Show filters
268 Total Results
Displaying 61-70 of 268
Sort by:
Attacker Value
Unknown
CVE-2022-34536
Disclosure Date: July 19, 2022 (last updated February 24, 2025)
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows attackers to access the core log file and perform session hijacking via a crafted session token.
0
Attacker Value
Unknown
CVE-2022-34535
Disclosure Date: July 19, 2022 (last updated February 24, 2025)
Digital Watchdog DW MEGApix IP cameras A7.2.2_20211029 allows unauthenticated attackers to view internal paths and scripts via web files.
0
Attacker Value
Unknown
CVE-2022-28590
Disclosure Date: May 03, 2022 (last updated October 07, 2023)
A Remote Code Execution (RCE) vulnerability exists in Pixelimity 1.0 via admin/admin-ajax.php?action=install_theme.
0
Attacker Value
Unknown
CVE-2022-28589
Disclosure Date: May 03, 2022 (last updated February 23, 2025)
A stored cross-site scripting (XSS) vulnerability in Pixelimity 1.0 allows attackers to execute arbitrary web scripts or HTML via the Title field in admin/pages.php?action=add_new
0
Attacker Value
Unknown
CVE-2022-29417
Disclosure Date: April 25, 2022 (last updated February 23, 2025)
Plugin Settings Update vulnerability in ShortPixel's ShortPixel Adaptive Images plugin <= 3.3.1 at WordPress allows an attacker with a low user role like a subscriber or higher to change the plugin settings.
0
Attacker Value
Unknown
CVE-2021-42866
Disclosure Date: March 31, 2022 (last updated February 23, 2025)
A Cross Site Scripting vulnerabilty exists in Pixelimity 1.0 via the Site Description field in pixelimity/admin/setting.php
0
Attacker Value
Unknown
CVE-2021-44648
Disclosure Date: January 12, 2022 (last updated February 23, 2025)
GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12.
0
Attacker Value
Unknown
CVE-2021-24972
Disclosure Date: December 13, 2021 (last updated February 23, 2025)
The Pixel Cat WordPress plugin before 2.6.3 does not escape some of its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html is disallowed
0
Attacker Value
Unknown
CVE-2021-24922
Disclosure Date: December 13, 2021 (last updated February 23, 2025)
The Pixel Cat WordPress plugin before 2.6.2 does not have CSRF check when saving its settings, and did not sanitise as well as escape some of them, which could allow attacker to make a logged in admin change them and perform Cross-Site Scripting attacks
0
Attacker Value
Unknown
CVE-2021-43563
Disclosure Date: November 10, 2021 (last updated February 23, 2025)
An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The Access Control in the bundled media browser is broken, which allows an unauthenticated attacker to perform requests to the pixx.io API for the configured API user. This allows an attacker to download various media files from the DAM system.
0