Show filters
180 Total Results
Displaying 121-130 of 180
Sort by:
Attacker Value
Unknown

CVE-2015-9306

Disclosure Date: August 12, 2019 (last updated November 27, 2024)
The wp-ultimate-csv-importer plugin before 3.8.1 for WordPress has XSS.
0
Attacker Value
Unknown

CVE-2018-19498

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
The Simplenia Pages plugin 2.6.0 for Atlassian Bitbucket Server has XSS.
0
Attacker Value
Unknown

CVE-2018-16481

Disclosure Date: February 01, 2019 (last updated November 27, 2024)
A XSS vulnerability was found in html-page <=2.1.1 that allows malicious Javascript code to be executed in the user's browser due to the absence of sanitization of the paths before rendering.
0
Attacker Value
Unknown

CVE-2017-1679

Disclosure Date: September 10, 2018 (last updated November 27, 2024)
IBM OpenPages GRC Platform 7.2, 7.3, 7.4, and 8.0 could allow an attacker to obtain sensitive information from error log files. IBM X-Force ID: 134001.
Attacker Value
Unknown

CVE-2016-0234

Disclosure Date: August 30, 2018 (last updated November 27, 2024)
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 could allow a local user to obtain sensitive information when a previous user has logged out of the system but neglected to close their browser. IBM X-Force ID: 110303.
0
Attacker Value
Unknown

CVE-2018-8171

Disclosure Date: July 11, 2018 (last updated November 27, 2024)
A Security Feature Bypass vulnerability exists in ASP.NET when the number of incorrect login attempts is not validated, aka "ASP.NET Security Feature Bypass Vulnerability." This affects ASP.NET, ASP.NET Core 1.1, ASP.NET Core 1.0, ASP.NET Core 2.0, ASP.NET MVC 5.2.
0
Attacker Value
Unknown

CVE-2016-10526

Disclosure Date: May 31, 2018 (last updated November 26, 2024)
A common setup to deploy to gh-pages on every commit via a CI system is to expose a github token to ENV and to use it directly in the auth part of the url. In module versions < 0.9.1 the auth portion of the url is outputted as part of the grunt tasks logging function. If this output is publicly available then the credentials should be considered compromised.
0
Attacker Value
Unknown

CVE-2018-11580

Disclosure Date: May 31, 2018 (last updated November 26, 2024)
An issue was discovered in mass-pages-posts-creator.php in the MULTIDOTS Mass Pages/Posts Creator plugin 1.2.2 for WordPress. Any logged in user can launch Mass Pages/Posts creation with custom content. There is no nonce or user capability check, so anyone can launch a DoS attack against a site and create hundreds of thousands of posts with custom content.
0
Attacker Value
Unknown

CVE-2018-3744

Disclosure Date: May 29, 2018 (last updated November 26, 2024)
The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the server with cURL.
Attacker Value
Unknown

CVE-2017-1148

Disclosure Date: November 01, 2017 (last updated November 26, 2024)
IBM OpenPages GRC Platform 7.2 and 7.3 with OpenPages Loss Event Entry (LEE) application could allow a user to obtain sensitive information including private APIs that could be used in further attacks against the system. IBM X-Force ID: 122201.
0