Show filters
60 Total Results
Displaying 11-20 of 60
Sort by:
Attacker Value
Unknown
CVE-2023-28882
Disclosure Date: April 28, 2023 (last updated October 08, 2023)
Trustwave ModSecurity 3.0.5 through 3.0.8 before 3.0.9 allows a denial of service (worker crash and unresponsiveness) because some inputs cause a segfault in the Transaction class for some configurations.
0
Attacker Value
Unknown
CVE-2022-4681
Disclosure Date: February 06, 2023 (last updated October 08, 2023)
The Hide My WP WordPress plugin before 6.2.9 does not properly sanitize and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.
0
Attacker Value
Unknown
CVE-2023-24021
Disclosure Date: January 20, 2023 (last updated October 08, 2023)
Incorrect handling of '\0' bytes in file uploads in ModSecurity before 2.9.7 may allow for Web Application Firewall bypasses and buffer over-reads on the Web Application Firewall when executing rules that read the FILES_TMP_CONTENT collection.
0
Attacker Value
Unknown
CVE-2022-48279
Disclosure Date: January 20, 2023 (last updated October 08, 2023)
In ModSecurity before 2.9.6 and 3.x before 3.0.8, HTTP multipart requests were incorrectly parsed and could bypass the Web Application Firewall. NOTE: this is related to CVE-2022-39956 but can be considered independent changes to the ModSecurity (C language) codebase.
0
Attacker Value
Unknown
CVE-2022-34907
Disclosure Date: July 25, 2022 (last updated February 24, 2025)
An authentication bypass vulnerability exists in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to gain access to the system with the highest authority possible and gain full control over the FileWave platform.
0
Attacker Value
Unknown
CVE-2022-34906
Disclosure Date: July 25, 2022 (last updated February 24, 2025)
A hard-coded cryptographic key is used in FileWave before 14.6.3 and 14.7.x before 14.7.2. Exploitation could allow an unauthenticated actor to decrypt sensitive information saved in FileWave, and even send crafted requests.
0
Attacker Value
Unknown
CVE-2018-17240
Disclosure Date: June 10, 2022 (last updated February 23, 2025)
There is a memory dump vulnerability on Netwave IP camera devices at //proc/kcore that allows an unauthenticated attacker to exfiltrate sensitive information from the network configuration (e.g., username and password).
0
Attacker Value
Unknown
CVE-2021-42717
Disclosure Date: December 07, 2021 (last updated February 23, 2025)
ModSecurity 3.x through 3.0.5 mishandles excessively nested JSON objects. Crafted JSON objects with nesting tens-of-thousands deep could result in the web server being unable to service legitimate requests. Even a moderately large (e.g., 300KB) HTTP request can occupy one of the limited NGINX worker processes for minutes and consume almost all of the available CPU on the machine. Modsecurity 2 is similarly vulnerable: the affected versions include 2.8.0 through 2.9.4.
0
Attacker Value
Unknown
CVE-2021-36917
Disclosure Date: November 24, 2021 (last updated February 23, 2025)
WordPress Hide My WP plugin (versions <= 6.2.3) can be deactivated by any unauthenticated user. It is possible to retrieve a reset token which can then be used to deactivate the plugin.
0
Attacker Value
Unknown
CVE-2021-36916
Disclosure Date: November 24, 2021 (last updated February 23, 2025)
The SQL injection vulnerability in the Hide My WP WordPress plugin (versions <= 6.2.3) is possible because of how the IP address is retrieved and used inside a SQL query. The function "hmwp_get_user_ip" tries to retrieve the IP address from multiple headers, including IP address headers that the user can spoof, such as "X-Forwarded-For." As a result, the malicious payload supplied in one of these IP address headers will be directly inserted into the SQL query, making SQL injection possible.
0