Show filters
79 Total Results
Displaying 51-60 of 79
Sort by:
Attacker Value
Unknown

CVE-2021-38188

Disclosure Date: August 08, 2021 (last updated November 28, 2024)
An issue was discovered in the iced-x86 crate through 1.10.3 for Rust. In Decoder::new(), slice.get_unchecked(slice.length()) is used unsafely.
Attacker Value
Unknown

CVE-2021-28953

Disclosure Date: March 21, 2021 (last updated February 22, 2025)
The unofficial C/C++ Advanced Lint extension before 1.9.0 for Visual Studio Code allows attackers to execute arbitrary binaries if the user opens a crafted repository.
Attacker Value
Unknown

CVE-2020-35598

Disclosure Date: December 23, 2020 (last updated February 22, 2025)
ACS Advanced Comment System 1.0 is affected by Directory Traversal via an advanced_component_system/index.php?ACS_path=..%2f URI. NOTE: this might be the same as CVE-2009-4623
Attacker Value
Unknown

CVE-2020-25102

Disclosure Date: September 03, 2020 (last updated February 22, 2025)
silverstripe-advancedreports (aka the Advanced Reports module for SilverStripe) 1.0 through 2.0 is vulnerable to Cross-Site Scripting (XSS) because it is possible to inject and store malicious JavaScript code. The affects admin/advanced-reports/DataObjectReport/EditForm/field/DataObjectReport/item (aka report preview) when an SVG document is provided in the Description parameter.
Attacker Value
Unknown

CVE-2019-20336

Disclosure Date: January 05, 2020 (last updated February 21, 2025)
In PHP Scripts Mall advanced-real-estate-script 4.0.9, the search-results.php searchtext parameter is vulnerable to XSS.
Attacker Value
Unknown

CVE-2016-10929

Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The advanced-ajax-page-loader plugin before 2.7.7 for WordPress has no protection against the reading of uploaded files when not logged in.
0
Attacker Value
Unknown

CVE-2019-20337

Disclosure Date: April 19, 2019 (last updated February 21, 2025)
In PHP Scripts Mall advanced-real-estate-script 4.0.9, the news_edit.php news_id parameter is vulnerable to SQL Injection.
Attacker Value
Unknown

CVE-2018-18845

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
internal/advanced_comment_system/index.php and internal/advanced_comment_system/admin.php in Advanced Comment System, version 1.0, contain a reflected cross-site scripting vulnerability via ACS_path. A remote unauthenticated attacker could potentially exploit this vulnerability to supply malicious HTML or JavaScript code to a vulnerable web application, which is then reflected back to the victim and executed by the web browser. The product is discontinued.
0
Attacker Value
Unknown

CVE-2018-18619

Disclosure Date: November 29, 2018 (last updated November 27, 2024)
internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query, allowing remote attackers to execute the sqli attack via a URL in the "page" parameter. NOTE: The product is discontinued.
0
Attacker Value
Unknown

CVE-2018-15187

Disclosure Date: August 10, 2018 (last updated November 27, 2024)
PHP Scripts Mall advanced-real-estate-script 4.0.9 has CSRF via edit-profile.php.
0