Show filters
46 Total Results
Displaying 21-30 of 46
Sort by:
Attacker Value
Unknown
CVE-2021-24171
Disclosure Date: April 05, 2021 (last updated February 22, 2025)
The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions such as .php. It was possible to bypass this and upload a file with a PHP extension by embedding a "blocked" extension within another "blocked" extension in the "wcuf_file_name" parameter. It was also possible to perform a double extension attack and upload files to a different location via path traversal using the "wcuf_current_upload_session_id" parameter.
0
Attacker Value
Unknown
CVE-2020-35308
Disclosure Date: March 31, 2021 (last updated November 28, 2024)
CONQUEST DICOM SERVER before 1.5.0 has a code execution vulnerability which can be exploited by attackers to execute malicious code.
0
Attacker Value
Unknown
CVE-2020-36208
Disclosure Date: January 26, 2021 (last updated February 22, 2025)
An issue was discovered in the conquer-once crate before 0.3.2 for Rust. Thread crossing can occur for a non-Send but Sync type, leading to memory corruption.
0
Attacker Value
Unknown
CVE-2018-18689
Disclosure Date: January 07, 2021 (last updated February 22, 2025)
The Portable Document Format (PDF) specification does not provide any information regarding the concrete procedure of how to validate signatures. Consequently, a Signature Wrapping vulnerability exists in multiple products. An attacker can use /ByteRange and xref manipulations that are not detected by the signature-validation logic. This affects Foxit Reader before 9.4 and PhantomPDF before 8.3.9 and 9.x before 9.4. It also affects eXpert PDF 12 Ultimate, Expert PDF Reader, Nitro Pro, Nitro Reader, PDF Architect 6, PDF Editor 6 Pro, PDF Experte 9 Ultimate, PDFelement6 Pro, PDF Studio Viewer 2018, PDF Studio Pro, PDF-XChange Editor and Viewer, Perfect PDF 10 Premium, Perfect PDF Reader, Soda PDF, and Soda PDF Desktop.
0
Attacker Value
Unknown
CVE-2020-15182
Disclosure Date: September 17, 2020 (last updated February 22, 2025)
The SOY Inquiry component of SOY CMS is affected by Cross-site Request Forgery (CSRF) and Remote Code Execution (RCE). The vulnerability affects versions 2.0.0.3 and earlier of SOY Inquiry. This allows remote attackers to force the administrator to edit files once the administrator loads a specially crafted webpage. An administrator must be logged in for exploitation to be possible. This issue is fixed in SOY Inquiry version 2.0.0.4 and included in SOY CMS 3.0.2.328.
0
Attacker Value
Unknown
CVE-2020-5559
Disclosure Date: March 25, 2020 (last updated February 21, 2025)
Cross-site scripting vulnerability in WL-Enq 1.11 and 1.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2020-5560
Disclosure Date: March 25, 2020 (last updated February 21, 2025)
WL-Enq 1.11 and 1.12 allows remote attackers to execute arbitrary OS commands with the administrative privilege via unspecified vectors.
0
Attacker Value
Unknown
CVE-2019-13000
Disclosure Date: January 31, 2020 (last updated February 21, 2025)
Eclair through 0.3 allows attackers to trigger loss of funds because of Incorrect Access Control. NOTE: README.md states "it is beta-quality software and don't put too much money in it."
0
Attacker Value
Unknown
CVE-2019-12880
Disclosure Date: June 24, 2019 (last updated November 27, 2024)
BCN Quark Quarking Password Manager 3.1.84 suffers from a clickjacking vulnerability caused by allowing * within web_accessible_resources. An attacker can take advantage of this vulnerability and cause significant harm.
0
Attacker Value
Unknown
CVE-2018-13757
Disclosure Date: July 09, 2018 (last updated November 27, 2024)
The mintToken function of a smart contract implementation for Coinquer, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
0