Show filters
666 Total Results
Displaying 131-140 of 666
Sort by:
Attacker Value
Unknown
CVE-2022-28028
Disclosure Date: April 21, 2022 (last updated February 23, 2025)
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via /reps/classes/Master.php?f=delete_amenity.
0
Attacker Value
Unknown
CVE-2022-0471
Disclosure Date: April 11, 2022 (last updated February 23, 2025)
The Favicon by RealFaviconGenerator WordPress plugin before 1.3.23 does not properly sanitise and escape the json_result_url parameter before outputting it back in the Favicon admin dashboard, leading to a Reflected Cross-Site Scripting issue
0
Attacker Value
Unknown
CVE-2021-45967
Disclosure Date: March 18, 2022 (last updated February 23, 2025)
An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints.
0
Attacker Value
Unknown
CVE-2022-25399
Disclosure Date: March 02, 2022 (last updated February 23, 2025)
Simple Real Estate Portal System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter.
0
Attacker Value
Unknown
CVE-2022-0193
Disclosure Date: February 14, 2022 (last updated February 23, 2025)
The Complianz WordPress plugin before 6.0.0 does not escape the s parameter before outputting it back in an attribute in an admin page, leading to a Reflected Cross-Site Scripting
0
Attacker Value
Unknown
CVE-2021-39306
Disclosure Date: December 22, 2021 (last updated February 23, 2025)
A stack buffer overflow was discovered on Realtek RTL8195AM device before 2.0.10, it exists in the client code when an attacker sends a big size Authentication challenge text in WEP security.
0
Attacker Value
Unknown
CVE-2021-24750
Disclosure Date: December 21, 2021 (last updated February 23, 2025)
The WP Visitor Statistics (Real Time Traffic) WordPress plugin before 4.8 does not properly sanitise and escape the refUrl in the refDetails AJAX action, available to any authenticated user, which could allow users with a role as low as subscriber to perform SQL injection attacks
0
Attacker Value
Unknown
CVE-2021-45043
Disclosure Date: December 15, 2021 (last updated February 23, 2025)
HD-Network Real-time Monitoring System 2.0 allows ../ directory traversal to read /etc/shadow via the /language/lang s_Language parameter.
0
Attacker Value
Unknown
CVE-2021-43573
Disclosure Date: November 11, 2021 (last updated February 23, 2025)
A buffer overflow was discovered on Realtek RTL8195AM devices before 2.0.10. It exists in the client code when processing a malformed IE length of HT capability information in the Beacon and Association response frame.
0
Attacker Value
Unknown
CVE-2021-36924
Disclosure Date: November 02, 2021 (last updated February 23, 2025)
RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve a pool overflow (leading to Escalation of Privileges, Denial of Service, and Code Execution) via a crafted Device IO Control packet to a device.
0