Show filters
148 Total Results
Displaying 51-60 of 148
Sort by:
Attacker Value
Unknown

CVE-2021-40966

Disclosure Date: September 15, 2021 (last updated February 23, 2025)
A Stored XSS exists in TinyFileManager All version up to and including 2.4.6 in /tinyfilemanager.php when the server is given a file that contains HTML and javascript in its name. A malicious user can upload a file with a malicious filename containing javascript code and it will run on any user browser when they access the server.
Attacker Value
Unknown

CVE-2021-40964

Disclosure Date: September 15, 2021 (last updated February 23, 2025)
A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload a file (with Admin credentials or with the CSRF vulnerability) with the "fullpath" parameter containing path traversal strings (../ and ..\) in order to escape the server's intended working directory and write malicious files onto any directory on the computer.
Attacker Value
Unknown

CVE-2020-28589

Disclosure Date: August 11, 2021 (last updated February 23, 2025)
An improper array index validation vulnerability exists in the LoadObj functionality of tinyobjloader v2.0-rc1 and tinyobjloader development commit 79d4421. A specially crafted file could lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
Attacker Value
Unknown

CVE-2021-37573

Disclosure Date: August 09, 2021 (last updated February 23, 2025)
A reflected cross-site scripting (XSS) vulnerability in the web server TTiny Java Web Server and Servlet Container (TJWS) <=1.115 allows an adversary to inject malicious code on the server's "404 Page not Found" error page
Attacker Value
Unknown

CVE-2020-36438

Disclosure Date: August 08, 2021 (last updated February 23, 2025)
An issue was discovered in the tiny_future crate before 0.4.0 for Rust. Future<T> does not have bounds on its Send and Sync traits.
Attacker Value
Unknown

CVE-2020-18428

Disclosure Date: July 26, 2021 (last updated February 23, 2025)
tinyexr commit 0.9.5 was discovered to contain an array index error in the tinyexr::SaveEXR component, which can lead to a denial of service (DOS).
Attacker Value
Unknown

CVE-2020-18430

Disclosure Date: July 26, 2021 (last updated February 23, 2025)
tinyexr 0.9.5 was discovered to contain an array index error in the tinyexr::DecodeEXRImage component, which can lead to a denial of service (DOS).
Attacker Value
Unknown

CVE-2020-19490

Disclosure Date: July 21, 2021 (last updated February 23, 2025)
tinyexr 0.9.5 has a integer overflow over-write in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.
Attacker Value
Unknown

CVE-2020-24026

Disclosure Date: May 18, 2021 (last updated February 22, 2025)
TinyShop, a free and open source mall based on RageFrame2, has a stored XSS vulnerability that affects version 1.2.0. TinyShop allows XSS via the explain_first and again_explain parameters of the /evaluate/index.php page. The vulnerability may be exploited remotely, resulting in cross-site scripting (XSS) or information disclosure.
Attacker Value
Unknown

CVE-2020-35884

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
An issue was discovered in the tiny_http crate through 2020-06-16 for Rust. HTTP Request smuggling can occur via a malformed Transfer-Encoding header.