Show filters
285 Total Results
Displaying 121-130 of 285
Sort by:
Attacker Value
Unknown
CVE-2020-23618
Disclosure Date: May 02, 2022 (last updated February 23, 2025)
A reflected cross site scripting (XSS) vulnerability in Xtend Voice Logger 1.0 allows attackers to execute arbitrary web scripts or HTML, via the path of the error page.
0
Attacker Value
Unknown
CVE-2022-29499
Disclosure Date: April 26, 2022 (last updated February 23, 2025)
The Service Appliance component in Mitel MiVoice Connect through 19.2 SP3 allows remote code execution because of incorrect data validation. The Service Appliances are SA 100, SA 400, and Virtual SA.
0
Attacker Value
Unknown
CVE-2022-26143
Disclosure Date: March 10, 2022 (last updated February 23, 2025)
The TP-240 (aka tp240dvr) component in Mitel MiCollab before 9.4 SP1 FP1 and MiVoice Business Express through 8.1 allows remote attackers to obtain sensitive information and cause a denial of service (performance degradation and excessive outbound traffic). This was exploited in the wild in February and March 2022 for the TP240PhoneHome DDoS attack.
0
Attacker Value
Unknown
CVE-2022-23835
Disclosure Date: February 25, 2022 (last updated February 23, 2025)
The Visual Voice Mail (VVM) application through 2022-02-24 for Android allows persistent access if an attacker temporarily controls an application that has the READ_SMS permission, and reads an IMAP credentialing message that is (by design) not displayed to the victim within the AOSP SMS/MMS messaging application. (Often, the IMAP credentials are usable to listen to voice mail messages sent before the vulnerability was exploited, in addition to new ones.) NOTE: some vendors characterize this as not a "concrete and exploitable risk.
0
Attacker Value
Unknown
CVE-2021-24991
Disclosure Date: January 03, 2022 (last updated February 23, 2025)
The WooCommerce PDF Invoices & Packing Slips WordPress plugin before 2.10.5 does not escape the tab and section parameters before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting in the admin dashboard
0
Attacker Value
Unknown
CVE-2021-36723
Disclosure Date: December 28, 2021 (last updated February 23, 2025)
Emuse - eServices / eNvoice Exposure Of Private Personal Information due to lack of identification mechanisms and predictable IDs an attacker can scrape all the files on the service.
0
Attacker Value
Unknown
CVE-2021-36722
Disclosure Date: December 28, 2021 (last updated February 23, 2025)
Emuse - eServices / eNvoice SQL injection can be used in various ways ranging from bypassing login authentication or dumping the whole database to full RCE on the affected endpoints. The SQLi caused by CWE-209: Generation of Error Message Containig Sensetive Information, showing parts of the aspx code and the webroot location , information an attacker can leverage to further compromise the host.
0
Attacker Value
Unknown
CVE-2021-3977
Disclosure Date: December 24, 2021 (last updated February 23, 2025)
invoiceninja is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
0
Attacker Value
Unknown
CVE-2021-45105
Disclosure Date: December 18, 2021 (last updated February 23, 2025)
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
0
Attacker Value
Unknown
CVE-2021-39315
Disclosure Date: December 13, 2021 (last updated February 23, 2025)
The Magic Post Voice WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the ids parameter found in the ~/inc/admin/main.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 1.2.
0