Show filters
25 Total Results
Displaying 1-10 of 25
Sort by:
Attacker Value
Unknown
CVE-2024-9108
Disclosure Date: October 01, 2024 (last updated January 05, 2025)
The Wechat Social login plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'convert_remoteimage_to_local' function in versions up to, and including, 1.3.0. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
0
Attacker Value
Unknown
CVE-2024-9106
Disclosure Date: October 01, 2024 (last updated January 05, 2025)
The Wechat Social login plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 1.3.0. This is due to insufficient verification on the user being supplied during the social login. This makes it possible for unauthenticated attackers to log in as any existing user on the site, such as an administrator, if they have access to the user id. This is only exploitable if the app secret is not set, so it has a default empty value.
0
Attacker Value
Unknown
CVE-2024-1324
Disclosure Date: June 01, 2024 (last updated January 05, 2025)
The QQWorld Auto Save Images plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the save_remote_images_get_auto_saved_results() function hooked via a norpriv AJAX in all versions up to, and including, 1.9.8. This makes it possible for unauthenticated attackers to retrieve the contents of arbitrary posts that may not be public.
0
Attacker Value
Unknown
CVE-2023-34312
Disclosure Date: June 01, 2023 (last updated October 08, 2023)
In Tencent QQ through 9.7.8.29039 and TIM through 3.4.7.22084, QQProtect.exe and QQProtectEngine.dll do not validate pointers from inter-process communication, which leads to a write-what-where condition.
0
Attacker Value
Unknown
CVE-2020-21119
Disclosure Date: February 15, 2023 (last updated October 08, 2023)
SQL Injection vulnerability in Kliqqi-CMS 2.0.2 in admin/admin_update_module_widgets.php in recordIDValue parameter, allows attackers to gain escalated privileges and execute arbitrary code.
0
Attacker Value
Unknown
CVE-2021-3942
Disclosure Date: December 12, 2022 (last updated October 08, 2023)
Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer overflow with use of Link-Local Multicast Name Resolution or LLMNR.
0
Attacker Value
Unknown
CVE-2022-28721
Disclosure Date: September 26, 2022 (last updated October 08, 2023)
Certain HP Print Products are potentially vulnerable to Remote Code Execution.
0
Attacker Value
Unknown
CVE-2021-33057
Disclosure Date: July 26, 2022 (last updated October 07, 2023)
The QQ application 8.7.1 for Android and iOS does not enforce the permission requirements (e.g., android.permission.ACCESS_FINE_LOCATION) for determining the device's physical location. An attacker can use qq.createMapContext to create a MapContext object, use MapContext.moveToLocation to move the center of the map to the device's location, and use MapContext.getCenterLocation to get the latitude and longitude of the current map center.
0
Attacker Value
Unknown
CVE-2020-21121
Disclosure Date: September 15, 2021 (last updated February 23, 2025)
Pligg CMS 2.0.2 contains a time-based SQL injection vulnerability via the $recordIDValue parameter in the admin_update_module_widgets.php file.
0
Attacker Value
Unknown
CVE-2020-10551
Disclosure Date: April 09, 2020 (last updated February 21, 2025)
QQBrowser before 10.5.3870.400 installs a Windows service TsService.exe. This file is writable by anyone belonging to the NT AUTHORITY\Authenticated Users group, which includes all local and remote users. This can be abused by local attackers to escalate privileges to NT AUTHORITY\SYSTEM by writing a malicious executable to the location of TsService.
0