Show filters
42 Total Results
Displaying 21-30 of 42
Sort by:
Attacker Value
Unknown
CVE-2022-36173
Disclosure Date: September 12, 2022 (last updated February 24, 2025)
FreshService macOS Agent < 4.4.0 and FreshServce Linux Agent < 3.4.0 are vulnerable to TLS Man-in-The-Middle via the FreshAgent client and scheduled update service.
0
Attacker Value
Unknown
CVE-2022-28665
Disclosure Date: July 27, 2022 (last updated February 24, 2025)
A memory corruption vulnerability exists in the httpd unescape functionality of FreshTomato 2022.1. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.The `freshtomato-arm` has a vulnerable URL-decoding feature that can lead to memory corruption.
0
Attacker Value
Unknown
CVE-2022-28664
Disclosure Date: July 27, 2022 (last updated February 24, 2025)
A memory corruption vulnerability exists in the httpd unescape functionality of FreshTomato 2022.1. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.The `freshtomato-mips` has a vulnerable URL-decoding feature that can lead to memory corruption.
0
Attacker Value
Unknown
CVE-2021-40909
Disclosure Date: January 24, 2022 (last updated February 23, 2025)
Cross site scripting (XSS) vulnerability in sourcecodester PHP CRUD without Refresh/Reload using Ajax and DataTables Tutorial v1 by oretnom23, allows remote attackers to execute arbitrary code via the first_name, last_name, and email parameters to /ajax_crud.
0
Attacker Value
Unknown
CVE-2019-6190
Disclosure Date: February 14, 2020 (last updated February 21, 2025)
Lenovo was notified of a potential denial of service vulnerability, affecting various versions of BIOS for Lenovo Desktop, Desktop - All in One, and ThinkStation, that could cause PCRs to be cleared intermittently after resuming from sleep (S3) on systems with Intel TXT enabled.
0
Attacker Value
Unknown
CVE-2015-9496
Disclosure Date: October 22, 2019 (last updated November 27, 2024)
The freshmail-newsletter plugin before 1.6 for WordPress has shortcode.php SQL Injection via the 'FM_form id=' substring.
0
Attacker Value
Unknown
CVE-2019-10381
Disclosure Date: August 07, 2019 (last updated October 26, 2023)
Jenkins Codefresh Integration Plugin 1.8 and earlier disables SSL/TLS and hostname verification globally for the Jenkins master JVM.
0
Attacker Value
Unknown
CVE-2019-6156
Disclosure Date: April 10, 2019 (last updated November 27, 2024)
In Lenovo systems, SMM BIOS Write Protection is used to prevent writes to SPI Flash. While this provides sufficient protection, an additional layer of protection is provided by SPI Protected Range Registers (PRx). Lenovo was notified that after resuming from S3 sleep mode in various versions of BIOS for Lenovo systems, the PRx is not set. This does not impact the SMM BIOS Write Protection, which keeps systems protected.
0
Attacker Value
Unknown
CVE-2018-19782
Disclosure Date: January 30, 2019 (last updated November 27, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject arbitrary web script or HTML via the (1) c parameter or (2) a parameter.
0
Attacker Value
Unknown
CVE-2018-1000847
Disclosure Date: December 20, 2018 (last updated November 27, 2024)
FreshDNS version 1.0.3 and prior contains a Cross Site Scripting (XSS) vulnerability in Account data form; Zone editor that can result in Execution of attacker's JavaScript code in victim's session. This attack appear to be exploitable via The attacker stores a specially crafted string as their Full Name in their account details. The victim (e.g. the administrator of the FreshDNS instance) opens the User List in the admin interface.. This vulnerability appears to have been fixed in 1.0.5 and later.
0