Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown

CVE-2022-47166

Disclosure Date: March 13, 2023 (last updated November 08, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in voidCoders Void Contact Form 7 Widget For Elementor Page Builder plugin <= 2.1.1 versions.
Attacker Value
Unknown

CVE-2021-20784

Disclosure Date: July 14, 2021 (last updated February 23, 2025)
HTTP header injection vulnerability in Everything version 1.0, 1.1, and 1.2 except the Lite version may allow a remote attacker to inject an arbitrary script or alter the website that uses the product.
Attacker Value
Unknown

CVE-2021-25899

Disclosure Date: April 23, 2021 (last updated February 22, 2025)
An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. An unauthenticated attacker can send a crafted HTTP request to perform a blind time-based SQL Injection. The vulnerable parameter is param1.
Attacker Value
Unknown

CVE-2021-25898

Disclosure Date: April 23, 2021 (last updated February 22, 2025)
An issue was discovered in svc-login.php in Void Aural Rec Monitor 9.0.0.1. Passwords are stored in unencrypted source-code text files. This was noted when accessing the svc-login.php file. The value is used to authenticate a high-privileged user upon authenticating with the server.
Attacker Value
Unknown

CVE-2020-24567

Disclosure Date: August 21, 2020 (last updated November 08, 2023)
voidtools Everything before 1.4.1 Beta Nightly 2020-08-18 allows privilege escalation via a Trojan horse urlmon.dll file in the installation directory. NOTE: this is only relevant if low-privileged users can write to the installation directory, which may be considered a site-specific configuration error
Attacker Value
Unknown

CVE-2018-16982

Disclosure Date: September 13, 2018 (last updated November 27, 2024)
Open Chinese Convert (OpenCC) 1.0.5 allows attackers to cause a denial of service (segmentation fault) because BinaryDict::NewFromFile in BinaryDict.cpp may have out-of-bounds keyOffset and valueOffset values via a crafted .ocd file.
0
Attacker Value
Unknown

CVE-2015-7777

Disclosure Date: November 21, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in index.php in JosephErnest Void before 2015-10-02 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.
0