Show filters
118 Total Results
Displaying 1-10 of 118
Sort by:
Attacker Value
Unknown
CVE-2024-12559
Disclosure Date: January 07, 2025 (last updated January 07, 2025)
The ClickDesigns plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'clickdesigns_add_api' and the 'clickdesigns_remove_api' functions in all versions up to, and including, 1.8.0. This makes it possible for unauthenticated attackers to modify or remove the plugin's API key.
0
Attacker Value
Unknown
CVE-2024-10510
Disclosure Date: November 28, 2024 (last updated December 21, 2024)
The adBuddy+ (AdBlocker Detection) by NetfunkDesign WordPress plugin through 1.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
0
Attacker Value
Unknown
CVE-2020-26164
Disclosure Date: October 07, 2020 (last updated February 22, 2025)
In kdeconnect-kde (aka KDE Connect) before 20.08.2, an attacker on the local network could send crafted packets that trigger use of large amounts of CPU, memory, or network connection slots, aka a Denial of Service attack.
0
Attacker Value
Unknown
CVE-2018-19516
Disclosure Date: March 12, 2020 (last updated February 21, 2025)
messagepartthemes/default/defaultrenderer.cpp in messagelib in KDE Applications before 18.12.0 does not properly restrict the handling of an http-equiv="REFRESH" value.
0
Attacker Value
Unknown
CVE-2012-4512
Disclosure Date: February 08, 2020 (last updated February 21, 2025)
The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion."
0
Attacker Value
Unknown
CVE-2014-9211
Disclosure Date: January 14, 2020 (last updated February 21, 2025)
ClickDesk version 4.3 and below has persistent cross site scripting
0
Attacker Value
Unknown
CVE-2013-4133
Disclosure Date: December 10, 2019 (last updated November 27, 2024)
kde-workspace before 4.10.5 has a memory leak in plasma desktop
0
Attacker Value
Unknown
CVE-2018-19120
Disclosure Date: November 29, 2018 (last updated November 08, 2023)
The HTML thumbnailer plugin in KDE Applications before 18.12.0 allows attackers to trigger outbound TCP connections to arbitrary IP addresses, leading to disclosure of the source IP address.
0
Attacker Value
Unknown
CVE-2015-7543
Disclosure Date: July 25, 2017 (last updated November 26, 2024)
aRts 1.5.10 and kdelibs3 3.5.10 and earlier do not properly create temporary directories, which allows local users to hijack the IPC by pre-creating the temporary directory.
0
Attacker Value
Unknown
CVE-2017-8422
Disclosure Date: May 17, 2017 (last updated November 26, 2024)
KDE kdelibs before 4.14.32 and KAuth before 5.34 allow local users to gain root privileges by spoofing a callerID and leveraging a privileged helper app.
0