Show filters
813 Total Results
Displaying 311-320 of 813
Sort by:
Attacker Value
Unknown

CVE-2021-24672

Disclosure Date: October 18, 2021 (last updated February 23, 2025)
The One User Avatar WordPress plugin before 2.3.7 does not escape the link and target attributes of its shortcode, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks
Attacker Value
Unknown

CVE-2021-24675

Disclosure Date: October 18, 2021 (last updated February 23, 2025)
The One User Avatar WordPress plugin before 2.3.7 does not check for CSRF when updating the Avatar in page where the [avatar_upload] shortcode is embed. As a result, attackers could make logged in user change their avatar via a CSRF attack
Attacker Value
Unknown

CVE-2021-41917

Disclosure Date: October 08, 2021 (last updated February 23, 2025)
webTareas version 2.4 and earlier allows an authenticated user to store arbitrary web script or HTML by creating or editing a client name in the clients section, due to incorrect sanitization of user-supplied data and achieve a Stored Cross-Site Scripting attack against the platform users and administrators. The affected endpoint is /clients/editclient.php, on the HTTP POST cn parameter.
Attacker Value
Unknown

CVE-2021-41920

Disclosure Date: October 08, 2021 (last updated February 23, 2025)
webTareas version 2.4 and earlier allows an unauthenticated user to perform Time and Boolean-based blind SQL Injection on the endpoint /includes/library.php, via the sor_cible, sor_champs, and sor_ordre HTTP POST parameters. This allows an attacker to access all the data in the database and obtain access to the webTareas application.
Attacker Value
Unknown

CVE-2021-41918

Disclosure Date: October 08, 2021 (last updated February 23, 2025)
webTareas version 2.4 and earlier allows an authenticated user to inject arbitrary web script or HTML due to incorrect sanitization of user-supplied data and achieve a Reflected Cross-Site Scripting attack against the platform users and administrators. The issue affects every endpoint on the application because it is related on how each URL is echoed back on every response page.
Attacker Value
Unknown

CVE-2021-41916

Disclosure Date: October 08, 2021 (last updated February 23, 2025)
A Cross-Site Request Forgery (CSRF) vulnerability in webTareas version 2.4 and earlier allows a remote attacker to create a new administrative profile and add a new user to the new profile. without the victim's knowledge, by enticing an authenticated admin user to visit an attacker's web page.
Attacker Value
Unknown

CVE-2021-41919

Disclosure Date: October 08, 2021 (last updated February 23, 2025)
webTareas version 2.4 and earlier allows an authenticated user to arbitrarily upload potentially dangerous files without restrictions. This is working by adding or replacing a personal profile picture. The affected endpoint is /includes/upload.php on the HTTP POST data. This allows an attacker to exploit the platform by injecting code or malware and, under certain conditions, to execute code on remote user browsers.
Attacker Value
Unknown

CVE-2021-41617

Disclosure Date: September 26, 2021 (last updated February 23, 2025)
sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user.
Attacker Value
Unknown

CVE-2021-3804

Disclosure Date: September 17, 2021 (last updated February 23, 2025)
taro is vulnerable to Inefficient Regular Expression Complexity
Attacker Value
Unknown

CVE-2021-25665

Disclosure Date: September 14, 2021 (last updated February 23, 2025)
A vulnerability has been identified in Simcenter STAR-CCM+ Viewer (All versions < V2021.2.1). The starview+.exe application lacks proper validation of user-supplied data when parsing scene files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-13700)