Show filters
72 Total Results
Displaying 21-30 of 72
Sort by:
Attacker Value
Unknown

CVE-2023-2258

Disclosure Date: April 24, 2023 (last updated February 24, 2025)
Improper Neutralization of Formula Elements in a CSV File in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.
Attacker Value
Unknown

CVE-2022-47158

Disclosure Date: April 24, 2023 (last updated February 24, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pakpobox alfred24 Click & Collect plugin <= 1.1.7 versions.
Attacker Value
Unknown

CVE-2023-23591

Disclosure Date: April 12, 2023 (last updated February 24, 2025)
The Logback component in Terminalfour before 8.3.14.1 allows OS administrators to obtain sensitive information from application server logs when debug logging is enabled. The fixed versions are 8.2.18.7, 8.2.18.2.2, 8.3.11.1, and 8.3.14.1.
Attacker Value
Unknown

CVE-2022-4474

Disclosure Date: January 23, 2023 (last updated October 08, 2023)
The Easy Social Feed WordPress plugin before 6.4.0 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admin.
Attacker Value
Unknown

CVE-2022-33941

Disclosure Date: September 08, 2022 (last updated February 24, 2025)
PowerCMS XMLRPC API provided by Alfasado Inc. contains a command injection vulnerability. Sending a specially crafted message by POST method to PowerCMS XMLRPC API may allow arbitrary Perl script execution, and an arbitrary OS command may be executed through it. Affected products/versions are as follows: PowerCMS 6.021 and earlier (PowerCMS 6 Series), PowerCMS 5.21 and earlier (PowerCMS 5 Series), and PowerCMS 4.51 and earlier (PowerCMS 4 Series). Note that all versions of PowerCMS 3 Series and earlier which are unsupported (End-of-Life, EOL) are also affected by this vulnerability.
Attacker Value
Unknown

CVE-2022-30770

Disclosure Date: May 16, 2022 (last updated February 23, 2025)
Terminalfour versions 8.3.7, 8.3.x versions prior to version 8.3.8 and r 8.2.x versions prior to version 8.2.18.5 or 8.2.18.2.1 are vulnerable to (XSS) vulnerability that could be exploited by an attacker to mislead an administrator and steal their credentials.
Attacker Value
Unknown

CVE-2021-25120

Disclosure Date: April 18, 2022 (last updated February 23, 2025)
The Easy Social Feed Free and Pro WordPress plugins before 6.2.7 do not sanitise some of their parameters used via AJAX actions before outputting them back in the response, leading to Reflected Cross-Site Scripting issues
Attacker Value
Unknown

CVE-2022-0471

Disclosure Date: April 11, 2022 (last updated February 23, 2025)
The Favicon by RealFaviconGenerator WordPress plugin before 1.3.23 does not properly sanitise and escape the json_result_url parameter before outputting it back in the Favicon admin dashboard, leading to a Reflected Cross-Site Scripting issue
Attacker Value
Unknown

CVE-2022-25577

Disclosure Date: March 25, 2022 (last updated February 23, 2025)
ALF-BanCO v8.2.5 and below was discovered to use a hardcoded password to encrypt the SQLite database containing the user's data. Attackers who are able to gain remote or local access to the system are able to read and modify the data.
Attacker Value
Unknown

CVE-2020-18327

Disclosure Date: March 04, 2022 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exists in Alfresco Alfresco Community Edition v5.2.0 via the action parameter in the alfresco/s/admin/admin-nodebrowser API. Fixed in v6.2