Show filters
75 Total Results
Displaying 41-50 of 75
Sort by:
Attacker Value
Unknown
CVE-2021-24466
Disclosure Date: August 16, 2021 (last updated February 23, 2025)
The Verse-O-Matic WordPress plugin through 4.1.1 does not have any CSRF checks in place, allowing attackers to make logged in administrators do unwanted actions, such as add/edit/delete arbitrary verses and change the settings. Due to the lack of sanitisation in the settings and verses, this could also lead to Stored Cross-Site Scripting issues
0
Attacker Value
Unknown
CVE-2021-24410
Disclosure Date: August 16, 2021 (last updated February 23, 2025)
The తెలుగు బైబిల్ వచనములు WordPress plugin through 1.0 is lacking any CSRF check when saving its settings and verses, and do not sanitise or escape them when outputting them back in the page. This could allow attackers to make a logged in admin change the settings, as well as add malicious verses containing JavaScript code in them, leading to Stored XSS issues
0
Attacker Value
Unknown
CVE-2020-11805
Disclosure Date: September 25, 2020 (last updated February 22, 2025)
Pexip Reverse Proxy and TURN Server before 6.1.0 has Incorrect UDP Access Control via TURN.
0
Attacker Value
Unknown
CVE-2020-4100
Disclosure Date: July 15, 2020 (last updated February 21, 2025)
"HCL Verse for Android was found to employ dynamic code loading. This mechanism allows a developer to specify which components of the application should not be loaded by default when the application is started. Typically, core components and additional dependencies are loaded natively at runtime; however, dynamically loaded components are only loaded as they are specifically requested. While this can have a positive impact on performance, or grant additional functionality (for example, a non-invasive update feature), it can also open the application to loading unintended code if not implemented properly."
0
Attacker Value
Unknown
CVE-2019-19544
Disclosure Date: January 08, 2020 (last updated February 21, 2025)
CA Automic Dollar Universe 5.3.3 contains a vulnerability, related to the uxdqmsrv binary being setuid root, that allows local attackers to elevate privileges. This vulnerability was reported to CA several years after CA Automic Dollar Universe 5.3.3 reached End of Life (EOL) status on April 1, 2015.
0
Attacker Value
Unknown
CVE-2019-5239
Disclosure Date: August 08, 2019 (last updated November 27, 2024)
Huawei PCManager with the versions before 9.0.1.66 (Oversea) and versions before 9.0.1.70 (China) have an information leak vulnerability. Successful exploitation may cause the attacker to read information.
0
Attacker Value
Unknown
CVE-2019-5237
Disclosure Date: August 08, 2019 (last updated November 27, 2024)
Huawei PCManager with the versions before 9.0.1.66 (Oversea) and versions before 9.0.1.70 (China) have a code execution vulnerability. Successful exploitation may cause the attacker to execute code and read/write information.
0
Attacker Value
Unknown
CVE-2019-5238
Disclosure Date: August 08, 2019 (last updated November 27, 2024)
Huawei PCManager with the versions before 9.0.1.66 (Oversea) and versions before 9.0.1.70 (China) have a code execution vulnerability. Successful exploitation may cause the attacker to execute code and read/write information.
0
Attacker Value
Unknown
CVE-2018-17376
Disclosure Date: September 28, 2018 (last updated November 27, 2024)
SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter.
0
Attacker Value
Unknown
CVE-2018-7243
Disclosure Date: April 18, 2018 (last updated November 26, 2024)
An authorization bypass vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to get a full access to device, bypassing the authorization system.
0