Show filters
251 Total Results
Displaying 91-100 of 251
Sort by:
Attacker Value
Unknown

CVE-2020-23966

Disclosure Date: May 08, 2023 (last updated February 24, 2025)
SQL Injection vulnerability in victor cms 1.0 allows attackers to execute arbitrary commands via the post parameter to /post.php in a crafted GET request.
Attacker Value
Unknown

CVE-2023-27105

Disclosure Date: April 25, 2023 (last updated February 24, 2025)
A vulnerability in the Wi-Fi file transfer module of Shanling M5S Portable Music Player with Shanling MTouch OS v4.3 and Shanling M2X Portable Music Player with Shanling MTouch OS v3.3 allows attackers to arbitrarily read, delete, or modify any critical system files via directory traversal.
Attacker Value
Unknown

CVE-2022-44735

Disclosure Date: April 18, 2023 (last updated February 24, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Gus Sevilla WP Clictracker plugin <= 1.0.5 versions.
Attacker Value
Unknown

CVE-2023-26071

Disclosure Date: March 28, 2023 (last updated February 24, 2025)
An issue was discovered in MCUBO ICT through 10.12.4 (aka 6.0.2). An Observable Response Discrepancy can occur under the login web page. In particular, the web application provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor. That allow an unauthorized actor to perform User Enumeration attacks.
Attacker Value
Unknown

CVE-2022-3091

Disclosure Date: January 17, 2023 (last updated February 24, 2025)
RONDS EPM version 1.19.5 has a vulnerability in which a function could allow unauthenticated users to leak credentials. In some circumstances, an attacker can exploit this vulnerability to execute operating system (OS) commands.
Attacker Value
Unknown

CVE-2022-2893

Disclosure Date: January 17, 2023 (last updated February 24, 2025)
RONDS EPM version 1.19.5 does not properly validate the filename parameter, which could allow an unauthorized user to specify file paths and download files.  
Attacker Value
Unknown

CVE-2015-10055

Disclosure Date: January 16, 2023 (last updated February 24, 2025)
A vulnerability was found in PictureThisWebServer and classified as critical. This issue affects the function router.post of the file routes/user.js. The manipulation of the argument username/password leads to sql injection. The patch is named 68b9dc346e88b494df00d88c7d058e96820e1479. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218399.
Attacker Value
Unknown

CVE-2022-4890

Disclosure Date: January 16, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as critical, has been found in abhilash1985 PredictApp. This issue affects some unknown processing of the file config/initializers/new_framework_defaults_7_0.rb of the component Cookie Handler. The manipulation leads to deserialization. The attack may be initiated remotely. The patch is named b067372f3ee26fe1b657121f0f41883ff4461a06. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218387.
Attacker Value
Unknown

CVE-2022-1613

Disclosure Date: September 26, 2022 (last updated February 24, 2025)
The Restricted Site Access WordPress plugin before 7.3.2 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations in certain situations.
Attacker Value
Unknown

CVE-2022-40809

Disclosure Date: September 19, 2022 (last updated February 24, 2025)
The d8s-dicts for python, as distributed on PyPI, included a potential code-execution backdoor inserted by a third party. The backdoor is the democritus-hypothesis package. The affected version is 0.1.0