February 08, 2024)
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may allow an attacker to connect to a specific port.
0
Attacker Value
Unknown
CVE-2024-21852
Disclosure Date: February 01, 2024 (last updated February 08, 2024)
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can supply a malicious configuration file by utilizing a Zip Slip vulnerability in the unpacking routine to achieve remote code execution.
0
Attacker Value
Unknown
CVE-2023-47397
Disclosure Date: November 08, 2023 (last updated November 16, 2023)
WeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.
0
Attacker Value
Unknown
CVE-2023-24401
Disclosure Date: August 30, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Davidsword Mobile Call Now & Map Buttons plugin <= 1.5.0 versions.
0
Attacker Value
Unknown
CVE-2023-1169
Disclosure Date: June 09, 2023 (last updated October 08, 2023)
The OoohBoi Steroids for Elementor plugin for WordPress is vulnerable to missing authorization due to a missing capability check on the 'file_uploader_callback' function in versions up to, and including, 2.1.4. This makes it possible for subscriber-level attackers to upload image attachments to the site.
0
Attacker Value
Unknown
CVE-2023-0336
Disclosure Date: March 27, 2023 (last updated February 24, 2025)
The OoohBoi Steroids for Elementor WordPress plugin before 2.1.5 has CSRF and broken access control vulnerabilities which leads user with role as low as subscriber to delete attachment.
0
Attacker Value
Unknown
CVE-2022-41217
Disclosure Date: February 22, 2023 (last updated February 24, 2025)
Cloudflow contains a unauthenticated file upload vulnerability, which makes it possible for an attacker to upload malicious files to the CLOUDFLOW PROOFSCOPE built-in storage.
0
Attacker Value
Unknown
CVE-2022-41216
Disclosure Date: February 22, 2023 (last updated February 24, 2025)
Local File Inclusion vulnerability within Cloudflow allows attackers to retrieve confidential information from the system.
0
Attacker Value
Unknown
CVE-2022-44153
Disclosure Date: December 07, 2022 (last updated February 24, 2025)
Rapid Software LLC Rapid SCADA 5.8.4 is vulnerable to Cross Site Scripting (XSS).
0
Attacker Value
Unknown
CVE-2022-41477
Disclosure Date: October 14, 2022 (last updated February 24, 2025)
A security issue was discovered in WeBid <=1.2.2. A Server-Side Request Forgery (SSRF) vulnerability in the admin/theme.php file allows remote attackers to inject payloads via theme parameters to read files across directories.
0