Show filters
200 Total Results
Displaying 61-70 of 200
Sort by:
Attacker Value
Unknown
CVE-2021-28157
Disclosure Date: April 14, 2021 (last updated February 22, 2025)
An SQL Injection issue in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows an administrative user to execute arbitrary SQL commands via a username in api/security/userinfo/delete.
0
Attacker Value
Unknown
CVE-2021-28048
Disclosure Date: April 14, 2021 (last updated February 22, 2025)
An overly permissive CORS policy in Devolutions Server before 2021.1 and Devolutions Server LTS before 2020.3.18 allows a remote attacker to leak cross-origin data via a crafted HTML page.
0
Attacker Value
Unknown
CVE-2021-23921
Disclosure Date: April 01, 2021 (last updated February 22, 2025)
An issue was discovered in Devolutions Server before 2020.3. There is broken access control on Password List entry elements.
0
Attacker Value
Unknown
CVE-2021-23925
Disclosure Date: April 01, 2021 (last updated February 22, 2025)
An issue was discovered in Devolutions Server before 2020.3. There is a cross-site scripting (XSS) vulnerability in entries of type Document.
0
Attacker Value
Unknown
CVE-2021-23923
Disclosure Date: April 01, 2021 (last updated February 22, 2025)
An issue was discovered in Devolutions Server before 2020.3. There is Broken Authentication with Windows domain users.
0
Attacker Value
Unknown
CVE-2021-23924
Disclosure Date: April 01, 2021 (last updated February 22, 2025)
An issue was discovered in Devolutions Server before 2020.3. There is an exposure of sensitive information in diagnostic files.
0
Attacker Value
Unknown
CVE-2020-22839
Disclosure Date: February 09, 2021 (last updated February 22, 2025)
Reflected cross-site scripting vulnerability (XSS) in the evoadm.php file in b2evolution cms version 6.11.6-stable allows remote attackers to inject arbitrary webscript or HTML code via the tab3 parameter.
0
Attacker Value
Unknown
CVE-2020-22841
Disclosure Date: February 09, 2021 (last updated February 22, 2025)
Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution via the plugin name input field in the plugin module.
0
Attacker Value
Unknown
CVE-2020-22840
Disclosure Date: February 09, 2021 (last updated February 22, 2025)
Open redirect vulnerability in b2evolution CMS version prior to 6.11.6 allows an attacker to perform malicious open redirects to an attacker controlled resource via redirect_to parameter in email_passthrough.php.
0
Attacker Value
Unknown
CVE-2021-3349
Disclosure Date: February 01, 2021 (last updated February 22, 2025)
GNOME Evolution through 3.38.3 produces a "Valid signature" message for an unknown identifier on a previously trusted key because Evolution does not retrieve enough information from the GnuPG API. NOTE: third parties dispute the significance of this issue, and dispute whether Evolution is the best place to change this behavior
0