Show filters
175 Total Results
Displaying 121-130 of 175
Sort by:
Attacker Value
Unknown
CVE-2019-15842
Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The easy-pdf-restaurant-menu-upload plugin before 1.1.2 for WordPress has XSS.
0
Attacker Value
Unknown
CVE-2019-15819
Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The nd-restaurant-reservations plugin before 1.5 for WordPress has no requirement for nd_rst_import_settings_php_function authentication.
0
Attacker Value
Unknown
Avaya Aura Conferencing XSS
Disclosure Date: July 31, 2019 (last updated November 27, 2024)
A Cross-Site Scripting (XSS) vulnerability in the Web UI of Avaya Aura Conferencing may allow code execution and potentially disclose sensitive information. Affected versions of Avaya Aura Conferencing include all 8.x versions prior to 8.0 SP14 (8.0.14). Prior versions not listed were not evaluated.
0
Attacker Value
Unknown
Communication Manager Denial of Service
Disclosure Date: February 01, 2019 (last updated November 27, 2024)
A vulnerability in the "capro" (Call Processor) process component of Avaya Aura Communication Manager could allow a remote, unauthenticated user to cause denial of service. Affected versions include 6.3.x, all 7.x versions prior to 7.1.3.2, and all 8.x versions prior to 8.0.1.
0
Attacker Value
Unknown
CVE-2018-18537
Disclosure Date: December 26, 2018 (last updated November 27, 2024)
The GLCKIo low-level driver in ASUS Aura Sync v1.07.22 and earlier exposes a path to write an arbitrary DWORD to an arbitrary address.
0
Attacker Value
Unknown
CVE-2018-18535
Disclosure Date: December 26, 2018 (last updated November 27, 2024)
The Asusgio low-level driver in ASUS Aura Sync v1.07.22 and earlier exposes functionality to read and write Machine Specific Registers (MSRs). This could be leveraged to execute arbitrary ring-0 code.
0
Attacker Value
Unknown
CVE-2018-18536
Disclosure Date: December 26, 2018 (last updated November 27, 2024)
The GLCKIo and Asusgio low-level drivers in ASUS Aura Sync v1.07.22 and earlier expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.
0
Attacker Value
Unknown
System Platform Web UI Deserialization
Disclosure Date: October 17, 2018 (last updated November 27, 2024)
A vulnerability in the Web UI component of Avaya Aura System Platform could allow a remote, unauthenticated user to perform a targeted deserialization attack that could result in remote code execution. Affected versions of System Platform includes 6.3.0 through 6.3.9 and 6.4.0 through 6.4.2.
0
Attacker Value
Unknown
Communication Manager Local Administrator PrivEsc
Disclosure Date: September 27, 2018 (last updated November 27, 2024)
A vulnerability in the local system administration component of Avaya Aura Communication Manager can allow an authenticated, privileged user on the local system to gain root privileges. Affected versions include 6.3.x and all 7.x version prior to 7.1.3.1.
0
Attacker Value
Unknown
Orchestration Designer Runtime Config XSS
Disclosure Date: September 21, 2018 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could result in malicious content being returned to the user. Affected versions of Avaya Aura Orchestration Designer include all versions up to 7.2.1.
0