Show filters
215 Total Results
Displaying 181-190 of 215
Sort by:
Attacker Value
Unknown

CVE-2020-7055

Disclosure Date: April 22, 2020 (last updated February 21, 2025)
An issue was discovered in Elementor 2.7.4. Arbitrary file upload is possible in the Elementor Import Templates function, allowing an attacker to execute code via a crafted ZIP archive.
Attacker Value
Unknown

CVE-2014-8328

Disclosure Date: February 03, 2020 (last updated February 21, 2025)
The default configuration in the Dynamic Content Elements (dce) extension before 0.11.5 for TYPO3 allows remote attackers to obtain sensitive installation environment information by reading the update check request.
Attacker Value
Unknown

CVE-2019-12998

Disclosure Date: January 31, 2020 (last updated February 21, 2025)
c-lightning before 0.7.1 allows attackers to trigger loss of funds because of Incorrect Access Control. NOTE: README.md states "It can be used for testing, but it should not be used for real funds."
Attacker Value
Unknown

CVE-2020-8426

Disclosure Date: January 28, 2020 (last updated February 21, 2025)
The Elementor plugin before 2.8.5 for WordPress suffers from a reflected XSS vulnerability on the elementor-system-info page. These can be exploited by targeting an authenticated user.
Attacker Value
Unknown

CVE-2020-7109

Disclosure Date: January 22, 2020 (last updated November 27, 2024)
The Elementor Page Builder plugin before 2.8.4 for WordPress does not sanitize data during creation of a new template.
Attacker Value
Unknown

CVE-2018-18379

Disclosure Date: October 07, 2019 (last updated November 27, 2024)
The elementor-edit-template class in wp-admin/customize.php in the Elementor Pro plugin before 2.0.10 for WordPress has XSS.
Attacker Value
Unknown

CVE-2017-18596

Disclosure Date: September 10, 2019 (last updated November 27, 2024)
The elementor plugin before 1.8.0 for WordPress has incorrect access control for internal functions.
Attacker Value
Unknown

CVE-2017-18485

Disclosure Date: August 08, 2019 (last updated November 27, 2024)
Cognitoys Dino devices allow profiles_add.html CSRF.
0
Attacker Value
Unknown

CVE-2017-18484

Disclosure Date: August 08, 2019 (last updated November 27, 2024)
Cognitoys Dino devices allow XSS via the SSID.
0
Attacker Value
Unknown

CVE-2017-17608

Disclosure Date: December 13, 2017 (last updated November 26, 2024)
Child Care Script 1.0 has SQL Injection via the /list city parameter.
0