Show filters
82 Total Results
Displaying 51-60 of 82
Sort by:
Attacker Value
Unknown
CVE-2022-40427
Disclosure Date: September 19, 2022 (last updated February 24, 2025)
The d8s-domains for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-networking package. The affected version is 0.1.0
0
Attacker Value
Unknown
CVE-2022-40424
Disclosure Date: September 19, 2022 (last updated February 24, 2025)
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. A potential code execution backdoor inserted by third parties is the democritus-networking package. The affected version of d8s-urls is 0.1.0
0
Attacker Value
Unknown
CVE-2022-38880
Disclosure Date: September 19, 2022 (last updated February 24, 2025)
The d8s-urls for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The affected version is 0.1.0.
0
Attacker Value
Unknown
CVE-2022-28719
Disclosure Date: April 28, 2022 (last updated February 23, 2025)
Missing authentication for critical function in AssetView prior to Ver.13.2.0 allows a remote unauthenticated attacker with some knowledge on the system configuration to upload a crafted configuration file to the managing server, which may result in the managed clients to execute arbitrary code with the administrative privilege.
0
Attacker Value
Unknown
CVE-2021-38834
Disclosure Date: April 05, 2022 (last updated October 07, 2023)
easy-mock v1.5.0-v1.6.0 allows remote attackers to bypass the vm2 sandbox and execute arbitrary system commands through special js code.
0
Attacker Value
Unknown
CVE-2021-25023
Disclosure Date: January 03, 2022 (last updated February 23, 2025)
The Speed Booster Pack ⚡ PageSpeed Optimization Suite WordPress plugin before 4.3.3.1 does not escape the sbp_convert_table_name parameter before using it in a SQL statement to convert the related table, leading to an SQL injection
0
Attacker Value
Unknown
CVE-2021-32827
Disclosure Date: August 16, 2021 (last updated February 23, 2025)
MockServer is open source software which enables easy mocking of any system you integrate with via HTTP or HTTPS. An attacker that can trick a victim into visiting a malicious site while running MockServer locally, will be able to run arbitrary code on the MockServer machine. With an overly broad default CORS configuration MockServer allows any site to send cross-site requests. Additionally, MockServer allows you to create dynamic expectations using Javascript or Velocity templates. Both engines may allow an attacker to execute arbitrary code on-behalf of MockServer. By combining these two issues (Overly broad CORS configuration + Script injection), an attacker could serve a malicious page so that if a developer running MockServer visits it, they will get compromised. For more details including a PoC see the referenced GHSL-2021-059.
0
Attacker Value
Unknown
CVE-2021-24430
Disclosure Date: August 02, 2021 (last updated February 23, 2025)
The Speed Booster Pack ⚡ PageSpeed Optimization Suite WordPress plugin before 4.2.0 did not validate its caching_exclude_urls and caching_include_query_strings settings before outputting them in a PHP file, which could lead to RCE
0
Attacker Value
Unknown
CVE-2020-25106
Disclosure Date: December 22, 2020 (last updated February 22, 2025)
Nanosystems SupRemo 4.1.3.2348 allows attackers to obtain LocalSystem access because File Manager can be used to rename Supremo.exe and then upload a Trojan horse with the Supremo.exe filename.
0
Attacker Value
Unknown
CVE-2020-25406
Disclosure Date: November 18, 2020 (last updated February 22, 2025)
app\admin\controller\sys\Uploads.php in lemocms 1.8.x allows users to upload files to upload executable files.
0