Show filters
182 Total Results
Displaying 131-140 of 182
Sort by:
Attacker Value
Unknown
CVE-2020-14961
Disclosure Date: June 22, 2020 (last updated November 28, 2024)
Concrete5 before 8.5.3 does not constrain the sort direction to a valid asc or desc value.
0
Attacker Value
Unknown
CVE-2011-3183
Disclosure Date: January 14, 2020 (last updated February 21, 2025)
A Cross-Site Scripting (XSS) vulnerability exists in the rcID parameter in Concrete CMS 5.4.1.1 and earlier.
0
Attacker Value
Unknown
CVE-2017-18600
Disclosure Date: September 10, 2019 (last updated November 27, 2024)
The formcraft3 plugin before 3.4 for WordPress has stored XSS via the "New Form > Heading > Heading Text" field.
0
Attacker Value
Unknown
CVE-2019-15114
Disclosure Date: August 16, 2019 (last updated November 27, 2024)
The formcraft-form-builder plugin before 1.2.2 for WordPress has CSRF.
0
Attacker Value
Unknown
CVE-2018-19146
Disclosure Date: June 17, 2019 (last updated November 27, 2024)
Concrete5 8.4.3 has XSS because config/concrete.php allows uploads (by administrators) of SVG files that may contain HTML data with a SCRIPT element.
0
Attacker Value
Unknown
CVE-2019-5920
Disclosure Date: March 12, 2019 (last updated November 27, 2024)
Cross-site request forgery (CSRF) vulnerability in FormCraft 1.2.1 and earlier allows remote attackers to hijack the authentication of administrators via a specially crafted page.
0
Attacker Value
Unknown
CVE-2018-14087
Disclosure Date: July 16, 2018 (last updated November 27, 2024)
An issue was discovered in a smart contract implementation for EUC (EUC), an Ethereum token. The contract has an integer overflow. If the owner sets the value of buyPrice to a large number in setPrices() then the "msg.value * buyPrice" will cause an integer overflow in the fallback function.
0
Attacker Value
Unknown
CVE-2018-13790
Disclosure Date: July 09, 2018 (last updated November 27, 2024)
A Server Side Request Forgery (SSRF) vulnerability in tools/files/importers/remote.php in concrete5 8.2.0 can lead to attacks on the local network and mapping of the internal network, because of URL functionality on the File Manager page.
0
Attacker Value
Unknown
CVE-2018-13070
Disclosure Date: July 03, 2018 (last updated November 26, 2024)
The mintToken function of a smart contract implementation for EncryptedToken (ECC), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
0
Attacker Value
Unknown
CVE-2017-17668
Disclosure Date: March 20, 2018 (last updated November 26, 2024)
Memory write mechanism in NCR S1 Dispenser controller before firmware version 0x0156 allows an unauthenticated user to upgrade or downgrade the firmware of the device, including to older versions with known vulnerabilities.
0