Show filters
99 Total Results
Displaying 41-50 of 99
Sort by:
Attacker Value
Unknown
CVE-2021-24247
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
The Contact Form Check Tester WordPress plugin through 1.0.2 settings are visible to all registered users in the dashboard and are lacking any sanitisation. As a result, any registered user, such as subscriber, can leave an XSS payload in the plugin settings, which will be triggered by any user visiting them, and could allow for privilege escalation. The vendor decided to close the plugin.
0
Attacker Value
Unknown
CVE-2021-28794
Disclosure Date: March 18, 2021 (last updated November 28, 2024)
The unofficial ShellCheck extension before 0.13.4 for Visual Studio Code mishandles shellcheck.executablePath.
0
Attacker Value
Unknown
CVE-2020-36200
Disclosure Date: January 26, 2021 (last updated February 22, 2025)
TinyCheck before commits 9fd360d and ea53de8 allowed an authenticated attacker to send an HTTP GET request to the crafted URLs.
0
Attacker Value
Unknown
CVE-2020-36199
Disclosure Date: January 26, 2021 (last updated February 22, 2025)
TinyCheck before commits 9fd360d and ea53de8 was vulnerable to command injection due to insufficient checks of input parameters in several places.
0
Attacker Value
Unknown
CVE-2020-35929
Disclosure Date: January 19, 2021 (last updated February 22, 2025)
In TinyCheck before commits 9fd360d and ea53de8, the installation script of the tool contained hard-coded credentials to the backend part of the tool. This information could be used by an attacker for unauthorized access to remote data.
0
Attacker Value
Unknown
CVE-2020-27818
Disclosure Date: December 08, 2020 (last updated February 22, 2025)
A flaw was found in the check_chunk_name() function of pngcheck-2.4.0. An attacker able to pass a malicious file to be processed by pngcheck could cause a temporary denial of service, posing a low risk to application availability.
0
Attacker Value
Unknown
CVE-2019-6027
Disclosure Date: December 26, 2019 (last updated November 27, 2024)
Cross-site request forgery (CSRF) vulnerability in WP Spell Check 7.1.9 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
0
Attacker Value
Unknown
DLL Search Order Hijacking
Disclosure Date: December 11, 2019 (last updated November 08, 2023)
DLL Search Order Hijacking vulnerability in the Microsoft Windows client in McAfee Tech Check 3.0.0.17 and earlier allows local users to execute arbitrary code via the local folder placed there by an attacker.
0
Attacker Value
Unknown
CVE-2016-10934
Disclosure Date: August 27, 2019 (last updated November 27, 2024)
The check-email plugin before 0.5.2 for WordPress has XSS.
0
Attacker Value
Unknown
CVE-2018-18550
Disclosure Date: October 21, 2018 (last updated November 27, 2024)
ServersCheck Monitoring Software before 14.3.4 allows SQL Injection by an authenticated user.
0