Show filters
127 Total Results
Displaying 61-70 of 127
Sort by:
Attacker Value
Unknown

CVE-2020-4708

Disclosure Date: September 15, 2020 (last updated November 28, 2024)
IBM Security Trusteer Pinpoint Detect 11.6.5 could disclose some information due to using a wildcard in the Access-Control-Allow-Origin header. IBM X-Force ID: 187371.
Attacker Value
Unknown

CVE-2020-13433

Disclosure Date: May 24, 2020 (last updated February 21, 2025)
Jason2605 AdminPanel 4.0 allows SQL Injection via the editPlayer.php hidden parameter.
Attacker Value
Unknown

CVE-2020-10257

Disclosure Date: March 10, 2020 (last updated February 21, 2025)
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
Attacker Value
Unknown

CVE-2019-18909

Disclosure Date: November 22, 2019 (last updated November 27, 2024)
The VPN software within HP ThinPro does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with root privileges.
Attacker Value
Unknown

CVE-2019-16286

Disclosure Date: November 22, 2019 (last updated November 27, 2024)
An attacker may be able to bypass the OS application filter meant to restrict applications that can be executed by changing browser preferences to launch a separate process that in turn can execute arbitrary commands.
Attacker Value
Unknown

CVE-2019-16285

Disclosure Date: November 22, 2019 (last updated November 27, 2024)
If a local user has been configured and logged in, an unauthenticated attacker with physical access may be able to extract sensitive information onto a local drive.
Attacker Value
Unknown

CVE-2015-9460

Disclosure Date: October 10, 2019 (last updated November 27, 2024)
The booking-system plugin before 2.1 for WordPress has DOPBSPBackEndTranslation::display SQL injection via the language parameter.
Attacker Value
Unknown

CVE-2019-15871

Disclosure Date: September 03, 2019 (last updated November 27, 2024)
The LoginPress plugin before 1.1.4 for WordPress has no capability check for updates to settings.
0
Attacker Value
Unknown

CVE-2019-15872

Disclosure Date: September 03, 2019 (last updated November 27, 2024)
The LoginPress plugin before 1.1.4 for WordPress has SQL injection via an import of settings.
0
Attacker Value
Unknown

CVE-2019-15233

Disclosure Date: August 20, 2019 (last updated November 27, 2024)
The Live:Text Box macro in the Old Street Live Input Macros app before 2.11 for Confluence has XSS, leading to theft of the Administrator Session Cookie.