Show filters
543 Total Results
Displaying 91-100 of 543
Sort by:
Attacker Value
Unknown

CVE-2020-5557

Disclosure Date: March 25, 2020 (last updated February 21, 2025)
Cross-site scripting vulnerability in CuteNews 2.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Attacker Value
Unknown

CVE-2020-10257

Disclosure Date: March 10, 2020 (last updated February 21, 2025)
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
Attacker Value
Unknown

CVE-2015-7342

Disclosure Date: March 09, 2020 (last updated February 21, 2025)
JNews Joomla Component before 8.5.0 allows SQL injection via upload thumbnail, Queue Search Field, Subscribers Search Field, or Newsletters Search Field.
Attacker Value
Unknown

CVE-2015-7341

Disclosure Date: March 09, 2020 (last updated February 21, 2025)
JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .php5 extension.
Attacker Value
Unknown

CVE-2015-7343

Disclosure Date: March 09, 2020 (last updated February 21, 2025)
JNews Joomla Component before 8.5.0 has XSS via the mailingsearch parameter.
Attacker Value
Unknown

CVE-2011-2706

Disclosure Date: January 14, 2020 (last updated February 21, 2025)
A Cross-Site Scripting (XSS) vulnerability exists in the reorder administrator functions in sNews 1.71.
Attacker Value
Unknown

CVE-2012-2724

Disclosure Date: January 09, 2020 (last updated February 21, 2025)
The Simplenews module 6.x-1.x before 6.x-1.4, 6.x-2.x before 6.x-2.0-alpha4, and 7.x-1.x before 7.x-1.0-rc1 for Drupal reveals the email addresses of new mailing list subscribers when confirmation is required, which allows remote attackers to obtain sensitive information via the confirmation page.
Attacker Value
Unknown

CVE-2019-6032

Disclosure Date: December 26, 2019 (last updated November 27, 2024)
The NTV News24 prior to Ver.3.0.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Attacker Value
Unknown

CVE-2015-9504

Disclosure Date: October 23, 2019 (last updated November 27, 2024)
The weeklynews theme before 2.2.9 for WordPress has XSS via the s parameter.
Attacker Value
Unknown

CVE-2016-10999

Disclosure Date: September 20, 2019 (last updated November 27, 2024)
The Goodnews theme through 2016-02-28 for WordPress has XSS via the s parameter.