Show filters
86 Total Results
Displaying 31-40 of 86
Sort by:
Attacker Value
Unknown

CVE-2024-0370

Disclosure Date: February 05, 2024 (last updated February 10, 2024)
The Views for WPForms – Display & Edit WPForms Entries on your site frontend plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_view' function in all versions up to, and including, 3.2.2. This makes it possible for authenticated attackers, with subscriber access and above, to modify the titles of arbitrary posts.
Attacker Value
Unknown

CVE-2023-51079

Disclosure Date: December 27, 2023 (last updated January 11, 2024)
A long execution time can occur in the ParseTools.subCompileExpression method in MVEL 2.5.0.Final because of many Java class lookups. NOTE: the vendor disputes this because "the only thing that you could expect is that the parser will take a crazy amount of time to complete its task."
Attacker Value
Unknown

CVE-2023-0837

Disclosure Date: June 14, 2023 (last updated October 08, 2023)
An improper authorization check of local device settings in TeamViewer Remote between version 15.41 and 15.42.7 for Windows and macOS allows an unprivileged user to change basic local device settings even though the options were locked. This can result in unwanted changes to the configuration.
Attacker Value
Unknown

CVE-2022-31405

Disclosure Date: February 27, 2023 (last updated October 08, 2023)
MV iDigital Clinic Enterprise (iDCE) 1.0 stores passwords in cleartext.
Attacker Value
Unknown

CVE-2022-25853

Disclosure Date: February 06, 2023 (last updated November 08, 2023)
All versions of the package semver-tags are vulnerable to Command Injection via the getGitTagsRemote function due to improper input sanitization.
Attacker Value
Unknown

CVE-2016-20016

Disclosure Date: October 19, 2022 (last updated October 08, 2023)
MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /shell URI. A remote unauthenticated attacker can execute arbitrary operating system commands as root. This vulnerability has also been referred to as the "JAWS webserver RCE" because of the easily identifying HTTP response server field. Other firmware versions, at least from 2014 through 2019, can be affected. This was exploited in the wild in 2017 through 2022.
Attacker Value
Unknown

CVE-2022-31512

Disclosure Date: July 11, 2022 (last updated February 24, 2025)
The Atom02/flask-mvc repository through 2020-09-14 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
Attacker Value
Unknown

CVE-2022-30496

Disclosure Date: June 02, 2022 (last updated February 23, 2025)
SQL injection in Logon Page of IDCE MV's application, version 1.0, allows an attacker to inject SQL payloads in the user field, connecting to a database to access enterprise's private and sensitive information.
Attacker Value
Unknown

CVE-2021-43307

Disclosure Date: May 29, 2022 (last updated February 23, 2025)
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() method
Attacker Value
Unknown

CVE-2022-23242

Disclosure Date: March 22, 2022 (last updated February 23, 2025)
TeamViewer Linux versions before 15.28 do not properly execute a deletion command for the connection password in case of a process crash. Knowledge of the crash event and the TeamViewer ID as well as either possession of the pre-crash connection password or local authenticated access to the machine would have allowed to establish a remote connection by reusing the not properly deleted connection password.