Show filters
267 Total Results
Displaying 141-150 of 267
Sort by:
Attacker Value
Unknown

CVE-2022-34531

Disclosure Date: July 29, 2022 (last updated October 08, 2023)
DedeCMS v5.7.95 was discovered to contain a remote code execution (RCE) vulnerability via the component mytag_ main.php.
Attacker Value
Unknown

CVE-2020-28459

Disclosure Date: July 25, 2022 (last updated February 24, 2025)
This affects all versions of package markdown-it-decorate. An attacker can add an event handler or use javascript:xxx for the link.
Attacker Value
Unknown

CVE-2019-10800

Disclosure Date: July 13, 2022 (last updated February 24, 2025)
This affects the package codecov before 2.0.16. The vulnerability occurs due to not sanitizing gcov arguments before being being provided to the popen method.
Attacker Value
Unknown

CVE-2022-32265

Disclosure Date: June 03, 2022 (last updated October 07, 2023)
qDecoder before 12.1.0 does not ensure that the percent character is followed by two hex digits for URL decoding.
Attacker Value
Unknown

CVE-2022-30508

Disclosure Date: May 26, 2022 (last updated February 23, 2025)
DedeCMS v5.7.93 was discovered to contain arbitrary file deletion vulnerability in upload.php via the delete parameter.
Attacker Value
Unknown

CVE-2022-1255

Disclosure Date: May 02, 2022 (last updated February 23, 2025)
The Import and export users and customers WordPress plugin before 1.19.2.1 does not sanitise and escaped imported CSV data, which could allow high privilege users to import malicious javascript code and lead to Stored Cross-Site Scripting issues
Attacker Value
Unknown

CVE-2022-23337

Disclosure Date: February 14, 2022 (last updated February 23, 2025)
DedeCMS v5.7.87 was discovered to contain a SQL injection vulnerability in article_coonepage_rule.php via the ids parameter.
Attacker Value
Unknown

CVE-2021-37401

Disclosure Date: December 28, 2021 (last updated February 23, 2025)
An attacker may obtain the user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a result, the PLC user program may be uploaded, altered, and/or downloaded.
Attacker Value
Unknown

CVE-2021-37400

Disclosure Date: December 28, 2021 (last updated February 23, 2025)
An attacker may obtain the user credentials from the communication between the PLC and the software. As a result, the PLC user program may be uploaded, altered, and/or downloaded.
Attacker Value
Unknown

CVE-2021-20827

Disclosure Date: December 24, 2021 (last updated February 23, 2025)
Plaintext storage of a password vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.19.1 and earlier, WindEDIT Lite v1.3.1 and earlier, and Data File Manager v2.12.1 and earlier) allows an attacker to obtain the PLC Web server user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a result, the attacker may access the PLC Web server and hijack the PLC, and manipulation of the PLC output and/or suspension of the PLC may be conducted.