Show filters
68 Total Results
Displaying 21-30 of 68
Sort by:
Attacker Value
Unknown
CVE-2021-3025
Disclosure Date: January 08, 2021 (last updated February 22, 2025)
Invision Community IPS Community Suite before 4.5.4.2 allows SQL Injection via the Downloads REST API (the sortDir parameter in a sortBy=popular action to the GETindex() method in applications/downloads/api/files.php).
0
Attacker Value
Unknown
CVE-2021-3026
Disclosure Date: January 05, 2021 (last updated February 22, 2025)
Invision Community IPS Community Suite before 4.5.4.2 allows XSS during the quoting of a post or comment.
0
Attacker Value
Unknown
CVE-2020-29477
Disclosure Date: December 30, 2020 (last updated February 22, 2025)
Invision Community 4.5.4 is affected by cross-site scripting (XSS) in the Field Name field. This vulnerability can allow an attacker to inject the XSS payload in Field Name and each time any user will open that, the XSS triggers and the attacker can able to steal the cookie according to the crafted payload.
0
Attacker Value
Unknown
CVE-2009-5159
Disclosure Date: March 13, 2020 (last updated February 21, 2025)
Invision Power Board (aka IPB or IP.Board) 2.x through 3.0.4, when Internet Explorer 5 is used, allows XSS via a .txt attachment.
0
Attacker Value
Unknown
CVE-2013-3725
Disclosure Date: February 12, 2020 (last updated November 28, 2024)
Invision Power Board (IPB) through 3.x allows admin account takeover leading to code execution.
0
Attacker Value
Unknown
CVE-2012-2226
Disclosure Date: January 09, 2020 (last updated February 21, 2025)
Invision Power Board before 3.3.1 fails to sanitize user-supplied input which could allow remote attackers to obtain sensitive information or execute arbitrary code by uploading a malicious file.
0
Attacker Value
Unknown
CVE-2019-9197
Disclosure Date: December 31, 2019 (last updated November 27, 2024)
The com.unity3d.kharma protocol handler in Unity Editor 2018.3 allows remote attackers to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2015-9288
Disclosure Date: July 29, 2019 (last updated November 27, 2024)
The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online services via a victim's credentials
0
Attacker Value
Unknown
Unity8 converged application lifecycle allows background applications to use on…
Disclosure Date: April 22, 2019 (last updated November 27, 2024)
In all versions of Unity8 a running but not active application on a large-screen device could talk with Maliit and consume keyboard input.
0
Attacker Value
Unknown
CVE-2019-8278
Disclosure Date: March 02, 2019 (last updated November 27, 2024)
Stored XSS in Invision Power Board versions 3.3.1 - 3.4.8 leads to Remote Code Execution.
0