Show filters
666 Total Results
Displaying 101-110 of 666
Sort by:
Attacker Value
Unknown

CVE-2023-1069

Disclosure Date: March 27, 2023 (last updated October 08, 2023)
The Complianz WordPress plugin before 6.4.2, Complianz Premium WordPress plugin before 6.4.2 do not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
Attacker Value
Unknown

CVE-2023-0364

Disclosure Date: March 20, 2023 (last updated October 08, 2023)
The real.Kit WordPress plugin before 5.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2023-24078

Disclosure Date: February 17, 2023 (last updated February 24, 2025)
Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the component /FuguHub/cmsdocs/.
Attacker Value
Unknown

CVE-2023-0159

Disclosure Date: February 13, 2023 (last updated December 05, 2023)
The Extensive VC Addons for WPBakery page builder WordPress plugin before 1.9.1 does not validate a parameter passed to the php extract function when loading templates, allowing an unauthenticated attacker to override the template path to read arbitrary files from the hosts file system. This may be escalated to RCE using PHP filter chains.
Attacker Value
Unknown

CVE-2022-40740

Disclosure Date: December 30, 2022 (last updated February 24, 2025)
Realtek GPON router has insufficient filtering for special characters. A remote attacker authenticated as an administrator can exploit this vulnerability to perform command injection attacks, to execute arbitrary system command, manipulate system or disrupt service.
Attacker Value
Unknown

CVE-2022-32967

Disclosure Date: November 29, 2022 (last updated February 24, 2025)
RTL8111EP-CG/RTL8111FP-CG DASH function has hard-coded password. An unauthenticated physical attacker can use the hard-coded default password during system reboot triggered by other user, to acquire partial system information such as serial number and server information.
Attacker Value
Unknown

CVE-2022-32966

Disclosure Date: November 29, 2022 (last updated February 24, 2025)
RTL8168FP-CG Dash remote management function has missing authorization. An unauthenticated attacker within the adjacent network can connect to DASH service port to disrupt service.
Attacker Value
Unknown

CVE-2022-3494

Disclosure Date: November 07, 2022 (last updated February 24, 2025)
The Complianz WordPress plugin before 6.3.4, and Complianz Premium WordPress plugin before 6.3.6 allow a translators to inject arbitrary SQL through an unsanitized translation. SQL can be injected through an infected translation file, or by a user with a translator role through translation plugins such as Loco Translate or WPML.
Attacker Value
Unknown

CVE-2022-3442

Disclosure Date: October 10, 2022 (last updated February 24, 2025)
A vulnerability was found in Crealogix EBICS 7.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /ebics-server/ebics.aspx. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 7.1 is able to address this issue. It is recommended to upgrade the affected component. VDB-210374 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-41975

Disclosure Date: September 30, 2022 (last updated October 08, 2023)
RealVNC VNC Server before 6.11.0 and VNC Viewer before 6.22.826 on Windows allow local privilege escalation via MSI installer Repair mode.