Show filters
231 Total Results
Displaying 171-180 of 231
Sort by:
Attacker Value
Unknown
CVE-2020-25487
Disclosure Date: September 22, 2020 (last updated February 22, 2025)
PHPGURUKUL Zoo Management System Using PHP and MySQL version 1.0 is affected by: SQL Injection via zms/animal-detail.php.
0
Attacker Value
Unknown
CVE-2020-6109
Disclosure Date: June 08, 2020 (last updated February 21, 2025)
An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including animated GIFs. A specially crafted chat message can cause an arbitrary file write, which could potentially be abused to achieve arbitrary code execution. An attacker needs to send a specially crafted message to a target user or a group to exploit this vulnerability.
0
Attacker Value
Unknown
CVE-2020-6110
Disclosure Date: June 08, 2020 (last updated February 21, 2025)
An exploitable partial path traversal vulnerability exists in the way Zoom Client version 4.6.10 processes messages including shared code snippets. A specially crafted chat message can cause an arbitrary binary planting which could be abused to achieve arbitrary code execution. An attacker needs to send a specially crafted message to a target user or a group to trigger this vulnerability. For the most severe effect, target user interaction is required.
0
Attacker Value
Unknown
CVE-2020-10257
Disclosure Date: March 10, 2020 (last updated February 21, 2025)
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
0
Attacker Value
Unknown
CVE-2019-16251
Disclosure Date: October 31, 2019 (last updated November 27, 2024)
plugin-fw/lib/yit-plugin-panel-wc.php in the YIT Plugin Framework through 3.3.8 for WordPress allows authenticated options changes.
0
Attacker Value
Unknown
CVE-2005-2349
Disclosure Date: October 28, 2019 (last updated November 27, 2024)
Zoo 2.10 has Directory traversal
0
Attacker Value
Unknown
CVE-2015-9471
Disclosure Date: October 10, 2019 (last updated November 27, 2024)
The dzs-zoomsounds plugin through 2.0 for WordPress has admin/upload.php arbitrary file upload.
0
Attacker Value
Unknown
CVE-2019-13567
Disclosure Date: July 12, 2019 (last updated November 27, 2024)
The Zoom Client before 4.4.53932.0709 on macOS allows remote code execution, a different vulnerability than CVE-2019-13450. If the ZoomOpener daemon (aka the hidden web server) is running, but the Zoom Client is not installed or can't be opened, an attacker can remotely execute code with a maliciously crafted launch URL. NOTE: ZoomOpener is removed by the Apple Malware Removal Tool (MRT) if this tool is enabled and has the 2019-07-10 MRTConfigData.
0
Attacker Value
Unknown
CVE-2019-13450
Disclosure Date: July 09, 2019 (last updated October 06, 2023)
In the Zoom Client through 4.4.4 and RingCentral 7.0.136380.0312 on macOS, remote attackers can force a user to join a video call with the video camera active. This occurs because any web site can interact with the Zoom web server on localhost port 19421 or 19424. NOTE: a machine remains vulnerable if the Zoom Client was installed in the past and then uninstalled. Blocking exploitation requires additional steps, such as the ZDisableVideo preference and/or killing the web server, deleting the ~/.zoomus directory, and creating a ~/.zoomus plain file.
0
Attacker Value
Unknown
CVE-2019-13449
Disclosure Date: July 09, 2019 (last updated November 08, 2023)
In the Zoom Client before 4.4.2 on macOS, remote attackers can cause a denial of service (continual focus grabs) via a sequence of invalid launch?action=join&confno= requests to localhost port 19421.
0