Show filters
728 Total Results
Displaying 181-190 of 728
Sort by:
Attacker Value
Unknown

CVE-2021-43932

Disclosure Date: April 28, 2022 (last updated February 23, 2025)
Elcomplus SmartPTT is vulnerable when an attacker injects JavaScript code into a specific parameter that can executed upon accessing the dashboard or the main page.
Attacker Value
Unknown

CVE-2021-43930

Disclosure Date: April 28, 2022 (last updated February 23, 2025)
Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate download requests, enabling malicious users to perform path traversal attacks and potentially download arbitrary files from the system.
Attacker Value
Unknown

CVE-2021-4225

Disclosure Date: April 25, 2022 (last updated February 23, 2025)
The SP Project & Document Manager WordPress plugin before 4.24 allows any authenticated users, such as subscribers, to upload files. The plugin attempts to prevent PHP and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that on Windows servers, the security checks in place were insufficient, enabling bad actors to potentially upload backdoors on vulnerable sites.
Attacker Value
Unknown

CVE-2021-43154

Disclosure Date: April 13, 2022 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exists in CMS Made Simple 2.2.15 via the Name field in an Add Category action in moduleinterface.php.
Attacker Value
Unknown

CVE-2021-46416

Disclosure Date: April 07, 2022 (last updated February 23, 2025)
Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups accessing due to insecure cookie handling.
Attacker Value
Unknown

CVE-2022-24387

Disclosure Date: March 14, 2022 (last updated February 23, 2025)
With administrator or admin privileges the application can be tricked into overwriting files in app_data/Config folder, e.g. the systemsettings.xml file. THis is possible in SmarterTrack v100.0.8019.14010
Attacker Value
Unknown

CVE-2022-24385

Disclosure Date: March 11, 2022 (last updated February 23, 2025)
A Direct Object Access vulnerability in SmarterTools SmarterTrack leads to information disclosure This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.
Attacker Value
Unknown

CVE-2022-24386

Disclosure Date: March 11, 2022 (last updated February 23, 2025)
Stored XSS in SmarterTools SmarterTrack This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.
Attacker Value
Unknown

CVE-2022-24384

Disclosure Date: March 11, 2022 (last updated February 23, 2025)
Cross-site Scripting (XSS) vulnerability in SmarterTools SmarterTrack This issue affects: SmarterTools SmarterTrack 100.0.8019.14010.
Attacker Value
Unknown

CVE-2021-46708

Disclosure Date: March 11, 2022 (last updated February 23, 2025)
The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the victim.