Show filters
543 Total Results
Displaying 71-80 of 543
Sort by:
Attacker Value
Unknown

CVE-2021-41731

Disclosure Date: September 16, 2022 (last updated October 08, 2023)
Cross Site Scripting (XSS vulnerability exists in )Sourcecodester News247 News Magazine (CMS) PHP 5.6 or higher and MySQL 5.7 or higher via the blog category name field
Attacker Value
Unknown

CVE-2017-20131

Disclosure Date: July 16, 2022 (last updated October 07, 2023)
A vulnerability was found in Itech News Portal 6.28. It has been classified as critical. Affected is an unknown function of the file /news-portal-script/information.php. The manipulation of the argument inf leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2021-36912

Disclosure Date: May 04, 2022 (last updated October 07, 2023)
Stored Cross-Site Scripting (XSS) vulnerability in Andrea Pernici News Sitemap for Google plugin <= 1.0.16 on WordPress, attackers must have contributor or higher user role.
Attacker Value
Unknown

CVE-2021-24867

Disclosure Date: February 21, 2022 (last updated October 07, 2023)
Numerous Plugins and Themes from the AccessPress Themes (aka Access Keys) vendor are backdoored due to their website being compromised. Only plugins and themes downloaded via the vendor website are affected, and those hosted on wordpress.org are not. However, all of them were updated or removed to avoid any confusion
Attacker Value
Unknown

CVE-2021-41256

Disclosure Date: November 30, 2021 (last updated February 23, 2025)
nextcloud news-android is an Android client for the Nextcloud news/feed reader app. In affected versions the Nextcloud News for Android app has a security issue by which a malicious application installed on the same device can send it an arbitrary Intent that gets reflected back, unintentionally giving read and write access to non-exported Content Providers in Nextcloud News for Android. Users should upgrade to version 0.9.9.63 or higher as soon as possible.
Attacker Value
Unknown

CVE-2021-39317

Disclosure Date: October 06, 2021 (last updated February 23, 2025)
A WordPress plugin and several WordPress themes developed by AccessPress Themes are vulnerable to malicious file uploads via the plugin_offline_installer AJAX action due to a missing capability check in the plugin_offline_installer_callback function found in the /demo-functions.php file or /welcome.php file of the affected products. The complete list of affected products and their versions are below: WordPress Plugin: AccessPress Demo Importer <=1.0.6 WordPress Themes: accesspress-basic <= 3.2.1 accesspress-lite <= 2.92 accesspress-mag <= 2.6.5 accesspress-parallax <= 4.5 accesspress-root <= 2.5 accesspress-store <= 2.4.9 agency-lite <= 1.1.6 arrival <= 1.4.2 bingle <= 1.0.4 bloger <= 1.2.6 brovy <= 1.3 construction-lite <= 1.2.5 doko <= 1.0.27 edict-lite <= 1.1.4 eightlaw-lite <= 2.1.5 eightmedi-lite <= 2.1.8 eight-sec <= 1.1.4 eightstore-lite <= 1.2.5 enlighten <= 1.3.5 fotography <= 2.4.0 opstore <= 1.4.3 parallaxsome <= 1.3.6 punte <= 1.1.2 revolve <= 1.3.1 ripple <= 1.2.0 sakala …
Attacker Value
Unknown

CVE-2021-36791

Disclosure Date: August 13, 2021 (last updated November 28, 2024)
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows Information Disclosure of application registration data.
Attacker Value
Unknown

CVE-2021-36789

Disclosure Date: August 13, 2021 (last updated February 23, 2025)
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection.
Attacker Value
Unknown

CVE-2021-36790

Disclosure Date: August 13, 2021 (last updated February 23, 2025)
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows XSS.
Attacker Value
Unknown

CVE-2021-36792

Disclosure Date: August 13, 2021 (last updated February 23, 2025)
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 has incorrect Access Control for confirming various applications.