Show filters
154 Total Results
Displaying 21-30 of 154
Sort by:
Attacker Value
Unknown
CVE-2023-0958
Disclosure Date: July 28, 2023 (last updated October 08, 2023)
Several plugins for WordPress by Inisev are vulnerable to unauthorized installation of plugins due to a missing capability check on the handle_installation function that is called via the inisev_installation AJAX aciton in various versions. This makes it possible for authenticated attackers with minimal permissions, such as subscribers, to install select plugins from Inisev on vulnerable sites. CVE-2023-38514 appears to be a duplicate of this vulnerability.
0
Attacker Value
Unknown
CVE-2023-24450
Disclosure Date: January 26, 2023 (last updated October 25, 2023)
Jenkins view-cloner Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
0
Attacker Value
Unknown
CVE-2022-25900
Disclosure Date: July 01, 2022 (last updated October 07, 2023)
All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack feature of git.
0
Attacker Value
Unknown
CVE-2022-0444
Disclosure Date: June 27, 2022 (last updated October 07, 2023)
The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset them, including generating a new backup encryption key.
0
Attacker Value
Unknown
CVE-2021-38443
Disclosure Date: May 05, 2022 (last updated October 07, 2023)
Eclipse CycloneDDS versions prior to 0.8.0 improperly handle invalid structures, which may allow an attacker to write arbitrary values in the XML parser.
0
Attacker Value
Unknown
CVE-2021-38441
Disclosure Date: May 05, 2022 (last updated October 07, 2023)
Eclipse CycloneDDS versions prior to 0.8.0 are vulnerable to a write-what-where condition, which may allow an attacker to write arbitrary values in the XML parser.
0
Attacker Value
Unknown
CVE-2022-24437
Disclosure Date: May 01, 2022 (last updated October 07, 2023)
The package git-pull-or-clone before 2.0.2 are vulnerable to Command Injection due to the use of the --upload-pack feature of git which is also supported for git clone. The source includes the use of the secure child process API spawn(). However, the outpath parameter passed to it may be a command-line argument to the git clone command and result in arbitrary command injection.
0
Attacker Value
Unknown
CVE-2022-0732
Disclosure Date: February 22, 2022 (last updated October 07, 2023)
The backend infrastructure shared by multiple mobile device monitoring services does not adequately authenticate or authorize API requests, creating an IDOR (Insecure Direct Object Reference) vulnerability.
0
Attacker Value
Unknown
CVE-2021-24733
Disclosure Date: January 24, 2022 (last updated October 07, 2023)
The WP Post Page Clone WordPress plugin before 1.2 allows users with a role as low as Contributor to clone and view other users' draft and password-protected posts which they cannot view normally.
0
Attacker Value
Unknown
CVE-2020-18735
Disclosure Date: August 23, 2021 (last updated November 29, 2024)
A heap buffer overflow in /src/dds_stream.c of Eclipse IOT Cyclone DDS Project v0.1.0 causes the DDS subscriber server to crash.
0