Show filters
54 Total Results
Displaying 31-40 of 54
Sort by:
Attacker Value
Unknown
CVE-2022-4481
Disclosure Date: January 16, 2023 (last updated October 08, 2023)
The Mesmerize Companion WordPress plugin before 1.6.135 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
0
Attacker Value
Unknown
CVE-2023-0162
Disclosure Date: January 10, 2023 (last updated October 08, 2023)
The CPO Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its content type settings parameters in versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2021-24867
Disclosure Date: February 21, 2022 (last updated October 07, 2023)
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
0
Attacker Value
Unknown
CVE-2020-14264
Disclosure Date: October 25, 2021 (last updated February 23, 2025)
"HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the included MobileIron AppConnect SDK"
0
Attacker Value
Unknown
CVE-2020-14263
Disclosure Date: October 21, 2021 (last updated February 23, 2025)
"HCL Traveler Companion is vulnerable to an iOS weak cryptographic process vulnerability via the included MobileIron AppConnect SDK"
0
Attacker Value
Unknown
CVE-2020-4019
Disclosure Date: April 21, 2020 (last updated February 21, 2025)
The file editing functionality in the Atlassian Companion App before version 1.0.0 allows local attackers to have the app run a different executable in place of the app's cmd.exe via a untrusted search path vulnerability.
0
Attacker Value
Unknown
CVE-2020-4020
Disclosure Date: April 21, 2020 (last updated February 21, 2025)
The file downloading functionality in the Atlassian Companion App before version 1.0.0 allows remote attackers, who control a Confluence Server instance that the Companion App is connected to, execute arbitrary .exe files via a Protection Mechanism Failure.
0
Attacker Value
Unknown
CVE-2020-0943
Disclosure Date: April 15, 2020 (last updated November 27, 2024)
An authentication bypass vulnerability exists in Microsoft YourPhoneCompanion application for Android, in the way the application processes notifications generated by work profiles.This could allow an unauthenticated attacker to view notifications, aka 'Microsoft YourPhone Application for Android Authentication Bypass Vulnerability'.
0
Attacker Value
Unknown
CVE-2020-6650
Disclosure Date: March 20, 2020 (last updated February 21, 2025)
UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call e.g.”eval” in “Update Manager” class when software attempts to see if there are updates available. This results in arbitrary code execution on the machine where software is installed.
0
Attacker Value
Unknown
CVE-2018-20973
Disclosure Date: August 16, 2019 (last updated November 27, 2024)
The companion-auto-update plugin before 3.2.1 for WordPress has local file inclusion.
0