Show filters
64 Total Results
Displaying 41-50 of 64
Sort by:
Attacker Value
Unknown

CVE-2021-39371

Disclosure Date: August 23, 2021 (last updated February 23, 2025)
An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the application server filesystem by assigning a path to the entity. OWSLib 0.24.1 may also be affected.
Attacker Value
Unknown

CVE-2021-3332

Disclosure Date: March 01, 2021 (last updated February 22, 2025)
WPS Hide Login 1.6.1 allows remote attackers to bypass a protection mechanism via post_password.
Attacker Value
Unknown

CVE-2020-25291

Disclosure Date: September 13, 2020 (last updated February 22, 2025)
GdiDrawHoriLineIAlt in Kingsoft WPS Office before 11.2.0.9403 allows remote heap corruption via a crafted PLTE chunk in PNG data within a Word document. This is related to QBrush::setMatrix in gui/painting/qbrush.cpp in Qt 4.x.
Attacker Value
Unknown

CVE-2014-2271

Disclosure Date: January 14, 2020 (last updated February 21, 2025)
cn.wps.moffice.common.beans.print.CloudPrintWebView in Kingsoft Office 5.3.1, as used in Huawei P2 devices before V100R001C00B043, falls back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and execute arbitrary Java code by leveraging a network position between the client and the registry to block HTTPS traffic.
Attacker Value
Unknown

CVE-2019-6027

Disclosure Date: December 26, 2019 (last updated November 27, 2024)
Cross-site request forgery (CSRF) vulnerability in WP Spell Check 7.1.9 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
Attacker Value
Unknown

CVE-2015-9498

Disclosure Date: October 22, 2019 (last updated November 27, 2024)
The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.
Attacker Value
Unknown

CVE-2019-15824

Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The wps-hide-login plugin before 1.5.3 for WordPress has an adminhash protection bypass.
0
Attacker Value
Unknown

CVE-2019-15823

Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass.
0
Attacker Value
Unknown

CVE-2019-15826

Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The wps-hide-login plugin before 1.5.3 for WordPress has a protection bypass via wp-login.php in the Referer field.
0
Attacker Value
Unknown

CVE-2019-15822

Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The wps-child-theme-generator plugin before 1.2 for WordPress has classes/helpers.php directory traversal.
0