Show filters
106 Total Results
Displaying 11-20 of 106
Sort by:
Attacker Value
Unknown

CVE-2022-25420

Disclosure Date: March 29, 2022 (last updated February 23, 2025)
NTT Resonant Incorporated goo blog App Web Application 1.0 is vulnerable to CLRF injection. This vulnerability allows attackers to execute arbitrary code via a crafted HTTP request.
Attacker Value
Unknown

CVE-2021-20847

Disclosure Date: December 01, 2021 (last updated February 23, 2025)
Cross-site scripting vulnerability in Wi-Fi STATION SH-52A (38JP_1_11G, 38JP_1_11J, 38JP_1_11K, 38JP_1_11L, 38JP_1_26F, 38JP_1_26G, 38JP_1_26J, 38JP_2_03B, and 38JP_2_03C) allows a remote unauthenticated attacker to inject an arbitrary script via WebUI of the device.
Attacker Value
Unknown

CVE-2021-20844

Disclosure Date: November 24, 2021 (last updated February 23, 2025)
Improper neutralization of HTTP request headers for scripting syntax vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier allows a remote authenticated attacker to obtain sensitive information via a specially crafted web page.
Attacker Value
Unknown

CVE-2021-20843

Disclosure Date: November 24, 2021 (last updated February 23, 2025)
Cross-site script inclusion vulnerability in the Web GUI of RTX830 Rev.15.02.17 and earlier, NVR510 Rev.15.01.18 and earlier, NVR700W Rev.15.00.19 and earlier, and RTX1210 Rev.14.01.38 and earlier allows a remote authenticated attacker to alter the settings of the product via a specially crafted web page.
Attacker Value
Unknown

CVE-2021-20728

Disclosure Date: June 09, 2021 (last updated February 22, 2025)
Improper access control vulnerability in goo blog App for Android ver.1.2.25 and earlier and for iOS ver.1.3.3 and earlier allows a remote attacker to lead a user to access an arbitrary website via the vulnerable App.
Attacker Value
Unknown

CVE-2021-31701

Disclosure Date: June 06, 2021 (last updated February 22, 2025)
Mintty before 3.4.7 mishandles Bracketed Paste Mode.
Attacker Value
Unknown

CVE-2021-28848

Disclosure Date: June 03, 2021 (last updated February 22, 2025)
Mintty before 3.4.5 allows remote servers to cause a denial of service (Windows GUI hang) by telling the Mintty window to change its title repeatedly at high speed, which results in many SetWindowTextA or SetWindowTextW calls. In other words, it does not implement a usleep or similar delay upon processing a title change.
Attacker Value
Unknown

CVE-2021-20674

Disclosure Date: March 12, 2021 (last updated February 22, 2025)
Untrusted search path vulnerability in Installer of MagicConnect Client program distributed before 2021 March 1 allows an attacker to gain privileges and via a Trojan horse DLL in an unspecified directory and to execute arbitrary code with the privilege of the user invoking the installer when a terminal is connected remotely using Remote desktop.
Attacker Value
Unknown

CVE-2020-15943

Disclosure Date: August 04, 2020 (last updated February 21, 2025)
An issue was discovered in the Gantt-Chart module before 5.5.4 for Jira. Due to a missing privilege check, it is possible to read and write to the module configuration of other users. This can also be used to deliver an XSS payload to other users' dashboards. To exploit this vulnerability, an attacker has to be authenticated.
Attacker Value
Unknown

CVE-2020-15944

Disclosure Date: August 04, 2020 (last updated February 21, 2025)
An issue was discovered in the Gantt-Chart module before 5.5.5 for Jira. Due to missing validation of user input, it is vulnerable to a persistent XSS attack. An attacker can embed the attack vectors in the dashboard of other users. To exploit this vulnerability, an attacker has to be authenticated.