Show filters
22 Total Results
Displaying 1-10 of 22
Sort by:
Attacker Value
Unknown

CVE-2025-24692

Disclosure Date: February 14, 2025 (last updated February 15, 2025)
Missing Authorization vulnerability in Michael Revellin-Clerc Bulk Menu Edit allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bulk Menu Edit: from n/a through 1.3.
0
Attacker Value
Unknown

CVE-2025-25095

Disclosure Date: February 07, 2025 (last updated February 07, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in reverbnationdev ReverbNation Widgets allows Stored XSS. This issue affects ReverbNation Widgets: from n/a through 2.1.
0
Attacker Value
Unknown

CVE-2023-29080

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
Potential privilege escalation vulnerability in Revenera InstallShield versions 2022 R2 and 2021 R2 due to adding InstallScript custom action to a Basic MSI or InstallScript MSI project extracting few binaries to a predefined writable folder during installation time. The standard user account has write access to these files and folders, hence replacing them during installation time can lead to a DLL hijacking vulnerability.
0
Attacker Value
Unknown

CVE-2024-13206

Disclosure Date: January 09, 2025 (last updated January 09, 2025)
A vulnerability classified as critical has been found in REVE Antivirus 1.0.0.0 on Linux. This affects an unknown part of the file /usr/local/reveantivirus/tmp/reveinstall. The manipulation leads to incorrect default permissions. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown

CVE-2023-46631

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Missing Authorization vulnerability in RevenueHunt Product Recommendation Quiz for eCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Product Recommendation Quiz for eCommerce: from n/a through 2.1.2.
0
Attacker Value
Unknown

CVE-2022-46968

Disclosure Date: January 27, 2023 (last updated October 08, 2023)
A stored cross-site scripting (XSS) vulnerability in /index.php?page=help of Revenue Collection System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into sent messages.
Attacker Value
Unknown

CVE-2022-46967

Disclosure Date: January 26, 2023 (last updated October 08, 2023)
An access control issue in Revenue Collection System v1.0 allows unauthenticated attackers to view the contents of /admin/DBbackup/ directory.
Attacker Value
Unknown

CVE-2022-46966

Disclosure Date: January 26, 2023 (last updated October 08, 2023)
Revenue Collection System v1.0 was discovered to contain a SQL injection vulnerability at step1.php.
Attacker Value
Unknown

CVE-2022-4879

Disclosure Date: January 06, 2023 (last updated October 20, 2023)
A vulnerability was found in Forged Alliance Forever up to 3746. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Vote Handler. The manipulation leads to improper authorization. Upgrading to version 3747 is able to address this issue. The patch is named 6880971bd3d73d942384aff62d53058c206ce644. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-217555.
Attacker Value
Unknown

CVE-2020-36568

Disclosure Date: December 27, 2022 (last updated October 08, 2023)
Unsanitized input in the query parser in github.com/revel/revel before v1.0.0 allows remote attackers to cause resource exhaustion via memory allocation.