Show filters
727 Total Results
Displaying 161-170 of 727
Sort by:
Attacker Value
Unknown
CVE-2022-1123
Disclosure Date: August 29, 2022 (last updated February 24, 2025)
The Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) WordPress plugin before 3.12.5 does not properly sanitize some parameters before inserting them into SQL queries. As a result, high privilege users could perform SQL injection attacks.
0
Attacker Value
Unknown
CVE-2022-34857
Disclosure Date: August 10, 2022 (last updated February 24, 2025)
Reflected Cross-Site Scripting (XSS) vulnerability in smartypants SP Project & Document Manager plugin <= 4.59 at WordPress
0
Attacker Value
Unknown
CVE-2022-34768
Disclosure Date: August 03, 2022 (last updated February 24, 2025)
insert HTML / js code inside input how to get to the vulnerable input : Workers > worker nickname > inject in this input the code.
0
Attacker Value
Unknown
CVE-2022-1551
Disclosure Date: July 25, 2022 (last updated February 24, 2025)
The SP Project & Document Manager WordPress plugin before 4.58 uses an easily guessable path to store user files, bad actors could use that to access other users' sensitive files.
0
Attacker Value
Unknown
CVE-2022-30628
Disclosure Date: July 21, 2022 (last updated October 07, 2023)
It was possible to download all receipts without authentication. Must first access the API https://XXXX.supersmart.me/services/v4/customer/signin to get a TOKEN. Then you can then access the API that provides invoice images based on the URL https://XXXX.supersmart.me/services/v4/invoiceImg?orderId=XXXXX
0
Attacker Value
Unknown
CVE-2020-21406
Disclosure Date: July 20, 2022 (last updated October 07, 2023)
An issue was discovered in RK Smart TV Box MAX and V88 SmartTV box that allows attackers to cause a denial of service via the switchNextDisplayInterface service.
0
Attacker Value
Unknown
CVE-2022-1912
Disclosure Date: July 18, 2022 (last updated February 24, 2025)
The Button Widget Smartsoft plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing nonce validation on the smartsoftbutton_settings page. This makes it possible for unauthenticated attackers to update the plugins settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2022-2140
Disclosure Date: June 27, 2022 (last updated February 24, 2025)
Elcomplus SmartICS v2.3.4.0 does not neutralize user-controllable input, which allows an authenticated user to inject arbitrary code into specific parameters.
0
Attacker Value
Unknown
CVE-2022-2106
Disclosure Date: June 27, 2022 (last updated February 24, 2025)
Elcomplus SmartICS v2.3.4.0 does not validate the filenames sufficiently, which enables authenticated administrator-level users to perform path traversal attacks and specify arbitrary files.
0
Attacker Value
Unknown
CVE-2022-2088
Disclosure Date: June 27, 2022 (last updated February 24, 2025)
An authenticated user with admin privileges may be able to terminate any process on the system running Elcomplus SmartICS v2.3.4.0.
0