Show filters
356 Total Results
Displaying 141-150 of 356
Sort by:
Attacker Value
Unknown

CVE-2020-23234

Disclosure Date: July 26, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerabiity exists in LavaLite CMS 5.8.0 via the Menu Blocks feature, which can be bypassed by using HTML event handlers, such as "ontoggle,".
Attacker Value
Unknown

CVE-2020-23700

Disclosure Date: July 07, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability in LavaLite-CMS 5.8.0 via the Menu Links feature.
Attacker Value
Unknown

CVE-2020-36396

Disclosure Date: July 02, 2021 (last updated February 22, 2025)
A stored cross site scripting (XSS) vulnerability in the /admin/roles/role component of LavaLite 5.8.0 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "New" parameter.
Attacker Value
Unknown

CVE-2020-36395

Disclosure Date: July 02, 2021 (last updated February 22, 2025)
A stored cross site scripting (XSS) vulnerability in the /admin/user/team component of LavaLite 5.8.0 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "New" parameter.
Attacker Value
Unknown

CVE-2020-36397

Disclosure Date: July 02, 2021 (last updated February 22, 2025)
A stored cross site scripting (XSS) vulnerability in the /admin/contact/contact component of LavaLite 5.8.0 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the "New" parameter.
Attacker Value
Unknown

CVE-2020-26801

Disclosure Date: June 25, 2021 (last updated February 22, 2025)
A stored cross-site scripting (XSS) vulnerability was discovered in /Forms/device_vars_1 on TrippLite SU2200RTXL2Ua with firmware version 12.04.0055. This vulnerability allows authenticated attackers to obtain other users' information via a crafted POST request.
Attacker Value
Unknown

CVE-2020-28124

Disclosure Date: April 14, 2021 (last updated February 22, 2025)
Cross Site Scripting (XSS) in LavaLite 5.8.0 via the Address field.
Attacker Value
Unknown

CVE-2021-26758

Disclosure Date: April 07, 2021 (last updated February 22, 2025)
Privilege Escalation in LiteSpeed Technologies OpenLiteSpeed web server version 1.7.8 allows attackers to gain root terminal access and execute commands on the host system.
Attacker Value
Unknown

CVE-2021-20227

Disclosure Date: March 23, 2021 (last updated February 22, 2025)
A flaw was found in SQLite's SELECT query functionality (src/select.c). This flaw allows an attacker who is capable of running SQL queries locally on the SQLite database to cause a denial of service or possible code execution by triggering a use-after-free. The highest threat from this vulnerability is to system availability.
Attacker Value
Unknown

CVE-2020-35870

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the rusqlite crate before 0.23.0 for Rust. Memory safety can be violated via an Auxdata API use-after-free.