Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown

CVE-2015-10059

Disclosure Date: January 17, 2023 (last updated February 24, 2025)
A vulnerability has been found in s134328 Webapplication-Veganguide and classified as problematic. This vulnerability affects unknown code of the file p05-integration/app/shared/api/apiService.js. The manipulation of the argument country/city leads to cross site scripting. The attack can be initiated remotely. The name of the patch is 2aa760fa4e779e40a28206a32ac22ac10356f519. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-218416.
Attacker Value
Unknown

CVE-2020-26296

Disclosure Date: December 30, 2020 (last updated February 22, 2025)
Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization designs. Vega in an npm package. In Vega before version 5.17.3 there is an XSS vulnerability in Vega expressions. Through a specially crafted Vega expression, an attacker could execute arbitrary javascript on a victim's machine. This is fixed in version 5.17.3
Attacker Value
Unknown

CVE-2019-10806

Disclosure Date: March 09, 2020 (last updated February 21, 2025)
vega-util prior to 1.13.1 allows manipulation of object prototype. The 'vega.mergeConfig' method within vega-util could be tricked into adding or modifying properties of the Object.prototype.
Attacker Value
Unknown

CVE-2019-7409

Disclosure Date: May 13, 2019 (last updated November 27, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in ProfileDesign CMS v6.0.2.5 allows remote attackers to inject arbitrary web script or HTML via the (1) page, (2) gbs, (3) side, (4) id, (5) imgid, (6) cat, or (7) orderby parameter.
0
Attacker Value
Unknown

CVE-2014-5824

Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The longjiang (aka com.longjiang.kr) application 2.0.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2006-1020

Disclosure Date: March 07, 2006 (last updated February 22, 2025)
SQL injection vulnerability in forumlib.php in Johnny_Vegas Vegas Forum 1.0 allows remote attackers to execute arbitrary SQL commands via the postid parameter.
0
Attacker Value
Unknown

CVE-2005-2610

Disclosure Date: August 17, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in index.php in VegaDNS 0.8.1, 0.9.8, and possibly other versions, allows remote attackers to inject arbitrary web script or HTML via the message parameter.
0
Attacker Value
Unknown

CVE-2005-2609

Disclosure Date: August 17, 2005 (last updated February 22, 2025)
index.php in VegaDNS 0.8.1, 0.9.8, and possibly other versions, allows remote attackers to obtain the full server path via an invalid VDNS_Sessid parameter.
0