Show filters
111 Total Results
Displaying 51-60 of 111
Sort by:
Attacker Value
Unknown

CVE-2021-24903

Disclosure Date: February 28, 2022 (last updated February 23, 2025)
The GRAND FlaGallery WordPress plugin through 6.1.2 does not sanitise and escape some of its gallery settings, which could allow high privilege users to perform Cross-Site scripting attacks even when the unfiltered_html capability is disallowed.
Attacker Value
Unknown

CVE-2022-23982

Disclosure Date: January 28, 2022 (last updated February 23, 2025)
The vulnerability discovered in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4) allows server information exposure.
Attacker Value
Unknown

CVE-2022-23981

Disclosure Date: January 28, 2022 (last updated February 23, 2025)
The vulnerability allows Subscriber+ level users to create brands in WordPress Perfect Brands for WooCommerce plugin (versions <= 2.0.4).
Attacker Value
Unknown

CVE-2022-0210

Disclosure Date: January 18, 2022 (last updated February 23, 2025)
The Random Banner WordPress plugin is vulnerable to Stored Cross-Site Scripting due to insufficient escaping via the category parameter found in the ~/include/models/model.php file which allowed attackers with administrative user access to inject arbitrary web scripts, in versions up to and including 4.1.4. This affects multi-site installations where unfiltered_html is disabled for administrators, and sites where unfiltered_html is disabled.
Attacker Value
Unknown

CVE-2021-45705

Disclosure Date: December 27, 2021 (last updated October 07, 2023)
An issue was discovered in the nanorand crate before 0.6.1 for Rust. There can be multiple mutable references to the same object because the TlsWyRand Deref implementation dereferences a raw pointer.
Attacker Value
Unknown

CVE-2020-27372

Disclosure Date: October 11, 2021 (last updated February 23, 2025)
A buffer overflow vulnerability exists in Brandy Basic V Interpreter 1.21 in the run_interpreter function.
Attacker Value
Unknown

CVE-2021-34656

Disclosure Date: August 13, 2021 (last updated February 23, 2025)
The 2Way VideoCalls and Random Chat - HTML5 Webcam Videochat WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the `vws_notice` function found in the ~/inc/requirements.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 5.2.7.
Attacker Value
Unknown

CVE-2021-24503

Disclosure Date: August 02, 2021 (last updated February 23, 2025)
The Popular Brand Icons – Simple Icons WordPress plugin before 2.7.8 does not sanitise or validate some of its shortcode parameters, such as "color", "size" or "class", allowing users with a role as low as Contributor to set Cross-Site payload in them. A post made by a contributor would still have to be approved by an admin to have the XSS triggered in the frontend, however, higher privilege users, such as editor could exploit this without the need of approval, and even when the blog disallows the unfiltered_html capability.
Attacker Value
Unknown

CVE-2021-0143

Disclosure Date: June 17, 2021 (last updated February 22, 2025)
Improper permissions in the installer for the Intel(R) Brand Verification Tool before version 11.0.0.1225 may allow an authenticated user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2021-0086

Disclosure Date: June 09, 2021 (last updated February 22, 2025)
Observable response discrepancy in floating-point operations for some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.