Show filters
24 Total Results
Displaying 21-24 of 24
Sort by:
Attacker Value
Unknown

CVE-2021-24919

Disclosure Date: February 01, 2022 (last updated February 23, 2025)
The Wicked Folders WordPress plugin before 2.8.10 does not sanitise and escape the folder_id parameter before using it in a SQL statement in the wicked_folders_save_sort_order AJAX action, available to any authenticated user. leading to an SQL injection
Attacker Value
Unknown

CVE-2020-7217

Disclosure Date: February 11, 2020 (last updated February 21, 2025)
An ni_dhcp4_fsm_process_dhcp4_packet memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial of service by sending DHCP4 packets with a different client-id.
Attacker Value
Unknown

CVE-2020-7216

Disclosure Date: February 05, 2020 (last updated February 21, 2025)
An ni_dhcp4_parse_response memory leak in openSUSE wicked 0.6.55 and earlier allows network attackers to cause a denial of service by sending DHCP4 packets without a message type option.
Attacker Value
Unknown

CVE-2013-4413

Disclosure Date: March 11, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in controller/concerns/render_redirect.rb in the Wicked gem before 1.0.1 for Ruby allows remote attackers to read arbitrary files via a %2E%2E%2F (encoded dot dot slash) in the step.
0