Show filters
150 Total Results
Displaying 51-60 of 150
Sort by:
Attacker Value
Unknown
CVE-2022-31580
Disclosure Date: July 11, 2022 (last updated February 24, 2025)
The sanojtharindu/caretakerr-api repository through 2021-05-17 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
0
Attacker Value
Unknown
CVE-2022-32987
Disclosure Date: June 23, 2022 (last updated February 24, 2025)
Multiple cross-site scripting (XSS) vulnerabilities in /bsms/?page=manage_account of Simple Bakery Shop Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Username or Full Name fields.
0
Attacker Value
Unknown
CVE-2021-32997
Disclosure Date: May 25, 2022 (last updated February 23, 2025)
The affected Baker Hughes Bentley Nevada products (3500 System 1 6.x, Part No. 3060/00 versions 6.98 and prior, 3500 System 1, Part No. 3071/xx & 3072/xx versions 21.1 HF1 and prior, 3500 Rack Configuration, Part No. 129133-01 versions 6.4 and prior, and 3500/22M Firmware, Part No. 288055-01 versions 5.05 and prior) utilize a weak encryption algorithm for storage and transmission of sensitive data, which may allow an attacker to more easily obtain credentials used for access.
0
Attacker Value
Unknown
CVE-2022-28063
Disclosure Date: April 04, 2022 (last updated October 07, 2023)
Simple Bakery Shop Management System v1.0 contains a file disclosure via /bsms/?page=products.
0
Attacker Value
Unknown
CVE-2022-25393
Disclosure Date: March 02, 2022 (last updated February 23, 2025)
Simple Bakery Shop Management v1.0 was discovered to contain a SQL injection vulnerability via the username parameter.
0
Attacker Value
Unknown
CVE-2021-34087
Disclosure Date: January 10, 2022 (last updated February 23, 2025)
In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5.2.16, the local webserver can be used for clickjacking. This includes the settings page.
0
Attacker Value
Unknown
CVE-2021-34086
Disclosure Date: January 10, 2022 (last updated February 23, 2025)
In Ultimaker S3 3D printer, Ultimaker S5 3D printer, Ultimaker 3 3D printer S-line through 6.3 and Ultimaker 3 through 5.2.16, the local webserver hosts APIs vulnerable to CSRF. They do not verify incoming requests.
0
Attacker Value
Unknown
CVE-2021-24243
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.6 did not have capability checks nor sanitization, allowing low privilege users (subscriber+) to call it and set XSS payloads, which will be triggered in all backend pages.
0
Attacker Value
Unknown
CVE-2021-24244
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
An AJAX action registered by the WPBakery Page Builder (Visual Composer) Clipboard WordPress plugin before 4.5.8 did not have capability checks, allowing low privilege users, such as subscribers, to update the license options (key, email).
0
Attacker Value
Unknown
CVE-2020-28587
Disclosure Date: February 23, 2021 (last updated February 22, 2025)
A specially crafted document can cause the document parser to copy data from a particular record type into a static-sized buffer within an object that is smaller than the size used for the copy, which will cause a heap-based buffer overflow. An attacker can entice the victim to open a document to trigger this vulnerability. This affects SoftMaker Software GmbH SoftMaker Office PlanMaker 2021 (Revision 1014).
0