Show filters
21 Total Results
Displaying 1-10 of 21
Sort by:
Attacker Value
Unknown
CVE-2025-22799
Disclosure Date: January 15, 2025 (last updated January 16, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vertim Coders Neon Product Designer allows SQL Injection.This issue affects Neon Product Designer: from n/a through 2.1.1.
0
Attacker Value
Unknown
CVE-2023-5817
Disclosure Date: October 27, 2023 (last updated November 08, 2023)
The Neon text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's neontext_box shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes (color). This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2020-23576
Disclosure Date: August 27, 2020 (last updated February 22, 2025)
Laborator Neon dashboard v3 is affected by stored Cross Site Scripting (XSS) via the chat tab.
0
Attacker Value
Unknown
CVE-2020-13890
Disclosure Date: June 06, 2020 (last updated February 21, 2025)
The Neon theme 2.0 before 2020-06-03 for Bootstrap allows XSS via an Add Task Input operation in a dashboard.
0
Attacker Value
Unknown
CVE-2019-20141
Disclosure Date: December 30, 2019 (last updated November 27, 2024)
An XSS issue was discovered in the Laborator Neon theme 2.0 for WordPress via the data/autosuggest-remote.php q parameter.
0
Attacker Value
Unknown
CVE-2018-5258
Disclosure Date: January 17, 2018 (last updated November 26, 2024)
The Neon app 1.6.14 iOS does not verify X.509 certificates from SSL servers, which allows remote attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-7462
Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Fashion Story: Neon 90's (aka com.teamlava.fashionstory39) application 1.5.6.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2009-2473
Disclosure Date: August 21, 2009 (last updated October 04, 2023)
neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.
0
Attacker Value
Unknown
CVE-2009-2474
Disclosure Date: August 21, 2009 (last updated October 04, 2023)
neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
0
Attacker Value
Unknown
CVE-2008-3746
Disclosure Date: August 27, 2008 (last updated October 04, 2023)
neon 0.28.0 through 0.28.2 allows remote servers to cause a denial of service (NULL pointer dereference and crash) via vectors related to Digest authentication, Digest domain parameter support, and the parse_domain function.
0