Show filters
150 Total Results
Displaying 71-80 of 150
Sort by:
Attacker Value
Unknown

CVE-2020-13545

Disclosure Date: January 06, 2021 (last updated February 22, 2025)
An exploitable signed conversion vulnerability exists in the TextMaker document parsing functionality of SoftMaker Office 2021’s TextMaker application. A specially crafted document can cause the document parser to miscalculate a length used to allocate a buffer, later upon usage of this buffer the application will write outside its bounds resulting in a heap-based memory corruption. An attacker can entice the victim to open a document to trigger this vulnerability.
Attacker Value
Unknown

CVE-2020-13544

Disclosure Date: January 06, 2021 (last updated February 22, 2025)
An exploitable sign extension vulnerability exists in the TextMaker document parsing functionality of SoftMaker Office 2021’s TextMaker application. A specially crafted document can cause the document parser to sign-extend a length used to terminate a loop, which can later result in the loop’s index being used to write outside the bounds of a heap buffer during the reading of file data. An attacker can entice the victim to open a document to trigger this vulnerability.
Attacker Value
Unknown

CVE-2020-13526

Disclosure Date: December 10, 2020 (last updated February 22, 2025)
SQL injection vulnerability exists in the handling of sort parameters in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. The reportTables_Ajax and clientSetupAjax pages are vulnerable to SQL injection in the sort parameter.An attacker can make an authenticated HTTP request to trigger these vulnerabilities.
Attacker Value
Unknown

CVE-2020-13525

Disclosure Date: December 03, 2020 (last updated February 22, 2025)
The sort parameter in the download page /sysworkflow/en/neoclassic/reportTables/reportTables_Ajax is vulnerable to SQL injection in ProcessMaker 3.4.11. A specially crafted HTTP request can cause an SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Attacker Value
Unknown

CVE-2020-28650

Disclosure Date: November 16, 2020 (last updated February 22, 2025)
The WPBakery plugin before 6.4.1 for WordPress allows XSS because it calls kses_remove_filters to disable the standard WordPress XSS protection mechanism for the Author and Contributor roles.
Attacker Value
Unknown

CVE-2020-25990

Disclosure Date: October 01, 2020 (last updated February 22, 2025)
WebsiteBaker 2.12.2 allows SQL Injection via parameter 'display_name' in /websitebaker/admin/preferences/save.php. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Attacker Value
Unknown

CVE-2020-9298

Disclosure Date: August 28, 2020 (last updated February 22, 2025)
The Spinnaker template resolution functionality is vulnerable to Server-Side Request Forgery (SSRF), which allows an attacker to send requests on behalf of Spinnaker potentially leading to sensitive data disclosure.
Attacker Value
Unknown

CVE-2013-7489

Disclosure Date: June 26, 2020 (last updated February 21, 2025)
The Beaker library through 1.11.0 for Python is affected by deserialization of untrusted data, which could lead to arbitrary code execution.
Attacker Value
Unknown

CVE-2020-12079

Disclosure Date: April 23, 2020 (last updated February 21, 2025)
Beaker before 0.8.9 allows a sandbox escape, enabling system access and code execution. This occurs because Electron context isolation is not used, and therefore an attacker can conduct a prototype-pollution attack against the Electron internal messaging API.
Attacker Value
Unknown

CVE-2011-4322

Disclosure Date: January 21, 2020 (last updated February 21, 2025)
websitebaker prior to and including 2.8.1 has an authentication error in backup module.