Show filters
67 Total Results
Displaying 51-60 of 67
Sort by:
Attacker Value
Unknown

CVE-2018-9206

Disclosure Date: October 11, 2018 (last updated November 27, 2024)
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
Attacker Value
Unknown

CVE-2018-0645

Disclosure Date: September 07, 2018 (last updated November 27, 2024)
MTAppjQuery 1.8.1 and earlier allows remote PHP code execution via unspecified vectors.
0
Attacker Value
Unknown

CVE-2017-16045

Disclosure Date: June 04, 2018 (last updated November 26, 2024)
`jquery.js` was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm.
0
Attacker Value
Unknown

CVE-2018-1325

Disclosure Date: April 18, 2018 (last updated November 26, 2024)
In Apache wicket-jquery-ui <= 6.29.0, <= 7.10.1, <= 8.0.0-M9.1, JS code created in WYSIWYG editor will be executed on display.
0
Attacker Value
Unknown

CVE-2017-15719

Disclosure Date: March 12, 2018 (last updated November 26, 2024)
In Wicket jQuery UI 6.28.0 and earlier, 7.9.1 and earlier, and 8.0.0-M8 and earlier, a security issue has been discovered in the WYSIWYG editor that allows an attacker to submit arbitrary JS code to WYSIWYG editor.
0
Attacker Value
Unknown

CVE-2012-6708

Disclosure Date: January 18, 2018 (last updated November 08, 2023)
jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differentiate selectors from HTML in a reliable fashion. In vulnerable versions, jQuery determined whether the input was HTML by looking for the '<' character anywhere in the string, giving attackers more flexibility when attempting to construct a malicious payload. In fixed versions, jQuery only deems the input to be HTML if it explicitly starts with the '<' character, limiting exploitability only to attackers who can control the beginning of a string, which is far less common.
0
Attacker Value
Unknown

CVE-2016-10707

Disclosure Date: January 18, 2018 (last updated February 10, 2024)
jQuery 3.0.0-rc.1 is vulnerable to Denial of Service (DoS) due to removing a logic that lowercased attribute names. Any attribute getter using a mixed-cased name for boolean attributes goes into an infinite recursion, exceeding the stack call limit.
Attacker Value
Unknown

CVE-2014-6071

Disclosure Date: January 16, 2018 (last updated November 26, 2024)
jQuery 1.4.2 allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to use of the text method inside after.
0
Attacker Value
Unknown

CVE-2017-1000170

Disclosure Date: November 17, 2017 (last updated November 26, 2024)
jqueryFileTree 2.1.5 and older Directory Traversal
Attacker Value
Unknown

CVE-2015-7943

Disclosure Date: October 18, 2017 (last updated November 26, 2024)
Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.41, the jQuery Update module 7.x-2.x before 7.x-2.7 for Drupal, and the LABjs module 7.x-1.x before 7.x-1.8 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-3233.
0