Show filters
59 Total Results
Displaying 21-30 of 59
Sort by:
Attacker Value
Unknown
CVE-2022-0599
Disclosure Date: March 28, 2022 (last updated February 23, 2025)
The Mapping Multiple URLs Redirect Same Page WordPress plugin through 5.8 does not sanitize and escape the mmursp_id parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
0
Attacker Value
Unknown
CVE-2021-41472
Disclosure Date: January 24, 2022 (last updated February 23, 2025)
SQL injection vulnerability in Sourcecodester Simple Membership System v1 by oretnom23, allows attackers to execute arbitrary SQL commands via the username and password parameters.
0
Attacker Value
Unknown
CVE-2021-40909
Disclosure Date: January 24, 2022 (last updated February 23, 2025)
Cross site scripting (XSS) vulnerability in sourcecodester PHP CRUD without Refresh/Reload using Ajax and DataTables Tutorial v1 by oretnom23, allows remote attackers to execute arbitrary code via the first_name, last_name, and email parameters to /ajax_crud.
0
Attacker Value
Unknown
CVE-2021-25994
Disclosure Date: January 03, 2022 (last updated February 23, 2025)
In Userfrosting, versions v0.3.1 to v4.6.2 are vulnerable to Host Header Injection. By luring a victim application user to click on a link, an unauthenticated attacker can use the “forgot password” functionality to reset the victim’s password and successfully take over their account.
0
Attacker Value
Unknown
CVE-2021-43523
Disclosure Date: November 10, 2021 (last updated February 23, 2025)
In uClibc and uClibc-ng before 1.0.39, incorrect handling of special characters in domain names returned by DNS servers via gethostbyname, getaddrinfo, gethostbyaddr, and getnameinfo can lead to output of wrong hostnames (leading to domain hijacking) or injection into applications (leading to remote code execution, XSS, applications crashes, etc.). In other words, a validation step, which is expected in any stub resolver, does not occur.
0
Attacker Value
Unknown
CVE-2020-7860
Disclosure Date: April 28, 2021 (last updated February 22, 2025)
UnEGG v0.5 and eariler versions have a Integer overflow vulnerability, triggered when the user opens a malformed specific file that is mishandled by UnEGG. Attackers could exploit this and arbitrary code execution. This issue affects: Estsoft UnEGG 0.5 versions prior to 1.0 on linux.
0
Attacker Value
Unknown
CVE-2020-29311
Disclosure Date: December 10, 2020 (last updated February 22, 2025)
Ubilling v1.0.9 allows Remote Command Execution as Root user by executing a malicious command that is injected inside the config file and being triggered by another part of the software.
0
Attacker Value
Unknown
CVE-2013-2109
Disclosure Date: February 10, 2020 (last updated February 21, 2025)
WordPress plugin wp-cleanfix has Remote Code Execution
0
Attacker Value
Unknown
CVE-2013-2108
Disclosure Date: February 10, 2020 (last updated February 21, 2025)
WordPress WP Cleanfix Plugin 2.4.4 has CSRF
0
Attacker Value
Unknown
CVE-2019-12971
Disclosure Date: July 05, 2019 (last updated November 27, 2024)
BKS EBK Ethernet-Buskoppler Pro before 3.01 allows Unrestricted Upload of a File with a Dangerous Type.
0