Show filters
356 Total Results
Displaying 131-140 of 356
Sort by:
Attacker Value
Unknown

CVE-2021-45715

Disclosure Date: December 26, 2021 (last updated February 23, 2025)
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_window_function has a use-after-free.
Attacker Value
Unknown

CVE-2021-45714

Disclosure Date: December 26, 2021 (last updated February 23, 2025)
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_aggregate_function has a use-after-free.
Attacker Value
Unknown

CVE-2021-45713

Disclosure Date: December 26, 2021 (last updated February 23, 2025)
An issue was discovered in the rusqlite crate 0.25.x before 0.25.4 and 0.26.x before 0.26.2 for Rust. create_scalar_function has a use-after-free.
Attacker Value
Unknown

CVE-2020-35037

Disclosure Date: December 01, 2021 (last updated February 23, 2025)
The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape some search parameter before outputing them in pages, which could lead to Cross-Site Scripting issues
Attacker Value
Unknown

CVE-2020-35012

Disclosure Date: December 01, 2021 (last updated February 23, 2025)
The Events Manager WordPress plugin before 5.9.8 does not sanitise and escape a parameter before using it in a SQL statement, leading to an SQL Injection
Attacker Value
Unknown

CVE-2021-20846

Disclosure Date: November 24, 2021 (last updated February 23, 2025)
Cross-site request forgery (CSRF) vulnerability in Push Notifications for WordPress (Lite) versions prior to 6.0.1 allows a remote attacker to hijack the authentication of an administrator and conduct an arbitrary operation via a specially crafted web page.
Attacker Value
Unknown

CVE-2021-24701

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
The Quiz Tool Lite WordPress plugin through 2.3.15 does not sanitize multiple input fields used when creating or managing quizzes and in other setting options, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Attacker Value
Unknown

CVE-2021-24769

Disclosure Date: October 25, 2021 (last updated February 23, 2025)
The Permalink Manager Lite WordPress plugin before 2.2.13.1 does not validate and escape the orderby parameter before using it in a SQL statement in the Permalink Manager page, leading to a SQL Injection
Attacker Value
Unknown

CVE-2021-23404

Disclosure Date: September 08, 2021 (last updated February 23, 2025)
This affects all versions of package sqlite-web. The SQL dashboard area allows sensitive actions to be performed without validating that the request originated from the application. This could enable an attacker to trick a user into performing these actions unknowingly through a Cross Site Request Forgery (CSRF) attack.
Attacker Value
Unknown

CVE-2021-36690

Disclosure Date: August 24, 2021 (last updated November 08, 2023)
A segmentation fault can occur in the sqlite3.exe command-line component of SQLite 3.36.0 via the idxGetTableInfo function when there is a crafted SQL query. NOTE: the vendor disputes the relevance of this report because a sqlite3.exe user already has full privileges (e.g., is intentionally allowed to execute commands). This report does NOT imply any problem in the SQLite library.