Show filters
203 Total Results
Displaying 81-90 of 203
Sort by:
Attacker Value
Unknown
CVE-2022-39289
Disclosure Date: October 07, 2022 (last updated February 24, 2025)
ZoneMinder is a free, open source Closed-circuit television software application. In affected versions the ZoneMinder API Exposes Database Log contents to user without privileges, allows insertion, modification, deletion of logs without System Privileges. Users are advised yo upgrade as soon as possible. Users unable to upgrade should disable database logging.
0
Attacker Value
Unknown
CVE-2022-39285
Disclosure Date: October 07, 2022 (last updated February 24, 2025)
ZoneMinder is a free, open source Closed-circuit television software application The file parameter is vulnerable to a cross site scripting vulnerability (XSS) by backing out of the current "tr" "td" brackets. This then allows a malicious user to provide code that will execute when a user views the specific log on the "view=log" page. This vulnerability allows an attacker to store code within the logs that will be executed when loaded by a legitimate user. These actions will be performed with the permission of the victim. This could lead to data loss and/or further exploitation including account takeover. This issue has been addressed in versions `1.36.27` and `1.37.24`. Users are advised to upgrade. Users unable to upgrade should disable database logging.
0
Attacker Value
Unknown
CVE-2022-3076
Disclosure Date: September 26, 2022 (last updated February 24, 2025)
The CM Download Manager WordPress plugin before 2.8.6 allows high privilege users such as admin to upload arbitrary files by setting the any extension via the plugin's setting, which could be used by admins of multisite blog to upload PHP files for example.
0
Attacker Value
Unknown
CVE-2022-2443
Disclosure Date: July 18, 2022 (last updated October 07, 2023)
The FreeMind WP Browser plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.2. This is due to missing nonce protection on the FreemindOptions() function found in the ~/freemind-wp-browser.php file. This makes it possible for unauthenticated attackers to inject malicious web scripts into the page, granted they can trick a site's administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2022-2435
Disclosure Date: July 18, 2022 (last updated February 24, 2025)
The AnyMind Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.1. This is due to missing nonce protection on the createDOMStructure() function found in the ~/anymind-widget-id.php file. This makes it possible for unauthenticated attackers to inject malicious web scripts into the page, granted they can trick a site’s administrator into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2021-33654
Disclosure Date: June 27, 2022 (last updated February 24, 2025)
When performing the initialization operation of the Split operator, if a dimension in the input shape is 0, it will cause a division by 0 exception.
0
Attacker Value
Unknown
CVE-2021-33653
Disclosure Date: June 27, 2022 (last updated February 24, 2025)
When performing the derivation shape operation of the SpaceToBatch operator, if there is a value of 0 in the parameter block_shape element, it will cause a division by 0 exception.
0
Attacker Value
Unknown
CVE-2021-33652
Disclosure Date: June 27, 2022 (last updated February 24, 2025)
When the Reduce operator run operation is executed, if there is a value of 0 in the parameter axis_sizes element, it will cause a division by 0 exception.
0
Attacker Value
Unknown
CVE-2021-33651
Disclosure Date: June 27, 2022 (last updated February 24, 2025)
When performing the analytical operation of the DepthwiseConv2D operator, if the attribute depth_multiplier is 0, it will cause a division by 0 exception.
0
Attacker Value
Unknown
CVE-2021-33650
Disclosure Date: June 27, 2022 (last updated February 24, 2025)
When performing the inference shape operation of the SparseToDense operator, if the number of inputs is less than three, it will access data outside of bounds of inputs which allocated from heap buffers.
0