Show filters
596 Total Results
Displaying 101-110 of 596
Sort by:
Attacker Value
Unknown

CVE-2022-38201

Disclosure Date: November 15, 2022 (last updated February 24, 2025)
An unvalidated redirect vulnerability exists in Esri Portal for ArcGIS Quick Capture Web Designer versions 10.8.1 to 10.9.1. A remote, unauthenticated attacker can potentially induce an unsuspecting authenticated user to access an an attacker controlled domain.
Attacker Value
Unknown

CVE-2022-39860

Disclosure Date: October 07, 2022 (last updated February 24, 2025)
Improper access control vulnerability in QuickShare prior to version 13.2.3.5 allows attackers to access sensitive information via implicit broadcast.
Attacker Value
Unknown

CVE-2022-1792

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The Quick Subscribe WordPress plugin through 1.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and leading to Stored XSS due to the lack of sanitisation and escaping in some of them
Attacker Value
Unknown

CVE-2022-30745

Disclosure Date: June 07, 2022 (last updated February 23, 2025)
Improper access control vulnerability in Quick Share prior to version 13.1.2.4 allows attacker to access internal files in Quick Share.
Attacker Value
Unknown

CVE-2022-29923

Disclosure Date: May 12, 2022 (last updated February 24, 2025)
Cross-site Scripting (XSS) vulnerability in ThingsForRestaurants Quick Restaurant Reservations (WordPress plugin) allows Reflected XSS.This issue affects Quick Restaurant Reservations (WordPress plugin): from n/a through 1.4.1.
Attacker Value
Unknown

CVE-2021-23247

Disclosure Date: April 01, 2022 (last updated February 23, 2025)
A command injection vulerability found in quick game engine allows arbitrary remote code in quick app. Allows remote attacke0rs to gain arbitrary code execution in quick game engine
Attacker Value
Unknown

CVE-2022-24286

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
Acer QuickAccess 2.01.300x before 2.01.3030 and 3.00.30xx before 3.00.3038 contains a local privilege escalation vulnerability. The user process communicates with a service of system authority through a named pipe. In this case, the Named Pipe is also given Read and Write rights to the general user. In addition, the service program does not verify the user when communicating. A thread may exist with a specific command. When the path of the program to be executed is sent, there is a local privilege escalation in which the service program executes the path with system privileges.
Attacker Value
Unknown

CVE-2021-43970

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
An arbitrary file upload vulnerability exists in albumimages.jsp in Quicklert for Digium 10.0.0 (1043) via a .mp3;.jsp filename for a file that begins with audio data bytes. It allows an authenticated (low privileged) attacker to execute remote code on the target server within the context of application's permissions (SYSTEM).
Attacker Value
Unknown

CVE-2021-43969

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
The login.jsp page of Quicklert for Digium 10.0.0 (1043) is affected by both Blind SQL Injection with Out-of-Band Interaction (DNS) and Blind Time-Based SQL Injections. Exploitation can be used to disclose all data within the database (up to and including the administrative accounts' login IDs and passwords) via the login.jsp uname parameter.
Attacker Value
Unknown

CVE-2021-45281

Disclosure Date: February 07, 2022 (last updated February 23, 2025)
QuickBox Pro v2.4.8 contains a cross-site scripting (XSS) vulnerability at "adminuseredit.php?usertoedit=XSS", as the user supplied input for the value of this parameter is not properly sanitized.