Show filters
215 Total Results
Displaying 151-160 of 215
Sort by:
Attacker Value
Unknown

CVE-2022-41904

Disclosure Date: November 11, 2022 (last updated February 24, 2025)
Element iOS is an iOS Matrix client provided by Element. It is based on MatrixSDK. Prior to version 1.9.7, events encrypted using Megolm for which trust could not be established did not get decorated accordingly (with warning shields). Therefore a malicious homeserver could inject messages into the room without the user being alerted that the messages were not sent by a verified group member, even if the user has previously verified all group members. This issue has been patched in Element iOS 1.9.7. There are currently no known workarounds.
Attacker Value
Unknown

CVE-2022-29602

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
The gridelements (aka Grid Elements) extension through 7.6.1, 8.x through 8.7.0, 9.x through 9.7.0, and 10.x through 10.2.0 extension for TYPO3 allows XSS.
Attacker Value
Unknown

CVE-2022-29455

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
DOM-based Reflected Cross-Site Scripting (XSS) vulnerability in Elementor's Elementor Website Builder plugin <= 3.5.5 versions.
Attacker Value
Unknown

CVE-2022-27103

Disclosure Date: April 25, 2022 (last updated February 23, 2025)
element-plus 2.0.5 is vulnerable to Cross Site Scripting (XSS) via el-table-column.
Attacker Value
Unknown

CVE-2022-1329

Disclosure Date: April 19, 2022 (last updated February 23, 2025)
The Elementor Website Builder plugin for WordPress is vulnerable to unauthorized execution of several AJAX actions due to a missing capability check in the ~/core/app/modules/onboarding/module.php file that make it possible for attackers to modify site data in addition to uploading malicious files that can be used to obtain remote code execution, in versions 3.6.0 to 3.6.2.
Attacker Value
Unknown

CVE-2022-24573

Disclosure Date: March 03, 2022 (last updated February 23, 2025)
A stored cross-site scripting (XSS) vulnerability in the admin interface in Element-IT HTTP Commander 7.0.0 allows unauthenticated users to get admin access by injecting a malicious script in the User-Agent field.
Attacker Value
Unknown

CVE-2022-23597

Disclosure Date: February 01, 2022 (last updated February 23, 2025)
Element Desktop is a Matrix client for desktop platforms with Element Web at its core. Element Desktop before 1.9.7 is vulnerable to a remote program execution bug with user interaction. The exploit is non-trivial and requires clicking on a malicious link, followed by another button click. To the best of our knowledge, the vulnerability has never been exploited in the wild. If you are using Element Desktop < 1.9.7, we recommend upgrading at your earliest convenience. If successfully exploited, the vulnerability allows an attacker to specify a file path of a binary on the victim's computer which then gets executed. Notably, the attacker does *not* have the ability to specify program arguments. However, in certain unspecified configurations, the attacker may be able to specify an URI instead of a file path which then gets handled using standard platform mechanisms. These may allow exploiting further vulnerabilities in those mechanisms, potentially leading to arbitrary code execution.
Attacker Value
Unknown

CVE-2021-40813

Disclosure Date: January 13, 2022 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability in the "Zip content" feature in Element-IT HTTP Commander 3.1.9 allows remote authenticated users to inject arbitrary web script or HTML via filenames.
Attacker Value
Unknown

CVE-2021-24891

Disclosure Date: November 23, 2021 (last updated February 23, 2025)
The Elementor Website Builder WordPress plugin before 3.4.8 does not sanitise or escape user input appended to the DOM via a malicious hash, resulting in a DOM Cross-Site Scripting issue.
Attacker Value
Unknown

CVE-2021-41592

Disclosure Date: October 04, 2021 (last updated February 23, 2025)
Blockstream c-lightning through 0.10.1 allows loss of funds because of dust HTLC exposure.