Show filters
50 Total Results
Displaying 41-50 of 50
Sort by:
Attacker Value
Unknown
CVE-2022-44634
Disclosure Date: November 10, 2022 (last updated February 24, 2025)
Auth. (admin+) Arbitrary File Read vulnerability in S2W – Import Shopify to WooCommerce plugin <= 1.1.12 on WordPress.
0
Attacker Value
Unknown
CVE-2022-41623
Disclosure Date: October 12, 2022 (last updated February 24, 2025)
Sensitive Data Exposure in Villatheme ALD - AliExpress Dropshipping and Fulfillment for WooCommerce premium plugin <= 1.1.0 on WordPress.
0
Attacker Value
Unknown
CVE-2022-29451
Disclosure Date: April 21, 2022 (last updated February 23, 2025)
Cross-Site Request Forgery (CSRF) leading to Arbitrary File Upload vulnerability in Rara One Click Demo Import plugin <= 1.2.9 on WordPress allows attackers to trick logged-in admin users into uploading dangerous files into /wp-content/uploads/ directory.
0
Attacker Value
Unknown
CVE-2022-1037
Disclosure Date: April 18, 2022 (last updated February 23, 2025)
The EXMAGE WordPress plugin before 1.0.7 does to ensure that images added via URLs are external images, which could lead to a blind SSRF issue by using local URLs
0
Attacker Value
Unknown
CVE-2022-24976
Disclosure Date: February 14, 2022 (last updated February 23, 2025)
Atheme IRC Services before 7.2.12, when used in conjunction with InspIRCd, allows authentication bypass by ending an IRC handshake at a certain point during a challenge-response login sequence.
0
Attacker Value
Unknown
CVE-2021-25062
Disclosure Date: January 24, 2022 (last updated February 23, 2025)
The Orders Tracking for WooCommerce WordPress plugin before 1.1.10 does not sanitise and escape the file_url before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
0
Attacker Value
Unknown
CVE-2017-6384
Disclosure Date: March 02, 2017 (last updated November 26, 2024)
Memory leak in the login_user function in saslserv/main.c in saslserv/main.so in Atheme 7.2.7 allows a remote unauthenticated attacker to consume memory and cause a denial of service. This is fixed in 7.2.8.
0
Attacker Value
Unknown
CVE-2016-4478
Disclosure Date: June 13, 2016 (last updated November 25, 2024)
Buffer overflow in the xmlrpc_char_encode function in modules/transport/xmlrpc/xmlrpclib.c in Atheme before 7.2.7 allows remote attackers to cause a denial of service via vectors related to XMLRPC response encoding.
0
Attacker Value
Unknown
CVE-2014-9773
Disclosure Date: June 13, 2016 (last updated November 25, 2024)
modules/chanserv/flags.c in Atheme before 7.2.7 allows remote attackers to modify the Anope FLAGS behavior by registering and dropping the (1) LIST, (2) CLEAR, or (3) MODIFY keyword nicks.
0
Attacker Value
Unknown
CVE-2012-1576
Disclosure Date: October 01, 2012 (last updated October 05, 2023)
The myuser_delete function in libathemecore/account.c in Atheme 5.x before 5.2.7, 6.x before 6.0.10, and 7.x before 7.0.0-beta2 does not properly clean up CertFP entries when a user is deleted, which allows remote attackers to access a different user account or cause a denial of service (daemon crash) via a login as a deleted user.
0