Show filters
69 Total Results
Displaying 41-50 of 69
Sort by:
Attacker Value
Unknown

CVE-2022-24656

Disclosure Date: March 21, 2022 (last updated October 07, 2023)
HexoEditor 1.1.8 is affected by Cross Site Scripting (XSS). By putting a common XSS payload in a markdown file, if opened with the app, will execute several times.
Attacker Value
Unknown

CVE-2021-25987

Disclosure Date: November 30, 2021 (last updated February 23, 2025)
Hexo versions 0.0.1 to 5.4.0 are vulnerable against stored XSS. The post “body” and “tags” don’t sanitize malicious javascript during web page generation. Local unprivileged attacker can inject arbitrary code.
Attacker Value
Unknown

CVE-2021-32611

Disclosure Date: May 12, 2021 (last updated February 22, 2025)
A NULL pointer dereference vulnerability exists in eXcall_api.c in Antisip eXosip2 through 5.2.0 when handling certain 3xx redirect responses.
Attacker Value
Unknown

CVE-2020-15364

Disclosure Date: June 28, 2020 (last updated February 21, 2025)
The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS.
Attacker Value
Unknown

CVE-2020-15363

Disclosure Date: June 28, 2020 (last updated February 21, 2025)
The Nexos theme through 1.7 for WordPress allows side-map/?search_order= SQL Injection.
Attacker Value
Unknown

CVE-2019-17606

Disclosure Date: October 23, 2019 (last updated November 08, 2023)
The Post editor functionality in the hexo-admin plugin versions 2.3.0 and earlier for Node.js is vulnerable to stored XSS via the content of a post.
Attacker Value
Unknown

CVE-2014-10375

Disclosure Date: August 14, 2019 (last updated November 27, 2024)
handle_messages in eXtl_tls.c in eXosip before 5.0.0 mishandles a negative value in a content-length header.
0
Attacker Value
Unknown

CVE-2019-1010005

Disclosure Date: July 15, 2019 (last updated November 27, 2024)
HexoEditor v1.1.8-beta is affected by: XSS to code execution.
0
Attacker Value
Unknown

CVE-2018-15851

Disclosure Date: August 25, 2018 (last updated November 27, 2024)
An issue was discovered in Flexo CMS v0.1.6. There is a CSRF vulnerability that can add an administrator via /admin/user/add.
0
Attacker Value
Unknown

CVE-2017-14328

Disclosure Date: October 23, 2017 (last updated November 26, 2024)
Extreme EXOS 15.7, 16.x, 21.x, and 22.x allows remote attackers to trigger a buffer overflow leading to a reboot.