Show filters
83 Total Results
Displaying 21-30 of 83
Sort by:
Attacker Value
Unknown

CVE-2020-19697

Disclosure Date: April 04, 2023 (last updated October 08, 2023)
Cross Site Scripting vulnerability found in Pandao Editor.md v.1.5.0 allows a remote attacker to execute arbitrary code via a crafted script in the <iframe>src parameter.
Attacker Value
Unknown

CVE-2023-24619

Disclosure Date: February 13, 2023 (last updated October 08, 2023)
Redpanda before 22.3.12 discloses cleartext AWS credentials. The import functionality in the rpk binary logs an AWS Access Key ID and Secret in cleartext to standard output, allowing a local user to view the key in the console, or in Kubernetes logs if stdout output is collected. The fixed versions are 22.3.12, 22.2.10, and 22.1.12.
Attacker Value
Unknown

CVE-2022-4306

Disclosure Date: January 30, 2023 (last updated October 08, 2023)
The Panda Pods Repeater Field WordPress plugin before 1.5.4 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against a user having at least Contributor permission.
Attacker Value
Unknown

CVE-2022-39213

Disclosure Date: September 15, 2022 (last updated October 08, 2023)
go-cvss is a Go module to manipulate Common Vulnerability Scoring System (CVSS). In affected versions when a full CVSS v2.0 vector string is parsed using `ParseVector`, an Out-of-Bounds Read is possible due to a lack of tests. The Go module will then panic. The problem is patched in tag `v0.4.0`, by the commit `d9d478ff0c13b8b09ace030db9262f3c2fe031f4`. Users are advised to upgrade. Users unable to upgrade may avoid this issue by parsing only CVSS v2.0 vector strings that do not have all attributes defined (e.g. `AV:N/AC:L/Au:N/C:P/I:P/A:C/E:U/RL:OF/RC:C/CDP:MH/TD:H/CR:M/IR:M/AR:M`). As stated in [SECURITY.md](https://github.com/pandatix/go-cvss/blob/master/SECURITY.md), the CPE v2.3 to refer to this Go module is `cpe:2.3:a:pandatix:go_cvss:*:*:*:*:*:*:*:*`. The entry has already been requested to the NVD CPE dictionary.
Attacker Value
Unknown

CVE-2021-26750

Disclosure Date: September 23, 2021 (last updated February 23, 2025)
DLL hijacking in Panda Agent <=1.16.11 in Panda Security, S.L.U. Panda Adaptive Defense 360 <= 8.0.17 allows attacker to escalate privileges via maliciously crafted DLL file.
Attacker Value
Unknown

CVE-2019-14653

Disclosure Date: August 03, 2019 (last updated November 27, 2024)
pandao Editor.md 1.5.0 allows XSS via an attribute of an ABBR or SUP element.
0
Attacker Value
Unknown

CVE-2019-12042

Disclosure Date: May 23, 2019 (last updated November 27, 2024)
Insecure permissions of the section object Global\PandaDevicesAgentSharedMemory and the event Global\PandaDevicesAgentSharedMemoryChange in Panda products before 18.07.03 allow attackers to queue an event (as an encrypted JSON string) to the system service AgentSvc.exe, which leads to privilege escalation when the CmdLineExecute event is queued. This affects Panda Antivirus, Panda Antivirus Pro, Panda Dome, Panda Global Protection, Panda Gold Protection, and Panda Internet Security.
0
Attacker Value
Unknown

CVE-2019-9737

Disclosure Date: March 13, 2019 (last updated November 27, 2024)
Editor.md 1.5.0 has DOM-based XSS via vectors involving the '<EMBED SRC="data:image/svg+xml' substring.
Attacker Value
Unknown

CVE-2018-19056

Disclosure Date: November 07, 2018 (last updated November 27, 2024)
pandao Editor.md 1.5.0 has DOM XSS via input starting with a "<<" substring, which is mishandled during construction of an A element.
0
Attacker Value
Unknown

CVE-2018-16330

Disclosure Date: September 02, 2018 (last updated November 27, 2024)
Pandao Editor.md 1.5.0 allows XSS via crafted attributes of an invalid IMG element.
0