Show filters
733 Total Results
Displaying 231-240 of 733
Sort by:
Attacker Value
Unknown
CVE-2021-24347
Disclosure Date: June 14, 2021 (last updated February 22, 2025)
The SP Project & Document Manager WordPress plugin before 4.22 allows users to upload files, however, the plugin attempts to prevent php and other similar files that could be executed on the server from being uploaded by checking the file extension. It was discovered that php files could still be uploaded by changing the file extension's case, for example, from "php" to "pHP".
0
Attacker Value
Unknown
CVE-2020-24662
Disclosure Date: June 10, 2021 (last updated February 22, 2025)
SmartStream Transaction Lifecycle Management (TLM) Reconciliation Premium (RP) <3.1.0 allows XSS. This was fixed in TLM RP 3.1.0.
0
Attacker Value
Unknown
CVE-2021-31684
Disclosure Date: June 01, 2021 (last updated February 22, 2025)
A vulnerability was discovered in the indexOf function of JSONParserByteArray in JSON Smart versions 1.3 and 2.4 which causes a denial of service (DOS) via a crafted web request.
0
Attacker Value
Unknown
CVE-2020-27377
Disclosure Date: June 01, 2021 (last updated February 22, 2025)
A cross-site scripting (XSS) vulnerability was discovered in the Administrator panel on the 'Setting News' module on CMS Made Simple 2.2.14 which allows an attacker to execute arbitrary web scripts.
0
Attacker Value
Unknown
CVE-2021-24335
Disclosure Date: June 01, 2021 (last updated February 22, 2025)
The Car Repair Services & Auto Mechanic WordPress theme before 4.0 did not properly sanitise its serviceestimatekey search parameter before outputting it back in the page, leading to a reflected Cross-Site Scripting issue
0
Attacker Value
Unknown
CVE-2020-36365
Disclosure Date: May 19, 2021 (last updated February 22, 2025)
Smartstore (aka SmartStoreNET) before 4.1.0 allows CommonController.ClearCache, ClearDatabaseCache, RestartApplication, and ScheduleTaskController.Edit open redirect.
0
Attacker Value
Unknown
CVE-2020-36364
Disclosure Date: May 19, 2021 (last updated February 22, 2025)
An issue was discovered in Smartstore (aka SmartStoreNET) before 4.1.0. Administration/Controllers/ImportController.cs allows path traversal (for copy and delete actions) in the ImportController.Create method via a TempFileName field.
0
Attacker Value
Unknown
CVE-2021-32607
Disclosure Date: May 12, 2021 (last updated November 28, 2024)
An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1. Views/PrivateMessages/View.cshtml does not call HtmlUtils.SanitizeHtml on a private message.
0
Attacker Value
Unknown
CVE-2021-32608
Disclosure Date: May 12, 2021 (last updated November 28, 2024)
An issue was discovered in Smartstore (aka SmartStoreNET) through 4.1.1. Views/Boards/Partials/_ForumPost.cshtml does not call HtmlUtils.SanitizeHtml on certain text for a forum post.
0
Attacker Value
Unknown
CVE-2021-21415
Disclosure Date: April 29, 2021 (last updated February 22, 2025)
Prisma VS Code a VSCode extension for Prisma schema files. This is a Remote Code Execution Vulnerability that affects all versions of the Prisma VS Code extension older than 2.20.0. If a custom binary path for the Prisma format binary is set in VS Code Settings, for example by downloading a project that has a .vscode/settings.json file that sets a value for "prismaFmtBinPath". That custom binary is executed when auto-formatting is triggered by VS Code or when validation checks are triggered after each keypress on a *.prisma file. Fixed in versions 2.20.0 and 20.0.27. As a workaround users can either edit or delete the `.vscode/settings.json` file or check if the binary is malicious and delete it.
0