Show filters
538 Total Results
Displaying 181-190 of 538
Sort by:
Attacker Value
Unknown

CVE-2022-23172

Disclosure Date: June 26, 2022 (last updated February 24, 2025)
An attacker can access to "Forgot my password" button, as soon as he puts users is valid in the system, the system would issue a message that a password reset email had been sent to user. This way you can verify which users are in the system and which are not.
Attacker Value
Unknown

CVE-2022-2067

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
SQL Injection in GitHub repository francoisjacquet/rosariosis prior to 9.0.
Attacker Value
Unknown

CVE-2021-41502

Disclosure Date: June 11, 2022 (last updated February 23, 2025)
An issue was discovered in Subrion CMS v4.2.1 There is a stored cross-site scripting (XSS) vulnerability that can execute malicious JavaScript code by modifying the name of the uploaded image, closing the html tag, or adding the onerror attribute.
Attacker Value
Unknown

CVE-2022-2036

Disclosure Date: June 09, 2022 (last updated February 23, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 9.0.1.
Attacker Value
Unknown

CVE-2022-1997

Disclosure Date: June 08, 2022 (last updated February 23, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository francoisjacquet/rosariosis prior to 9.0.
Attacker Value
Unknown

CVE-2021-27427

Disclosure Date: May 03, 2022 (last updated February 23, 2025)
RIOT OS version 2020.01.1 is vulnerable to integer wrap-around in its implementation of calloc function, which can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash or a remote code injection/execution.
Attacker Value
Unknown

CVE-2021-41948

Disclosure Date: April 29, 2022 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability exists in the "contact us" plugin for Subrion CMS <= 4.2.1 version via "List of subjects".
Attacker Value
Unknown

CVE-2021-43464

Disclosure Date: April 04, 2022 (last updated October 07, 2023)
A Remiote Code Execution (RCE) vulnerability exiss in Subrion CMS 4.2.1 via modified code in a background field; when the information is modified, the data in it will be executed through eval().
Attacker Value
Unknown

CVE-2021-42171

Disclosure Date: March 14, 2022 (last updated February 23, 2025)
Zenario CMS 9.0.54156 is vulnerable to File Upload. The web server can be compromised by uploading and executing a web-shell which can run commands, browse system files, browse local resources, attack other servers, and exploit the local vulnerabilities, and so forth.
Attacker Value
Unknown

CVE-2021-41952

Disclosure Date: March 14, 2022 (last updated February 23, 2025)
Zenario CMS 9.0.54156 is vulnerable to Cross Site Scripting (XSS) via upload file to *.SVG. An attacker can send malicious files to victims and steals victim's cookie leads to account takeover. The person viewing the image of a contact can be victim of XSS.