Show filters
148 Total Results
Displaying 31-40 of 148
Sort by:
Attacker Value
Unknown

CVE-2022-37832

Disclosure Date: December 16, 2022 (last updated October 08, 2023)
Mutiny 7.2.0-10788 suffers from Hardcoded root password.
Attacker Value
Unknown

CVE-2022-23494

Disclosure Date: December 08, 2022 (last updated October 08, 2023)
tinymce is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in the alert and confirm dialogs when these dialogs were provided with malicious HTML content. This can occur in plugins that use the alert or confirm dialogs, such as in the `image` plugin, which presents these dialogs when certain errors occur. The vulnerability allowed arbitrary JavaScript execution when an alert presented in the TinyMCE UI for the current user. This vulnerability has been patched in TinyMCE 5.10.7 and TinyMCE 6.3.1 by ensuring HTML sanitization was still performed after unwrapping invalid elements. Users are advised to upgrade to either 5.10.7 or 6.3.1. Users unable to upgrade may ensure the the `images_upload_handler` returns a valid value as per the images_upload_handler documentation.
Attacker Value
Unknown

CVE-2022-45476

Disclosure Date: November 25, 2022 (last updated November 08, 2023)
Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returning them for download. This is possible because the application is vulnerable to insecure file upload.
Attacker Value
Unknown

CVE-2022-45475

Disclosure Date: November 25, 2022 (last updated November 08, 2023)
Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to access the application's internal files. This is possible because the application is vulnerable to broken access control.
Attacker Value
Unknown

CVE-2022-23044

Disclosure Date: November 25, 2022 (last updated November 08, 2023)
Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to persuade users to perform unintended actions within the application. This is possible because the application is vulnerable to CSRF.
Attacker Value
Unknown

CVE-2022-39287

Disclosure Date: October 07, 2022 (last updated October 08, 2023)
tiny-csrf is a Node.js cross site request forgery (CSRF) protection middleware. In versions prior to 1.1.0 cookies were not encrypted and thus CSRF tokens were transmitted in the clear. This issue has been addressed in commit `8eead6d` and the patch with be included in version 1.1.0. Users are advised to upgrade. There are no known workarounds for this issue.
Attacker Value
Unknown

CVE-2022-40468

Disclosure Date: September 19, 2022 (last updated October 08, 2023)
Potential leak of left-over heap data if custom error page templates containing special non-standard variables are used. Tinyproxy commit 84f203f and earlier use uninitialized buffers in process_request() function.
Attacker Value
Unknown

CVE-2022-38529

Disclosure Date: September 06, 2022 (last updated October 08, 2023)
tinyexr commit 0647fb3 was discovered to contain a heap-buffer overflow via the component rleUncompress.
Attacker Value
Unknown

CVE-2022-3008

Disclosure Date: September 05, 2022 (last updated October 08, 2023)
The tinygltf library uses the C library function wordexp() to perform file path expansion on untrusted paths that are provided from the input file. This function allows for command injection by using backticks. An attacker could craft an untrusted path input that would result in a path expansion. We recommend upgrading to 2.6.0 or past commit 52ff00a38447f06a17eab1caa2cf0730a119c751
Attacker Value
Unknown

CVE-2022-1846

Disclosure Date: June 27, 2022 (last updated February 24, 2025)
The Tiny Contact Form WordPress plugin through 0.7 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack