Show filters
154 Total Results
Displaying 91-100 of 154
Sort by:
Attacker Value
Unknown

CVE-2020-11835

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/charger_ic/oppo_da9313.c, failure to check the parameter buf in the function proc_work_mode_write in proc_work_mode_write causes a vulnerability.
Attacker Value
Unknown

CVE-2020-11834

Disclosure Date: December 31, 2020 (last updated February 22, 2025)
In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/oppo_vooc.c, the function proc_fastchg_fw_update_write in proc_fastchg_fw_update_write does not check the parameter len, resulting in a vulnerability.
Attacker Value
Unknown

CVE-2020-7764

Disclosure Date: November 08, 2020 (last updated February 22, 2025)
This affects the package find-my-way before 2.2.5, from 3.0.0 and before 3.0.5. It accepts the Accept-Version' header by default, and if versioned routes are not being used, this could lead to a denial of service. Accept-Version can be used as an unkeyed header in a cache poisoning attack.
Attacker Value
Unknown

CVE-2020-2317

Disclosure Date: November 04, 2020 (last updated February 22, 2025)
Jenkins FindBugs Plugin 5.0.0 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide report files to Jenkins FindBugs Plugin's post build step.
Attacker Value
Unknown

CVE-2019-16252

Disclosure Date: June 12, 2020 (last updated February 21, 2025)
Missing SSL Certificate Validation in the Nutfind.com application through 3.9.12 for Android allows a man-in-the-middle attacker to sniff and manipulate all API requests, including login credentials and location data.
Attacker Value
Unknown

CVE-2020-13641

Disclosure Date: May 28, 2020 (last updated February 21, 2025)
An issue was discovered in the Real-Time Find and Replace plugin before 4.0.2 for WordPress. The far_options_page function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The find and replace rules could be updated with malicious JavaScript, allowing for that be executed later in the victims browser.
Attacker Value
Unknown

CVE-2020-2178

Disclosure Date: April 16, 2020 (last updated February 21, 2025)
Jenkins Parasoft Findings Plugin 10.4.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Attacker Value
Unknown

CVE-2019-15862

Disclosure Date: September 26, 2019 (last updated November 27, 2024)
An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file names allows remote attackers to upload files without any extension (even if the application was configured to accept files only with a defined set of extensions). This affects CKFinder for ASP, CKFinder for ASP.NET, CKFinder for ColdFusion, and CKFinder for PHP.
Attacker Value
Unknown

CVE-2019-15891

Disclosure Date: September 26, 2019 (last updated November 27, 2024)
An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0. The documentation has misleading information that could lead to a conclusion that the application has a built-in bulletproof content sniffing protection.
Attacker Value
Unknown

CVE-2016-10955

Disclosure Date: September 13, 2019 (last updated November 27, 2024)
The cysteme-finder plugin before 1.4 for WordPress has unrestricted file upload because of incorrect session tracking.