Show filters
256 Total Results
Displaying 201-210 of 256
Sort by:
Attacker Value
Unknown

CVE-2020-7106

Disclosure Date: January 16, 2020 (last updated February 21, 2025)
Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is displayed by $header to trigger the XSS).
Attacker Value
Unknown

CVE-2015-2060

Disclosure Date: November 29, 2019 (last updated November 27, 2024)
cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.
Attacker Value
Unknown

CVE-2019-10219

Disclosure Date: November 08, 2019 (last updated November 08, 2023)
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
Attacker Value
Unknown

CVE-2019-5089

Disclosure Date: November 05, 2019 (last updated November 27, 2024)
An exploitable memory corruption vulnerability exists in Investintech Able2Extract Professional 4.0.7 x64. A specially crafted JPEG file can cause an out-of-bounds memory write, allowing an attacker to execute arbitrary code on the victim machine. An attacker could exploit a vulnerability by providing the user with a specially crafted JPEG file.
Attacker Value
Unknown

CVE-2019-5088

Disclosure Date: November 05, 2019 (last updated November 27, 2024)
An exploitable memory corruption vulnerability exists in Investintech Able2Extract Professional 14.0.7 x64. A specially crafted BMP file can cause an out-of-bounds memory write, allowing a potential attacker to execute arbitrary code on the victim machine. Can trigger this vulnerability by sending the user a specially crafted BMP file.
Attacker Value
Unknown

CVE-2016-11002

Disclosure Date: September 20, 2019 (last updated November 27, 2024)
The Elegant Themes Extra theme before 1.2.4 for WordPress has privilege escalation.
Attacker Value
Unknown

CVE-2019-16250

Disclosure Date: September 11, 2019 (last updated November 27, 2024)
includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading Style Sheets (CSS) token sequence.
Attacker Value
Unknown

CVE-2019-15531

Disclosure Date: August 23, 2019 (last updated November 08, 2023)
GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c.
Attacker Value
Unknown

CVE-2019-14262

Disclosure Date: July 25, 2019 (last updated November 08, 2023)
MetadataExtractor 2.1.0 allows stack consumption.
0
Attacker Value
Unknown

CVE-2019-12739

Disclosure Date: June 05, 2019 (last updated November 27, 2024)
lib/Controller/ExtractionController.php in the Extract add-on before 1.2.0 for Nextcloud allows Remote Code Execution via shell metacharacters in a RAR filename via ajax/extractRar.php (nameOfFile and directory parameters).
0