Show filters
268 Total Results
Displaying 51-60 of 268
Sort by:
Attacker Value
Unknown

CVE-2023-0901

Disclosure Date: February 18, 2023 (last updated October 08, 2023)
Exposure of Sensitive Information to an Unauthorized Actor in GitHub repository pixelfed/pixelfed prior to 0.11.4.
Attacker Value
Unknown

CVE-2022-4671

Disclosure Date: January 30, 2023 (last updated October 08, 2023)
The PixCodes WordPress plugin before 2.3.7 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Attacker Value
Unknown

CVE-2023-22316

Disclosure Date: January 17, 2023 (last updated October 08, 2023)
Hidden functionality vulnerability in PIX-RT100 versions RT100_TEQ_2.1.1_EQ101 and RT100_TEQ_2.1.2_EQ101 allows a network-adjacent attacker to access the product via undocumented Telnet or SSH services.
Attacker Value
Unknown

CVE-2023-22304

Disclosure Date: January 17, 2023 (last updated October 08, 2023)
OS command injection vulnerability in PIX-RT100 versions RT100_TEQ_2.1.1_EQ101 and RT100_TEQ_2.1.2_EQ101 allows a network-adjacent attacker who can access product settings to execute an arbitrary OS command.
Attacker Value
Unknown

CVE-2022-44638

Disclosure Date: November 03, 2022 (last updated February 24, 2025)
In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterize_edges_8 due to an integer overflow in pixman_sample_floor_y.
Attacker Value
Unknown

CVE-2021-46829

Disclosure Date: July 24, 2022 (last updated February 24, 2025)
GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be abused for code execution, especially on 32-bit systems.
Attacker Value
Unknown

CVE-2022-34540

Disclosure Date: July 19, 2022 (last updated February 24, 2025)
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/license/license_tok.cgi. This vulnerability is exploitable via a crafted POST request.
Attacker Value
Unknown

CVE-2022-34539

Disclosure Date: July 19, 2022 (last updated February 24, 2025)
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/curltest.cgi. This vulnerability is exploitable via a crafted POST request.
Attacker Value
Unknown

CVE-2022-34538

Disclosure Date: July 19, 2022 (last updated February 24, 2025)
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a command injection vulnerability in the component /admin/vca/bia/addacph.cgi. This vulnerability is exploitable via a crafted POST request.
Attacker Value
Unknown

CVE-2022-34537

Disclosure Date: July 19, 2022 (last updated February 24, 2025)
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 was discovered to contain a cross-site scripting (XSS) vulnerability via the component bia_oneshot.cgi.