Show filters
203 Total Results
Displaying 91-100 of 203
Sort by:
Attacker Value
Unknown

CVE-2021-33649

Disclosure Date: June 27, 2022 (last updated February 24, 2025)
When performing the inference shape operation of the Transpose operator, if the value in the perm element is greater than or equal to the size of the input_shape, it will access data outside of bounds of input_shape which allocated from heap buffers.
Attacker Value
Unknown

CVE-2021-33648

Disclosure Date: June 27, 2022 (last updated February 24, 2025)
When performing the inference shape operation of Affine, Concat, MatMul, ArgMinMax, EmbeddingLookup, and Gather operators, if the input shape size is 0, it will access data outside of bounds of shape which allocated from heap buffers.
Attacker Value
Unknown

CVE-2021-33647

Disclosure Date: June 27, 2022 (last updated February 24, 2025)
When performing the inference shape operation of the Tile operator, if the input data type is not int or int32, it will access data outside of bounds of heap allocated buffers.
Attacker Value
Unknown

CVE-2022-1758

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The Genki Pre-Publish Reminder WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored XSS as well as RCE when custom code is added via the plugin settings.
Attacker Value
Unknown

CVE-2022-29806

Disclosure Date: April 26, 2022 (last updated February 23, 2025)
ZoneMinder before 1.36.13 allows remote code execution via an invalid language. Ability to create a debug log file at an arbitrary pathname contributes to exploitability.
Attacker Value
Unknown

CVE-2021-46086

Disclosure Date: January 25, 2022 (last updated February 23, 2025)
xzs-mysql >= t3.4.0 is vulnerable to Insecure Permissions. The front end of this open source system is an online examination system. There is an unsafe vulnerability in the functional method of submitting examination papers. An attacker can use burpuite to modify parameters in the packet to destroy real data.
Attacker Value
Unknown

CVE-2021-24713

Disclosure Date: November 23, 2021 (last updated February 23, 2025)
The Video Lessons Manager WordPress plugin before 1.7.2 and Video Lessons Manager Pro WordPress plugin before 3.5.9 do not properly sanitize and escape values when updating their settings, which could allow high privilege users to perform Cross-Site Scripting attacks
Attacker Value
Unknown

CVE-2021-24678

Disclosure Date: October 04, 2021 (last updated February 23, 2025)
The CM Tooltip Glossary WordPress plugin before 3.9.21 does not escape some glossary_tooltip shortcode attributes, which could allow users a role as low as Contributor to perform Stored Cross-Site Scripting attacks
Attacker Value
Unknown

CVE-2020-24146

Disclosure Date: July 07, 2021 (last updated February 23, 2025)
Directory traversal in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows authorized users to delete arbitrary files and possibly cause a denial of service via the fileName parameter in a deletescreenshot action.
Attacker Value
Unknown

CVE-2020-24145

Disclosure Date: July 07, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability in the CM Download Manager (aka cm-download-manager) plugin 2.7.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via a crafted deletescreenshot action.