Show filters
569 Total Results
Displaying 171-180 of 569
Sort by:
Attacker Value
Unknown
CVE-2022-0813
Disclosure Date: March 08, 2022 (last updated February 23, 2025)
PhpMyAdmin 5.1.1 and before allows an attacker to retrieve potentially sensitive information by creating invalid requests. This affects the lang parameter, the pma_parameter, and the cookie section.
0
Attacker Value
Unknown
CVE-2021-46371
Disclosure Date: February 14, 2022 (last updated February 23, 2025)
antd-admin 5.5.0 is affected by an incorrect access control vulnerability. Unauthorized access to some interfaces in the foreground leads to leakage of sensitive information.
0
Attacker Value
Unknown
CVE-2022-21660
Disclosure Date: February 09, 2022 (last updated February 23, 2025)
Gin-vue-admin is a backstage management system based on vue and gin. In versions prior to 2.4.7 low privilege users are able to modify higher privilege users. Authentication is missing on the `setUserInfo` function. Users are advised to update as soon as possible. There are no known workarounds.
0
Attacker Value
Unknown
CVE-2022-23808
Disclosure Date: January 22, 2022 (last updated February 23, 2025)
An issue was discovered in phpMyAdmin 5.1 before 5.1.2. An attacker can inject malicious code into aspects of the setup script, which can allow XSS or HTML injection.
0
Attacker Value
Unknown
CVE-2022-23807
Disclosure Date: January 22, 2022 (last updated February 23, 2025)
An issue was discovered in phpMyAdmin 4.9 before 4.9.8 and 5.1 before 5.1.2. A valid user who is already authenticated to phpMyAdmin can manipulate their account to bypass two-factor authentication for future login instances.
0
Attacker Value
Unknown
CVE-2021-44586
Disclosure Date: January 10, 2022 (last updated February 23, 2025)
An issue was discovered in dst-admin v1.3.0. The product has an unauthorized arbitrary file download vulnerability that can expose sensitive information.
0
Attacker Value
Unknown
CVE-2021-43117
Disclosure Date: December 13, 2021 (last updated February 23, 2025)
fastadmin v1.2.1 is affected by a file upload vulnerability which allows arbitrary code execution through shell access.
0
Attacker Value
Unknown
CVE-2021-24784
Disclosure Date: December 13, 2021 (last updated February 23, 2025)
The WP Admin Logo Changer WordPress plugin through 1.0 does not have CSRF check when saving its settings, which could allow attackers to make a logged in admin update them via a CSRF attack.
0
Attacker Value
Unknown
CVE-2021-44219
Disclosure Date: November 24, 2021 (last updated October 07, 2023)
Gin-Vue-Admin before 2.4.6 mishandles a SQL database.
0
Attacker Value
Unknown
CVE-2021-26844
Disclosure Date: November 05, 2021 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability in Power Admin PA Server Monitor 8.2.1.1 allows remote attackers to inject arbitrary web script or HTML via Console.exe.
0