Show filters
120 Total Results
Displaying 81-90 of 120
Sort by:
Attacker Value
Unknown
CVE-2016-10606
Disclosure Date: June 01, 2018 (last updated November 26, 2024)
grunt-webdriver-qunit is a grunt plugin to run qunit with webdriver in grunt grunt-webdriver-qunit downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.
0
Attacker Value
Unknown
CVE-2018-0579
Disclosure Date: May 14, 2018 (last updated November 26, 2024)
Cross-site scripting vulnerability in Open Graph for Facebook, Google+ and Twitter Card Tags plugin prior to version 2.2.4.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2017-17744
Disclosure Date: December 19, 2017 (last updated November 26, 2024)
A cross-site scripting (XSS) vulnerability in the custom-map plugin through 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map_id parameter to view/advancedsettings.php.
0
Attacker Value
Unknown
CVE-2015-7517
Disclosure Date: August 29, 2017 (last updated November 26, 2024)
Multiple SQL injection vulnerabilities in the Double Opt-In for Download plugin before 2.0.9 for WordPress allow remote attackers to execute arbitrary SQL commands via the ver parameter to (1) class-doifd-download.php or (2) class-doifd-landing-page.php in public/includes/.
0
Attacker Value
Unknown
CVE-2017-12199
Disclosure Date: August 02, 2017 (last updated November 26, 2024)
The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has SQL injection with these wp-admin/admin-ajax.php POST actions: catalogue_update_order list-item, video_update_order video-item, image_update_order list-item, tag_group_update_order list_item, category_products_update_order category-product-item, custom_fields_update_order field-item, categories_update_order category-item, subcategories_update_order subcategory-item, and tags_update_order tag-list-item.
0
Attacker Value
Unknown
CVE-2017-12200
Disclosure Date: August 02, 2017 (last updated November 26, 2024)
The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has XSS in the Add Product Manually component.
0
Attacker Value
Unknown
CVE-2015-0902
Disclosure Date: April 03, 2015 (last updated October 05, 2023)
The Semper Fi All in One SEO Pack plugin before 2.2.6 for WordPress does not consider the presence of password protection during generation of the Meta Description field, which allows remote attackers to obtain sensitive information by reading HTML source code.
0
Attacker Value
Unknown
CVE-2014-7123
Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Brevir Harian V2 (aka com.brevir.harian.v) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-6997
Disclosure Date: October 16, 2014 (last updated October 05, 2023)
The Dino Village (aka com.tappocket.dinovillage) application 1.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2013-3532
Disclosure Date: May 10, 2013 (last updated October 05, 2023)
SQL injection vulnerability in settings.php in the Web Dorado Spider Video Player plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the theme parameter.
0