Show filters
51 Total Results
Displaying 21-30 of 51
Sort by:
Attacker Value
Unknown
CVE-2022-3769
Disclosure Date: November 28, 2022 (last updated October 08, 2023)
The OWM Weather WordPress plugin before 5.6.9 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a role as low as contributor
0
Attacker Value
Unknown
CVE-2021-24709
Disclosure Date: October 11, 2021 (last updated February 23, 2025)
The Weather Effect WordPress plugin before 1.3.6 does not properly validate and escape some of its settings (like *_size_leaf, *_flakes_leaf, *_speed) which could lead to Stored Cross-Site Scripting issues
0
Attacker Value
Unknown
CVE-2021-24683
Disclosure Date: October 11, 2021 (last updated February 23, 2025)
The Weather Effect WordPress plugin before 1.3.4 does not have any CSRF checks in place when saving its settings, and do not validate or escape them, which could lead to Stored Cross-Site Scripting issue.
0
Attacker Value
Unknown
CVE-2021-24474
Disclosure Date: August 02, 2021 (last updated February 23, 2025)
The Awesome Weather Widget WordPress plugin through 3.0.2 does not sanitize the id parameter of its awesome_weather_refresh AJAX action, leading to an unauthenticated Reflected Cross-Site Scripting (XSS) Vulnerability.
0
Attacker Value
Unknown
CVE-2020-9407
Disclosure Date: February 26, 2020 (last updated February 21, 2025)
IBL Online Weather before 4.3.5a allows attackers to obtain sensitive information by reading the IWEBSERVICE_JSONRPC_COOKIE cookie.
0
Attacker Value
Unknown
CVE-2020-9406
Disclosure Date: February 26, 2020 (last updated February 21, 2025)
IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service.
0
Attacker Value
Unknown
CVE-2020-9405
Disclosure Date: February 26, 2020 (last updated February 21, 2025)
IBL Online Weather before 4.3.5a allows unauthenticated reflected XSS via the redirect page.
0
Attacker Value
Unknown
CVE-2014-4561
Disclosure Date: January 10, 2020 (last updated February 21, 2025)
The ultimate-weather plugin 1.0 for WordPress has XSS
0
Attacker Value
Unknown
CVE-2018-18875
Disclosure Date: June 18, 2019 (last updated November 27, 2024)
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a stored Cross-site scripting (XSS) vulnerability allows remote authenticated users to inject arbitrary web script via changestationname.php.
0
Attacker Value
Unknown
CVE-2018-18878
Disclosure Date: June 18, 2019 (last updated November 27, 2024)
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, the BACnet daemon does not properly validate input, which could allow a remote attacker to send specially crafted packets causing the device to become unavailable.
0