Show filters
200 Total Results
Displaying 51-60 of 200
Sort by:
Attacker Value
Unknown

CVE-2022-2316

Disclosure Date: July 06, 2022 (last updated October 07, 2023)
HTML injection vulnerability in secure messages of Devolutions Server before 2022.2 allows attackers to alter the rendering of the page or redirect a user to another site.
Attacker Value
Unknown

CVE-2022-26149

Disclosure Date: February 26, 2022 (last updated February 23, 2025)
MODX Revolution through 2.8.3-pl allows remote authenticated administrators to execute arbitrary code by uploading an executable file, because the Uploadable File Types setting can be changed by an administrator.
Attacker Value
Unknown

CVE-2021-31632

Disclosure Date: December 06, 2021 (last updated February 23, 2025)
b2evolution CMS v7.2.3 was discovered to contain a SQL injection vulnerability via the parameter cfqueryparam in the User login section. This vulnerability allows attackers to execute arbitrary code via a crafted input.
Attacker Value
Unknown

CVE-2021-31631

Disclosure Date: December 06, 2021 (last updated February 23, 2025)
b2evolution CMS v7.2.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the User login page. This vulnerability allows attackers to escalate privileges.
Attacker Value
Unknown

CVE-2020-25911

Disclosure Date: October 31, 2021 (last updated February 23, 2025)
A XML External Entity (XXE) vulnerability was discovered in the modRestServiceRequest component in MODX CMS 2.7.3 which can lead to an information disclosure or denial of service (DOS).
Attacker Value
Unknown

CVE-2021-39361

Disclosure Date: August 22, 2021 (last updated February 23, 2025)
In GNOME evolution-rss through 0.3.96, network-soup.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
Attacker Value
Unknown

CVE-2020-23238

Disclosure Date: July 26, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability in Evolution CMS 2.0.2 via the Document Manager feature.
Attacker Value
Unknown

CVE-2021-36382

Disclosure Date: July 12, 2021 (last updated February 23, 2025)
Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-the-middle attack against the connections/partial endpoint (which accepts cleartext).
Attacker Value
Unknown

CVE-2009-3721

Disclosure Date: May 26, 2021 (last updated February 22, 2025)
Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitrary locations on the filesystem, crash, or potentially execute arbitrary code when decoding attachments.
Attacker Value
Unknown

CVE-2021-28242

Disclosure Date: April 15, 2021 (last updated February 22, 2025)
SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive database information by injecting SQL commands into the "cf_name" parameter when creating a new filter under the "Collections" tab.