Show filters
256 Total Results
Displaying 201-210 of 256
Sort by:
Attacker Value
Unknown
CVE-2020-7106
Disclosure Date: January 16, 2020 (last updated February 21, 2025)
Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is displayed by $header to trigger the XSS).
0
Attacker Value
Unknown
CVE-2015-2060
Disclosure Date: November 29, 2019 (last updated November 27, 2024)
cabextract before 1.6 does not properly check for leading slashes when extracting files, which allows remote attackers to conduct absolute directory traversal attacks via a malformed UTF-8 character that is changed to a UTF-8 encoded slash.
0
Attacker Value
Unknown
CVE-2019-10219
Disclosure Date: November 08, 2019 (last updated November 08, 2023)
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
0
Attacker Value
Unknown
CVE-2019-5089
Disclosure Date: November 05, 2019 (last updated November 27, 2024)
An exploitable memory corruption vulnerability exists in Investintech Able2Extract Professional 4.0.7 x64. A specially crafted JPEG file can cause an out-of-bounds memory write, allowing an attacker to execute arbitrary code on the victim machine. An attacker could exploit a vulnerability by providing the user with a specially crafted JPEG file.
0
Attacker Value
Unknown
CVE-2019-5088
Disclosure Date: November 05, 2019 (last updated November 27, 2024)
An exploitable memory corruption vulnerability exists in Investintech Able2Extract Professional 14.0.7 x64. A specially crafted BMP file can cause an out-of-bounds memory write, allowing a potential attacker to execute arbitrary code on the victim machine. Can trigger this vulnerability by sending the user a specially crafted BMP file.
0
Attacker Value
Unknown
CVE-2016-11002
Disclosure Date: September 20, 2019 (last updated November 27, 2024)
The Elegant Themes Extra theme before 1.2.4 for WordPress has privilege escalation.
0
Attacker Value
Unknown
CVE-2019-16250
Disclosure Date: September 11, 2019 (last updated November 27, 2024)
includes/wizard/wizard.php in the Ocean Extra plugin through 1.5.8 for WordPress allows unauthenticated options changes and injection of a Cascading Style Sheets (CSS) token sequence.
0
Attacker Value
Unknown
CVE-2019-15531
Disclosure Date: August 23, 2019 (last updated November 08, 2023)
GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c.
0
Attacker Value
Unknown
CVE-2019-14262
Disclosure Date: July 25, 2019 (last updated November 08, 2023)
MetadataExtractor 2.1.0 allows stack consumption.
0
Attacker Value
Unknown
CVE-2019-12739
Disclosure Date: June 05, 2019 (last updated November 27, 2024)
lib/Controller/ExtractionController.php in the Extract add-on before 1.2.0 for Nextcloud allows Remote Code Execution via shell metacharacters in a RAR filename via ajax/extractRar.php (nameOfFile and directory parameters).
0