Show filters
104 Total Results
Displaying 81-90 of 104
Sort by:
Attacker Value
Unknown
CVE-2019-10219
Disclosure Date: November 08, 2019 (last updated November 08, 2023)
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
0
Attacker Value
Unknown
CVE-2015-9455
Disclosure Date: October 07, 2019 (last updated November 27, 2024)
The buddypress-activity-plus plugin before 1.6.2 for WordPress has CSRF with resultant directory traversal via the wp-admin/admin-ajax.php bpfb_photos[] parameter in a bpfb_remove_temp_images action.
0
Attacker Value
Unknown
CVE-2016-10890
Disclosure Date: August 21, 2019 (last updated December 27, 2023)
The aryo-activity-log plugin before 2.3.2 for WordPress has XSS.
0
Attacker Value
Unknown
CVE-2016-10891
Disclosure Date: August 21, 2019 (last updated December 27, 2023)
The aryo-activity-log plugin before 2.3.3 for WordPress has XSS.
0
Attacker Value
Unknown
CVE-2019-10173
Disclosure Date: July 23, 2019 (last updated November 27, 2024)
It was found that xstream API version 1.4.10 before 1.4.11 introduced a regression for a previous deserialization flaw. If the security framework has not been initialized, it may allow a remote attacker to run arbitrary shell commands when unmarshalling XML or any supported format. e.g. JSON. (regression of CVE-2013-7285)
0
Attacker Value
Unknown
CVE-2017-1601
Disclosure Date: May 02, 2018 (last updated November 26, 2024)
IBM Security Guardium 10.0, 10.0.1, and 10.1 through 10.1.4 Database Activity Monitor does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 132624.
0
Attacker Value
Unknown
CVE-2018-8729
Disclosure Date: March 15, 2018 (last updated December 27, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote attackers to inject arbitrary JavaScript or HTML via a title that is not escaped.
0
Attacker Value
Unknown
CVE-2016-0235
Disclosure Date: March 12, 2018 (last updated November 26, 2024)
IBM Security Guardium Database Activity Monitor 10 allows local users to have unspecified impact by leveraging administrator access to a hardcoded password, related to use on GRUB systems. IBM X-Force ID: 110326.
0
Attacker Value
Unknown
CVE-2016-0237
Disclosure Date: March 12, 2018 (last updated November 26, 2024)
IBM Security Guardium Database Activity Monitor 10 allows local users to obtain sensitive information by reading cached browser data. IBM X-Force ID: 110328.
0
Attacker Value
Unknown
CVE-2018-1368
Disclosure Date: February 09, 2018 (last updated November 26, 2024)
IBM Security Guardium Database Activity Monitor 9.0, 9.1, and 9.5 could allow a local user with low privileges to view report pages and perform some actions that only an admin should be performing, so there is risk that someone not authorized can change things that they are not suppose to. IBM X-Force ID: 137765.
0