Show filters
207 Total Results
Displaying 101-110 of 207
Sort by:
Attacker Value
Unknown

CVE-2020-14496

Disclosure Date: May 19, 2022 (last updated February 23, 2025)
Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and execute malicious programs, which could cause a denial-of-service condition, and allow information to be disclosed, tampered with, and/or destroyed.
Attacker Value
Unknown

CVE-2021-4096

Disclosure Date: April 19, 2022 (last updated February 23, 2025)
The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import class that makes it possible for attackers to upload malicious files that could be used to gain webshell access to a server in versions up to, and including, 4.7.5.
Attacker Value
Unknown

CVE-2022-23985

Disclosure Date: February 22, 2022 (last updated February 23, 2025)
The affected product is vulnerable to an out-of-bounds write while processing project files, which allows an attacker to craft a project file that would allow arbitrary code execution.
Attacker Value
Unknown

CVE-2022-25170

Disclosure Date: February 22, 2022 (last updated February 23, 2025)
The affected product is vulnerable to a stack-based buffer overflow while processing project files, which may allow an attacker to execute arbitrary code
Attacker Value
Unknown

CVE-2022-21209

Disclosure Date: February 22, 2022 (last updated February 23, 2025)
The affected product is vulnerable to an out-of-bounds read while processing project files, which allows an attacker to craft a project file that would allow arbitrary code execution.
Attacker Value
Unknown

CVE-2021-24867

Disclosure Date: February 21, 2022 (last updated February 23, 2025)
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
Attacker Value
Unknown

CVE-2021-4134

Disclosure Date: February 16, 2022 (last updated February 23, 2025)
The Fancy Product Designer WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the ID parameter found in the ~/inc/api/class-view.php file which allows attackers with administrative level permissions to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 4.7.4.
Attacker Value
Unknown

CVE-2021-22817

Disclosure Date: February 09, 2022 (last updated February 23, 2025)
A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation. Affected Product: Harmony/Magelis iPC Series (All Versions), Vijeo Designer (All Versions prior to V6.2 SP11 Multiple HotFix 4), Vijeo Designer Basic (All Versions prior to V1.2.1)
Attacker Value
Unknown

CVE-2022-0218

Disclosure Date: February 04, 2022 (last updated February 23, 2025)
The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings due to a missing capability check on the /themesettings REST-API endpoint found in the ~/includes/class-template-designer.php file, in versions up to and including 3.0.9. This makes it possible for attackers with no privileges to execute the endpoint and add malicious JavaScript to a vulnerable WordPress site.
Attacker Value
Unknown

CVE-2021-42703

Disclosure Date: November 09, 2021 (last updated February 23, 2025)
This vulnerability could allow an attacker to send malicious Javascript code resulting in hijacking of the user’s cookie/session tokens, redirecting the user to a malicious webpage, and performing unintended browser action.