Show filters
74 Total Results
Displaying 61-70 of 74
Sort by:
Attacker Value
Unknown

CVE-2021-39297

Disclosure Date: February 16, 2022 (last updated October 07, 2023)
Potential vulnerabilities have been identified in UEFI firmware (BIOS) for some PC products which may allow escalation of privilege and arbitrary code execution.
Attacker Value
Unknown

CVE-2021-23173

Disclosure Date: January 10, 2022 (last updated February 23, 2025)
The affected product is vulnerable to an improper access control, which may allow an authenticated user to gain unauthorized access to sensitive data.
Attacker Value
Unknown

CVE-2021-36832

Disclosure Date: August 17, 2021 (last updated February 23, 2025)
WordPress Popups, Welcome Bar, Optins and Lead Generation Plugin – Icegram (versions <= 2.0.2) vulnerable at "Headline" (&message_data[16][headline]) input.
Attacker Value
Unknown

CVE-2021-29781

Disclosure Date: July 29, 2021 (last updated February 23, 2025)
IBM Partner Engagement Manager 2.0 could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization flaw. By sending specially-crafted data, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 203091.
Attacker Value
Unknown

CVE-2020-5421

Disclosure Date: September 17, 2020 (last updated November 08, 2023)
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
Attacker Value
Unknown

CVE-2019-6184

Disclosure Date: November 20, 2019 (last updated November 27, 2024)
A potential vulnerability in the discontinued Customer Engagement Service (CCSDK) software version 2.0.21.1 may allow local privilege escalation.
Attacker Value
Unknown

CVE-2016-10963

Disclosure Date: September 16, 2019 (last updated January 11, 2024)
The icegram plugin before 1.9.19 for WordPress has XSS.
Attacker Value
Unknown

CVE-2016-10962

Disclosure Date: September 16, 2019 (last updated January 11, 2024)
The icegram plugin before 1.9.19 for WordPress has CSRF via the wp-admin/edit.php option_name parameter.
Attacker Value
Unknown

CVE-2019-15830

Disclosure Date: August 30, 2019 (last updated January 11, 2024)
The icegram plugin before 1.10.29 for WordPress has ig_cat_list XSS.
0
Attacker Value
Unknown

CVE-2019-7727

Disclosure Date: April 23, 2019 (last updated November 27, 2024)
In NICE Engage through 6.5, the default configuration binds an unauthenticated JMX/RMI interface to all network interfaces, without restricting registration of MBeans, which allows remote attackers to execute arbitrary code via the RMI protocol by using the JMX connector. The observed affected TCP port is 6338 but, based on the product's configuration, a different one could be vulnerable.
0