Show filters
64 Total Results
Displaying 41-50 of 64
Sort by:
Attacker Value
Unknown
CVE-2021-39371
Disclosure Date: August 23, 2021 (last updated February 23, 2025)
An XML external entity (XXE) injection in PyWPS before 4.4.5 allows an attacker to view files on the application server filesystem by assigning a path to the entity. OWSLib 0.24.1 may also be affected.
0
Attacker Value
Unknown
CVE-2021-3332
Disclosure Date: March 01, 2021 (last updated February 22, 2025)
WPS Hide Login 1.6.1 allows remote attackers to bypass a protection mechanism via post_password.
0
Attacker Value
Unknown
CVE-2020-25291
Disclosure Date: September 13, 2020 (last updated February 22, 2025)
GdiDrawHoriLineIAlt in Kingsoft WPS Office before 11.2.0.9403 allows remote heap corruption via a crafted PLTE chunk in PNG data within a Word document. This is related to QBrush::setMatrix in gui/painting/qbrush.cpp in Qt 4.x.
0
Attacker Value
Unknown
CVE-2014-2271
Disclosure Date: January 14, 2020 (last updated February 21, 2025)
cn.wps.moffice.common.beans.print.CloudPrintWebView in Kingsoft Office 5.3.1, as used in Huawei P2 devices before V100R001C00B043, falls back to HTTP when the HTTPS connection to the registry fails, which allows man-in-the-middle attackers to conduct downgrade attacks and execute arbitrary Java code by leveraging a network position between the client and the registry to block HTTPS traffic.
0
Attacker Value
Unknown
CVE-2019-6027
Disclosure Date: December 26, 2019 (last updated November 27, 2024)
Cross-site request forgery (CSRF) vulnerability in WP Spell Check 7.1.9 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-9498
Disclosure Date: October 22, 2019 (last updated November 27, 2024)
The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.
0
Attacker Value
Unknown
CVE-2019-15824
Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The wps-hide-login plugin before 1.5.3 for WordPress has an adminhash protection bypass.
0
Attacker Value
Unknown
CVE-2019-15823
Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass.
0
Attacker Value
Unknown
CVE-2019-15826
Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The wps-hide-login plugin before 1.5.3 for WordPress has a protection bypass via wp-login.php in the Referer field.
0
Attacker Value
Unknown
CVE-2019-15822
Disclosure Date: August 30, 2019 (last updated November 27, 2024)
The wps-child-theme-generator plugin before 1.2 for WordPress has classes/helpers.php directory traversal.
0