Show filters
699 Total Results
Displaying 231-240 of 699
Sort by:
Attacker Value
Unknown
CVE-2021-24945
Disclosure Date: December 13, 2021 (last updated February 23, 2025)
The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to get a list of email and IP addresses of people who liked content from the blog.
0
Attacker Value
Unknown
CVE-2021-3746
Disclosure Date: October 19, 2021 (last updated February 23, 2025)
A flaw was found in the libtpms code that may cause access beyond the boundary of internal buffers. The vulnerability is triggered by specially-crafted TPM2 command packets that then trigger the issue when the state of the TPM2's volatile state is written. The highest threat from this vulnerability is to system availability. This issue affects libtpms versions before 0.8.5, before 0.7.9 and before 0.6.6.
0
Attacker Value
Unknown
CVE-2021-41917
Disclosure Date: October 08, 2021 (last updated February 23, 2025)
webTareas version 2.4 and earlier allows an authenticated user to store arbitrary web script or HTML by creating or editing a client name in the clients section, due to incorrect sanitization of user-supplied data and achieve a Stored Cross-Site Scripting attack against the platform users and administrators. The affected endpoint is /clients/editclient.php, on the HTTP POST cn parameter.
0
Attacker Value
Unknown
CVE-2021-41920
Disclosure Date: October 08, 2021 (last updated February 23, 2025)
webTareas version 2.4 and earlier allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endpoint /includes/library.php, via the sor_cible, sor_champs, and sor_ordre HTTP POST parameters. This allows an attacker to access all the data in the database and obtain access to the webTareas application.
0
Attacker Value
Unknown
CVE-2021-41918
Disclosure Date: October 08, 2021 (last updated February 23, 2025)
webTareas version 2.4 and earlier allows an authenticated user to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a Reflected Cross-Site Scripting attack against the platform users and administrators. The issue affects every endpoint on the application because it is related on how each URL is echoed back on every response page.
0
Attacker Value
Unknown
CVE-2021-41916
Disclosure Date: October 08, 2021 (last updated February 23, 2025)
A Cross-Site Request Forgery (CSRF) vulnerability in webTareas version 2.4 and earlier allows a remote attacker to create a new administrative profile and add a new user to the new profile. without the victim's knowledge, by enticing an authenticated admin user to visit an attacker's web page.
0
Attacker Value
Unknown
CVE-2021-41919
Disclosure Date: October 08, 2021 (last updated February 23, 2025)
webTareas version 2.4 and earlier allows an authenticated user to arbitrarily upload potentially dangerous files without restrictions. This is working by adding or replacing a personal profile picture. The affected endpoint is /includes/upload.php on the HTTP POST data. This allows an attacker to exploit the platform by injecting code or malware and, under certain conditions, to execute code on remote user browsers.
0
Attacker Value
Unknown
CVE-2021-3830
Disclosure Date: September 26, 2021 (last updated February 23, 2025)
btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
0
Attacker Value
Unknown
CVE-2021-3646
Disclosure Date: September 10, 2021 (last updated February 23, 2025)
btcpayserver is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
0
Attacker Value
Unknown
CVE-2020-23069
Disclosure Date: August 18, 2021 (last updated February 23, 2025)
Path Traversal vulneraility exists in webTareas 2.0 via the extpath parameter in general_serv.php, which could let a malicious user read arbitrary files.
0