Show filters
93 Total Results
Displaying 41-50 of 93
Sort by:
Attacker Value
Unknown

CVE-2021-38260

Disclosure Date: October 25, 2021 (last updated February 23, 2025)
NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostParseDeviceConfigurationDescriptor().
Attacker Value
Unknown

CVE-2021-38258

Disclosure Date: October 25, 2021 (last updated February 23, 2025)
NXP MCUXpresso SDK v2.7.0 was discovered to contain a buffer overflow in the function USB_HostProcessCallback().
Attacker Value
Unknown

CVE-2021-40818

Disclosure Date: September 08, 2021 (last updated February 23, 2025)
scheme/webauthn.c in Glewlwyd SSO server through 2.5.3 has a buffer overflow during FIDO2 signature validation in webauthn registration.
Attacker Value
Unknown

CVE-2020-26153

Disclosure Date: July 13, 2021 (last updated February 23, 2025)
A cross-site scripting (XSS) vulnerability in wp-content/plugins/event-espresso-core-reg/admin_pages/messages/templates/ee_msg_admin_overview.template.php in the Event Espresso Core plugin before 4.10.7.p for WordPress allows remote attackers to inject arbitrary web script or HTML via the page parameter.
Attacker Value
Unknown

CVE-2021-28091

Disclosure Date: June 04, 2021 (last updated February 22, 2025)
Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
Attacker Value
Unknown

CVE-2021-26582

Disclosure Date: April 15, 2021 (last updated February 22, 2025)
A security vulnerability in HPE IceWall SSO Domain Gateway Option (Dgfw) module version 10.0 on RHEL 5/6/7, version 10.0 on HP-UX 11i v3, version 10.0 on Windows and 11.0 on Windows could be exploited remotely to allow cross-site scripting (XSS).
Attacker Value
Unknown

CVE-2020-8160

Disclosure Date: January 06, 2021 (last updated February 22, 2025)
MendixSSO <= 2.1.1 contains endpoints that make use of the openid handler, which is suffering from a Cross-Site Scripting vulnerability via the URL path. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output encoding. As a result, a JavaScript payload may be injected into the above endpoint causing it to be executed within the context of the victim's browser.
Attacker Value
Unknown

CVE-2020-7140

Disclosure Date: July 08, 2020 (last updated February 21, 2025)
A security vulnerability in HPE IceWall SSO Dfw and Dgfw (Domain Gateway Option) could be exploited remotely to cause a remote cross-site scripting (XSS). HPE has provided the following information to resolve this vulnerability in HPE IceWall SSO DFW and Dgfw: https://www.hpe.com/jp/icewall_patchaccess
Attacker Value
Unknown

CVE-2016-10928

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.
0
Attacker Value
Unknown

CVE-2019-11989

Disclosure Date: July 19, 2019 (last updated November 27, 2024)
A security vulnerability in HPE IceWall SSO Agent Option and IceWall MFA (Agent module ) could be exploited remotely to cause a denial of service. The versions and platforms of Agent Option modules that are impacted are as follows: 10.0 for Apache 2.2 on RHEL 5 and 6, 10.0 for Apache 2.4 on RHEL 7, 10.0 for Apache 2.4 on HP-UX 11i v3, 10.0 for IIS on Windows, 11.0 for Apache 2.4 on RHEL 7, MFA Proxy 4.0 (Agent module only) for Apache 2.4 on RHEL 7.
0