Show filters
727 Total Results
Displaying 161-170 of 727
Sort by:
Attacker Value
Unknown

CVE-2022-1123

Disclosure Date: August 29, 2022 (last updated February 24, 2025)
The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) WordPress plugin before 3.12.5 does not properly sanitize some parameters before inserting them into SQL queries. As a result, high privilege users could perform SQL injection attacks.
Attacker Value
Unknown

CVE-2022-34857

Disclosure Date: August 10, 2022 (last updated February 24, 2025)
Reflected Cross-Site Scripting (XSS) vulnerability in smartypants SP Project & Document Manager plugin <= 4.59 at WordPress
Attacker Value
Unknown

CVE-2022-34768

Disclosure Date: August 03, 2022 (last updated February 24, 2025)
insert HTML / js code inside input how to get to the vulnerable input : Workers &gt; worker nickname &gt; inject in this input the code.
Attacker Value
Unknown

CVE-2022-1551

Disclosure Date: July 25, 2022 (last updated February 24, 2025)
The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files.
Attacker Value
Unknown

CVE-2022-30628

Disclosure Date: July 21, 2022 (last updated October 07, 2023)
It was possible to download all receipts without authentication. Must first access the API https://XXXX.supersmart.me/services/v4/customer/signin to get a TOKEN. Then you can then access the API that provides invoice images based on the URL https://XXXX.supersmart.me/services/v4/invoiceImg?orderId=XXXXX
Attacker Value
Unknown

CVE-2020-21406

Disclosure Date: July 20, 2022 (last updated October 07, 2023)
An issue was discovered in RK Smart TV Box MAX and V88 SmartTV box that allows attackers to cause a denial of service via the switchNextDisplayInterface service.
Attacker Value
Unknown

CVE-2022-1912

Disclosure Date: July 18, 2022 (last updated February 24, 2025)
The Button Widget Smartsoft plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing nonce validation on the smartsoftbutton_settings page. This makes it possible for unauthenticated attackers to update the plugins settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2022-2140

Disclosure Date: June 27, 2022 (last updated February 24, 2025)
Elcomplus SmartICS v2.3.4.0 does not neutralize user-controllable input, which allows an authenticated user to inject arbitrary code into specific parameters.
Attacker Value
Unknown

CVE-2022-2106

Disclosure Date: June 27, 2022 (last updated February 24, 2025)
Elcomplus SmartICS v2.3.4.0 does not validate the filenames sufficiently, which enables authenticated administrator-level users to perform path traversal attacks and specify arbitrary files.
Attacker Value
Unknown

CVE-2022-2088

Disclosure Date: June 27, 2022 (last updated February 24, 2025)
An authenticated user with admin privileges may be able to terminate any process on the system running Elcomplus SmartICS v2.3.4.0.