Show filters
251 Total Results
Displaying 91-100 of 251
Sort by:
Attacker Value
Unknown
CVE-2020-23966
Disclosure Date: May 08, 2023 (last updated February 24, 2025)
SQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the post parameter to /post.php in a crafted GET request.
0
Attacker Value
Unknown
CVE-2023-27105
Disclosure Date: April 25, 2023 (last updated February 24, 2025)
A vulnerability in the Wi-Fi file transfer module of Shanling M5S Portable Music Player with Shanling MTouch OS v4.3 and Shanling M2X Portable Music Player with Shanling MTouch OS v3.3 allows attackers to arbitrarily read, delete, or modify any critical system files via directory traversal.
0
Attacker Value
Unknown
CVE-2022-44735
Disclosure Date: April 18, 2023 (last updated February 24, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gus Sevilla WP Clictracker plugin <= 1.0.5 versions.
0
Attacker Value
Unknown
CVE-2023-26071
Disclosure Date: March 28, 2023 (last updated February 24, 2025)
An issue was discovered in MCUBO ICT through 10.12.4 (aka 6.0.2). An Observable Response Discrepancy can occur under the login web page. In particular, the web application provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor. That allow an unauthorized actor to perform User Enumeration attacks.
0
Attacker Value
Unknown
CVE-2022-3091
Disclosure Date: January 17, 2023 (last updated February 24, 2025)
RONDS EPM version 1.19.5 has a vulnerability in which a function could
allow unauthenticated users to leak credentials. In some circumstances,
an attacker can exploit this vulnerability to execute operating system
(OS) commands.
0
Attacker Value
Unknown
CVE-2022-2893
Disclosure Date: January 17, 2023 (last updated February 24, 2025)
RONDS EPM version 1.19.5 does not properly validate the filename
parameter, which could allow an unauthorized user to specify file paths
and download files.
0
Attacker Value
Unknown
CVE-2015-10055
Disclosure Date: January 16, 2023 (last updated February 24, 2025)
A vulnerability was found in PictureThisWebServer and classified as critical. This issue affects the function router.post of the file routes/user.js. The manipulation of the argument username/password leads to sql injection. The patch is named 68b9dc346e88b494df00d88c7d058e96820e1479. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218399.
0
Attacker Value
Unknown
CVE-2022-4890
Disclosure Date: January 16, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as critical, has been found in abhilash1985 PredictApp. This issue affects some unknown processing of the file config/initializers/new_framework_defaults_7_0.rb of the component Cookie Handler. The manipulation leads to deserialization. The attack may be initiated remotely. The patch is named b067372f3ee26fe1b657121f0f41883ff4461a06. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218387.
0
Attacker Value
Unknown
CVE-2022-1613
Disclosure Date: September 26, 2022 (last updated February 24, 2025)
The Restricted Site Access WordPress plugin before 7.3.2 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations in certain situations.
0
Attacker Value
Unknown
CVE-2022-40809
Disclosure Date: September 19, 2022 (last updated February 24, 2025)
The d8s-dicts for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0
0