Show filters
67 Total Results
Displaying 31-40 of 67
Sort by:
Attacker Value
Unknown

CVE-2018-25019

Disclosure Date: November 01, 2021 (last updated February 23, 2025)
The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment_process_init() function, which could allow unauthenticated users to upload arbitrary files to the web server
Attacker Value
Unknown

CVE-2021-24658

Disclosure Date: August 23, 2021 (last updated February 23, 2025)
The Erident Custom Login and Dashboard WordPress plugin before 3.5.9 did not properly sanitise its settings, allowing high privilege users to use XSS payloads in them (even when the unfileted_html is disabled)
Attacker Value
Unknown

CVE-2021-23403

Disclosure Date: July 02, 2021 (last updated February 22, 2025)
All versions of package ts-nodash are vulnerable to Prototype Pollution via the Merge() function due to lack of validation input.
Attacker Value
Unknown

CVE-2020-36144

Disclosure Date: March 18, 2021 (last updated February 22, 2025)
Redash 8.0.0 is affected by LDAP Injection. There is an information leak through the crafting of special queries, escaping the provided template since the username included in the search filter lacks sanitization.
Attacker Value
Unknown

CVE-2021-27886

Disclosure Date: March 02, 2021 (last updated February 22, 2025)
rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter of an API request. NOTE: this is NOT a Docker, Inc. product.
Attacker Value
Unknown

CVE-2021-23337

Disclosure Date: February 15, 2021 (last updated February 22, 2025)
Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
Attacker Value
Unknown

CVE-2020-28500

Disclosure Date: February 15, 2021 (last updated February 22, 2025)
Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.
Attacker Value
Unknown

CVE-2020-24699

Disclosure Date: August 31, 2020 (last updated February 22, 2025)
The Chamber Dashboard Business Directory plugin 3.2.8 for WordPress allows XSS.
Attacker Value
Unknown

CVE-2020-8203

Disclosure Date: July 15, 2020 (last updated February 21, 2025)
Prototype pollution attack when using _.zipObjectDeep in lodash before 4.17.20.
Attacker Value
Unknown

CVE-2020-13651

Disclosure Date: June 15, 2020 (last updated February 21, 2025)
An issue was discovered in DigDash 2018R2 before p20200528, 2019R1 before p20200421, and 2019R2 before p20200430. It allows a user to provide data that will be used to generate the JNLP file used by a client to obtain the right Java application. By providing an attacker-controlled URL, the client will obtain a rogue JNLP file specifying the installation of malicious JAR archives and executed with full privileges on the client computer.