Show filters
144 Total Results
Displaying 31-40 of 144
Sort by:
Attacker Value
Unknown
CVE-2024-2845
Disclosure Date: April 09, 2024 (last updated April 10, 2024)
The BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer For Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 3.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-1698
Disclosure Date: February 27, 2024 (last updated February 27, 2024)
The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, and including, 2.8.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
0
Attacker Value
Unknown
CVE-2023-38891
Disclosure Date: September 14, 2023 (last updated October 08, 2023)
SQL injection vulnerability in Vtiger CRM v.7.5.0 allows a remote authenticated attacker to escalate privileges via the getQueryColumnsList function in ReportRun.php.
0
Attacker Value
Unknown
CVE-2023-35072
Disclosure Date: September 05, 2023 (last updated December 22, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Coyav Travel Proagent allows SQL Injection.This issue affects Proagent: before 20230904 .
0
Attacker Value
Unknown
CVE-2023-25437
Disclosure Date: April 27, 2023 (last updated October 08, 2023)
An issue was discovered in vTech VCS754 version 1.1.1.A before 1.1.1.H, allows attackers to gain escalated privileges and gain sensitive information due to cleartext passwords passed in the raw HTML.
0
Attacker Value
Unknown
CVE-2023-28877
Disclosure Date: March 31, 2023 (last updated October 08, 2023)
The VTEX apps-graphql@2.x GraphQL API module does not properly restrict unauthorized access to private configuration data. (apps-graphql@3.x is unaffected by this issue.)
0
Attacker Value
Unknown
CVE-2021-39427
Disclosure Date: December 15, 2022 (last updated October 08, 2023)
Cross site scripting vulnerability in 188Jianzhan 2.10 allows attackers to execute arbitrary code via the username parameter to /admin/reg.php.
0
Attacker Value
Unknown
CVE-2022-4170
Disclosure Date: December 09, 2022 (last updated October 08, 2023)
The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.
0
Attacker Value
Unknown
CVE-2022-38335
Disclosure Date: September 27, 2022 (last updated October 08, 2023)
Vtiger CRM v7.4.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the e-mail template modules.
0
Attacker Value
Unknown
CVE-2021-42521
Disclosure Date: August 25, 2022 (last updated October 08, 2023)
There is a NULL pointer dereference vulnerability in VTK before 9.2.5, and it lies in IO/Infovis/vtkXMLTreeReader.cxx. The vendor didn't check the return value of libxml2 API 'xmlDocGetRootElement', and try to dereference it. It is unsafe as the return value can be NULL and that NULL pointer dereference may crash the application.
0