Show filters
75 Total Results
Displaying 51-60 of 75
Sort by:
Attacker Value
Unknown
CVE-2021-24565
Disclosure Date: August 23, 2021 (last updated February 23, 2025)
The Contact Form 7 Captcha WordPress plugin before 0.0.9 does not have any CSRF check in place when saving its settings, allowing attacker to make a logged in user with the manage_options change them. Furthermore, the settings are not escaped when output in attributes, leading to a Stored Cross-Site Scripting issue.
0
Attacker Value
Unknown
CVE-2021-39362
Disclosure Date: August 22, 2021 (last updated February 23, 2025)
An XSS issue was discovered in ReCaptcha Solver 5.7. A response from Anti-Captcha.com, RuCaptcha.com, 2captcha.com, DEATHbyCAPTCHA.com, ImageTyperz.com, or BestCaptchaSolver.com in setCaptchaCode() is inserted into the DOM as HTML, resulting in full control over the user's browser by these servers.
0
Attacker Value
Unknown
CVE-2021-31245
Disclosure Date: May 06, 2021 (last updated February 22, 2025)
omr-admin.py in openmptcprouter-vps-admin 0.57.3 and earlier compares the user provided password with the original password in a length dependent manner, which allows remote attackers to guess the password via a timing attack.
0
Attacker Value
Unknown
CVE-2020-27265
Disclosure Date: January 14, 2021 (last updated February 22, 2025)
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server: All 6.x versions are vulnerable to a stack-based buffer overflow. Opening a specifically crafted OPC UA message could allow an attacker to crash the server and remotely execute code.
0
Attacker Value
Unknown
CVE-2020-27263
Disclosure Date: January 14, 2021 (last updated February 22, 2025)
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server: All 6.x versions, are vulnerable to a heap-based buffer overflow. Opening a specifically crafted OPC UA message could allow an attacker to crash the server and potentially leak data.
0
Attacker Value
Unknown
CVE-2020-27267
Disclosure Date: January 14, 2021 (last updated February 22, 2025)
KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-Aggregator (all versions), Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server v7.68.804 and v7.66, and Software Toolbox TOP Server all 6.x versions, are vulnerable to a heap-based buffer overflow. Opening a specifically crafted OPC UA message could allow an attacker to crash the server and potentially leak data.
0
Attacker Value
Unknown
CVE-2020-15514
Disclosure Date: July 07, 2020 (last updated February 21, 2025)
The jh_captcha extension through 2.1.3, and 3.x through 3.0.2, for TYPO3 allows XSS.
0
Attacker Value
Unknown
CVE-2019-14282
Disclosure Date: July 26, 2019 (last updated November 27, 2024)
The simple_captcha2 gem 0.2.3 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party.
0
Attacker Value
Unknown
CVE-2019-7412
Disclosure Date: February 05, 2019 (last updated November 27, 2024)
The PS PHPCaptcha WP plugin before v1.2.0 for WordPress mishandles sanitization of input values.
0
Attacker Value
Unknown
CVE-2018-18531
Disclosure Date: October 19, 2018 (last updated November 27, 2024)
text/impl/DefaultTextCreator.java, text/impl/ChineseTextProducer.java, and text/impl/FiveLetterFirstNameTextCreator.java in kaptcha 2.3.2 use the Random (rather than SecureRandom) function for generating CAPTCHA values, which makes it easier for remote attackers to bypass intended access restrictions via a brute-force approach.
0