Show filters
275 Total Results
Displaying 101-110 of 275
Sort by:
Attacker Value
Unknown
CVE-2023-33284
Disclosure Date: June 07, 2023 (last updated February 25, 2025)
Marval MSM through 14.19.0.12476 and 15.0 has a Remote Code Execution vulnerability. A remote attacker authenticated as any user is able to execute code in context of the web server.
0
Attacker Value
Unknown
CVE-2023-33283
Disclosure Date: June 07, 2023 (last updated February 25, 2025)
Marval MSM through 14.19.0.12476 uses a static encryption key for secrets. An attacker that gains access to encrypted secrets can decrypt them by using this key.
0
Attacker Value
Unknown
CVE-2023-33282
Disclosure Date: June 07, 2023 (last updated February 25, 2025)
Marval MSM through 14.19.0.12476 and 15.0 has a System account with default credentials. A remote attacker is able to login and create a valid session. This makes it possible to make backend calls to endpoints in the application.
0
Attacker Value
Unknown
CVE-2023-26131
Disclosure Date: May 31, 2023 (last updated February 25, 2025)
All versions of the package github.com/xyproto/algernon/engine; all versions of the package github.com/xyproto/algernon/themes are vulnerable to Cross-site Scripting (XSS) via the themes.NoPage(filename, theme) function due to improper user input sanitization. Exploiting this vulnerability is possible when a file/resource is not found.
0
Attacker Value
Unknown
CVE-2022-45144
Disclosure Date: May 17, 2023 (last updated February 25, 2025)
Algoo Tracim before 4.4.2 allows XSS via HTML file upload.
0
Attacker Value
Unknown
CVE-2022-46844
Disclosure Date: May 09, 2023 (last updated February 24, 2025)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in PixelGrade PixFields plugin <= 0.7.0 versions.
0
Attacker Value
Unknown
CVE-2020-36070
Disclosure Date: April 26, 2023 (last updated February 24, 2025)
Insecure Permission vulnerability found in Yoyager v.1.4 and before allows a remote attacker to execute arbitrary code via a crafted .php file to the media component.
0
Attacker Value
Unknown
CVE-2022-4671
Disclosure Date: January 30, 2023 (last updated October 08, 2023)
The PixCodes WordPress plugin before 2.3.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
0
Attacker Value
Unknown
CVE-2015-10022
Disclosure Date: January 07, 2023 (last updated February 24, 2025)
A vulnerability was found in IISH nlgis2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file scripts/etl/custom_import.pl. The manipulation leads to sql injection. The identifier of the patch is 8bdb6fcf7209584eaf1232437f0f53e735b2b34c. It is recommended to apply a patch to fix this issue. The identifier VDB-217609 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2021-4274
Disclosure Date: December 21, 2022 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, has been found in sileht bird-lg. This issue affects some unknown processing of the file templates/layout.html. The manipulation of the argument request_args leads to cross site scripting. The attack may be initiated remotely. The name of the patch is ef6b32c527478fefe7a4436e10b96ee28ed5b308. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216479.
0