Show filters
207 Total Results
Displaying 101-110 of 207
Sort by:
Attacker Value
Unknown
CVE-2020-14496
Disclosure Date: May 19, 2022 (last updated February 23, 2025)
Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and execute malicious programs, which could cause a denial-of-service condition, and allow information to be disclosed, tampered with, and/or destroyed.
0
Attacker Value
Unknown
CVE-2021-4096
Disclosure Date: April 19, 2022 (last updated February 23, 2025)
The Fancy Product Designer plugin for WordPress is vulnerable to Cross-Site Request Forgery via the FPD_Admin_Import class that makes it possible for attackers to upload malicious files that could be used to gain webshell access to a server in versions up to, and including, 4.7.5.
0
Attacker Value
Unknown
CVE-2022-23985
Disclosure Date: February 22, 2022 (last updated February 23, 2025)
The affected product is vulnerable to an out-of-bounds write while processing project files, which allows an attacker to craft a project file that would allow arbitrary code execution.
0
Attacker Value
Unknown
CVE-2022-25170
Disclosure Date: February 22, 2022 (last updated February 23, 2025)
The affected product is vulnerable to a stack-based buffer overflow while processing project files, which may allow an attacker to execute arbitrary code
0
Attacker Value
Unknown
CVE-2022-21209
Disclosure Date: February 22, 2022 (last updated February 23, 2025)
The affected product is vulnerable to an out-of-bounds read while processing project files, which allows an attacker to craft a project file that would allow arbitrary code execution.
0
Attacker Value
Unknown
CVE-2021-24867
Disclosure Date: February 21, 2022 (last updated February 23, 2025)
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
0
Attacker Value
Unknown
CVE-2021-4134
Disclosure Date: February 16, 2022 (last updated February 23, 2025)
The Fancy Product Designer WordPress plugin is vulnerable to SQL Injection due to insufficient escaping and parameterization of the ID parameter found in the ~/inc/api/class-view.php file which allows attackers with administrative level permissions to inject arbitrary SQL queries to obtain sensitive information, in versions up to and including 4.7.4.
0
Attacker Value
Unknown
CVE-2021-22817
Disclosure Date: February 09, 2022 (last updated February 23, 2025)
A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation. Affected Product: Harmony/Magelis iPC Series (All Versions), Vijeo Designer (All Versions prior to V6.2 SP11 Multiple HotFix 4), Vijeo Designer Basic (All Versions prior to V1.2.1)
0
Attacker Value
Unknown
CVE-2022-0218
Disclosure Date: February 04, 2022 (last updated February 23, 2025)
The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings due to a missing capability check on the /themesettings REST-API endpoint found in the ~/includes/class-template-designer.php file, in versions up to and including 3.0.9. This makes it possible for attackers with no privileges to execute the endpoint and add malicious JavaScript to a vulnerable WordPress site.
0
Attacker Value
Unknown
CVE-2021-42703
Disclosure Date: November 09, 2021 (last updated February 23, 2025)
This vulnerability could allow an attacker to send malicious Javascript code resulting in hijacking of the user’s cookie/session tokens, redirecting the user to a malicious webpage, and performing unintended browser action.
0