Show filters
145 Total Results
Displaying 91-100 of 145
Sort by:
Attacker Value
Unknown
CVE-2023-24552
Disclosure Date: February 14, 2023 (last updated February 15, 2024)
A vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The affected application contains an out of bounds read past the end of an allocated buffer while parsing a specially crafted PAR file. This could allow an attacker to to execute code in the context of the current process.
0
Attacker Value
Unknown
CVE-2022-3091
Disclosure Date: January 17, 2023 (last updated November 08, 2023)
RONDS EPM version 1.19.5 has a vulnerability in which a function could
allow unauthenticated users to leak credentials. In some circumstances,
an attacker can exploit this vulnerability to execute operating system
(OS) commands.
0
Attacker Value
Unknown
CVE-2022-2893
Disclosure Date: January 17, 2023 (last updated November 08, 2023)
RONDS EPM version 1.19.5 does not properly validate the filename
parameter, which could allow an unauthorized user to specify file paths
and download files.
0
Attacker Value
Unknown
CVE-2023-0295
Disclosure Date: January 13, 2023 (last updated October 08, 2023)
The Launchpad plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its settings parameters in versions up to, and including, 1.0.13 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
0
Attacker Value
Unknown
CVE-2022-1576
Disclosure Date: July 11, 2022 (last updated February 24, 2025)
The WP Maintenance Mode & Coming Soon WordPress plugin before 2.4.5 is lacking CSRF when emptying the subscribed users list, which could allow attackers to make a logged in admin perform such action via a CSRF attack
0
Attacker Value
Unknown
CVE-2022-30536
Disclosure Date: June 28, 2022 (last updated February 24, 2025)
Authenticated Stored Cross-Site Scripting (XSS) vulnerability in Florent Maillefaud's WP Maintenance plugin <= 6.0.7 at WordPress.
0
Attacker Value
Unknown
CVE-2022-1945
Disclosure Date: June 20, 2022 (last updated February 23, 2025)
The Coming Soon & Maintenance Mode by Colorlib WordPress plugin before 1.0.99 does not sanitize and escape some settings, allowing high privilege users such as admin to perform Stored Cross-Site Scripting when unfiltered_html is disallowed (for example in multisite setup)
0
Attacker Value
Unknown
CVE-2021-36828
Disclosure Date: April 15, 2022 (last updated February 23, 2025)
Authenticated (admin+) Stored Cross-Site Scripting (XSS) in WP Maintenance plugin <= 6.0.7 versions.
0
Attacker Value
Unknown
CVE-2022-0601
Disclosure Date: March 14, 2022 (last updated February 23, 2025)
The Countdown, Coming Soon, Maintenance WordPress plugin before 2.2.9 does not sanitize and escape the post parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting.
0
Attacker Value
Unknown
CVE-2022-0199
Disclosure Date: February 21, 2022 (last updated February 23, 2025)
The Coming soon and Maintenance mode WordPress plugin before 3.6.8 does not have CSRF check in its coming_soon_send_mail AJAX action, allowing attackers to make logged in admin to send arbitrary emails to all subscribed users via a CSRF attack
0