Show filters
1,232 Total Results
Displaying 251-260 of 1,232
Sort by:
Attacker Value
Unknown
CVE-2021-24781
Disclosure Date: November 01, 2021 (last updated February 23, 2025)
The Image Source Control WordPress plugin before 2.3.1 allows users with a role as low as Contributor to change arbitrary post meta fields of arbitrary posts (even those they should not be able to edit)
0
Attacker Value
Unknown
CVE-2021-39212
Disclosure Date: September 13, 2021 (last updated February 23, 2025)
ImageMagick is free software delivered as a ready-to-run binary distribution or as source code that you may use, copy, modify, and distribute in both open and proprietary applications. In affected versions and in certain cases, Postscript files could be read and written when specifically excluded by a `module` policy in `policy.xml`. ex. <policy domain="module" rights="none" pattern="PS" />. The issue has been resolved in ImageMagick 7.1.0-7 and in 6.9.12-22. Fortunately, in the wild, few users utilize the `module` policy and instead use the `coder` policy that is also our workaround recommendation: <policy domain="coder" rights="none" pattern="{PS,EPI,EPS,EPSF,EPSI}" />.
0
Attacker Value
Unknown
CVE-2021-32759
Disclosure Date: August 27, 2021 (last updated February 23, 2025)
OpenMage magento-lts is an alternative to the Magento CE official releases. Due to missing sanitation in data flow in versions prior to 19.4.15 and 20.0.13, it was possible for admin users to upload arbitrary executable files to the server. OpenMage versions 19.4.15 and 20.0.13 have a patch for this Issue.
0
Attacker Value
Unknown
CVE-2021-32758
Disclosure Date: August 27, 2021 (last updated February 23, 2025)
OpenMage Magento LTS is an alternative to the Magento CE official releases. Prior to versions 19.4.15 and 20.0.11, layout XML enabled admin users to execute arbitrary commands via block methods. The latest OpenMage Versions up from v19.4.15 and v20.0.11 have this Issue patched.
0
Attacker Value
Unknown
CVE-2021-38753
Disclosure Date: August 16, 2021 (last updated February 23, 2025)
An unrestricted file upload on Simple Image Gallery Web App can be exploited to upload a web shell and executed to gain unauthorized access to the server hosting the web app.
0
Attacker Value
Unknown
CVE-2021-38623
Disclosure Date: August 13, 2021 (last updated February 23, 2025)
The deferred_image_processing (aka Deferred image processing) extension before 1.0.2 for TYPO3 allows Denial of Service via the FAL API because of /var/transient disk consumption.
0
Attacker Value
Unknown
CVE-2021-34640
Disclosure Date: August 11, 2021 (last updated February 23, 2025)
The Securimage-WP-Fixed WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/securimage-wp.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.5.4.
0
Attacker Value
Unknown
CVE-2021-24333
Disclosure Date: June 01, 2021 (last updated February 22, 2025)
The Content Copy Protection & Prevent Image Save WordPress plugin through 1.3 does not check for CSRF when saving its settings, not perform any validation and sanitisation on them, allowing attackers to make a logged in administrator set arbitrary XSS payloads in them.
0
Attacker Value
Unknown
CVE-2020-1702
Disclosure Date: May 27, 2021 (last updated February 22, 2025)
A malicious container image can consume an unbounded amount of memory when being pulled to a container runtime host, such as Red Hat Enterprise Linux using podman, or OpenShift Container Platform. An attacker can use this flaw to trick a user, with privileges to pull container images, into crashing the process responsible for pulling the image. This flaw affects containers-image versions before 5.2.0.
0
Attacker Value
Unknown
CVE-2020-27769
Disclosure Date: May 14, 2021 (last updated February 22, 2025)
In ImageMagick versions before 7.0.9-0, there are outside the range of representable values of type 'float' at MagickCore/quantize.c.
0