Show filters
144 Total Results
Displaying 41-50 of 144
Sort by:
Attacker Value
Unknown

CVE-2021-44345

Disclosure Date: March 20, 2022 (last updated October 07, 2023)
Beijing Wisdom Vision Technology Industry Co., Ltd One Card Integrated Management System 3.0 is vulnerable to SQL Injection.
Attacker Value
Unknown

CVE-2020-23685

Disclosure Date: November 02, 2021 (last updated February 23, 2025)
SQL Injection vulnerability in 188Jianzhan v2.1.0, allows attackers to execute arbitrary code and gain escalated privileges, via the username parameter to login.php.
Attacker Value
Unknown

CVE-2021-34663

Disclosure Date: August 13, 2021 (last updated February 23, 2025)
The jQuery Tagline Rotator WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/jquery-tagline-rotator.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 0.1.5.
Attacker Value
Unknown

CVE-2021-33477

Disclosure Date: May 20, 2021 (last updated February 22, 2025)
rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q). A response is terminated by a newline.
Attacker Value
Unknown

CVE-2020-22807

Disclosure Date: April 29, 2021 (last updated February 22, 2025)
An issue was dicovered in vtiger crm 7.2. Union sql injection in the calendar exportdata feature.
Attacker Value
Unknown

CVE-2020-19362

Disclosure Date: January 20, 2021 (last updated February 22, 2025)
Reflected XSS in Vtiger CRM v7.2.0 in vtigercrm/index.php? through the view parameter can result in an attacker performing malicious actions to users who open a maliciously crafted link or third-party web page.
Attacker Value
Unknown

CVE-2020-19363

Disclosure Date: January 20, 2021 (last updated February 22, 2025)
Vtiger CRM v7.2.0 allows an attacker to display hidden files, list directories by using /libraries and /layout directories.
Attacker Value
Unknown

CVE-2020-10227

Disclosure Date: September 14, 2020 (last updated February 22, 2025)
A cross-site scripting (XSS) vulnerability in the messages module of vtecrm vtenext 19 CE allows attackers to inject arbitrary JavaScript code via the From field of an email.
Attacker Value
Unknown

CVE-2020-10229

Disclosure Date: September 14, 2020 (last updated February 22, 2025)
A CSRF issue in vtecrm vtenext 19 CE allows attackers to carry out unwanted actions on an administrator's behalf, such as uploading files, adding users, and deleting accounts.
Attacker Value
Unknown

CVE-2020-10228

Disclosure Date: September 14, 2020 (last updated February 22, 2025)
A file upload vulnerability in vtecrm vtenext 19 CE allows authenticated users to upload files with a .pht extension, resulting in remote code execution.