Show filters
728 Total Results
Displaying 181-190 of 728
Sort by:
Attacker Value
Unknown
CVE-2021-43932
Disclosure Date: April 28, 2022 (last updated February 23, 2025)
Elcomplus SmartPTT is vulnerable when an attacker injects JavaScript code into a specific parameter that can executed upon accessing the dashboard or the main page.
0
Attacker Value
Unknown
CVE-2021-43930
Disclosure Date: April 28, 2022 (last updated February 23, 2025)
Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate download requests, enabling malicious users to perform path traversal attacks and potentially download arbitrary files from the system.
0
Attacker Value
Unknown
CVE-2021-4225
Disclosure Date: April 25, 2022 (last updated February 23, 2025)
The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attempts to prevent PHP and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that on Windows servers, the security checks in place were insufficient, enabling bad actors to potentially upload backdoors on vulnerable sites.
0
Attacker Value
Unknown
CVE-2021-43154
Disclosure Date: April 13, 2022 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exists in CMS Made Simple 2.2.15 via the Name field in an Add Category action in moduleinterface.php.
0
Attacker Value
Unknown
CVE-2021-46416
Disclosure Date: April 07, 2022 (last updated February 23, 2025)
Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.
0
Attacker Value
Unknown
CVE-2022-24387
Disclosure Date: March 14, 2022 (last updated February 23, 2025)
With administrator or admin privileges the application can be tricked into overwriting files in app_data/Config folder, e.g. the systemsettings.xml file. THis is possible in SmarterTrack v100.0.8019.14010
0
Attacker Value
Unknown
CVE-2022-24385
Disclosure Date: March 11, 2022 (last updated February 23, 2025)
A Direct Object Access vulnerability in SmarterTools SmarterTrack leads to information disclosure This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.
0
Attacker Value
Unknown
CVE-2022-24386
Disclosure Date: March 11, 2022 (last updated February 23, 2025)
Stored XSS in SmarterTools SmarterTrack This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.
0
Attacker Value
Unknown
CVE-2022-24384
Disclosure Date: March 11, 2022 (last updated February 23, 2025)
Cross-site Scripting (XSS) vulnerability in SmarterTools SmarterTrack This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.
0
Attacker Value
Unknown
CVE-2021-46708
Disclosure Date: March 11, 2022 (last updated February 23, 2025)
The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.
0