Show filters
53 Total Results
Displaying 1-10 of 53
Sort by:
Attacker Value
Moderate

CVE-2020-11738

Disclosure Date: April 13, 2020 (last updated February 21, 2025)
The Snap Creek Duplicator plugin before 1.3.28 for WordPress (and Duplicator Pro before 3.8.7.1) allows Directory Traversal via ../ in the file parameter to duplicator_download or duplicator_init.
Attacker Value
Unknown

CVE-2024-50381

Disclosure Date: December 02, 2024 (last updated December 21, 2024)
A vulnerability exists in Snap One OVRC cloud where an attacker can impersonate a Hub device and send requests to claim and unclaim devices. The attacker only needs to provide the MAC address of the targeted device and can make a request to unclaim it from its original connection and make a request to claim it.
0
Attacker Value
Unknown

CVE-2024-50380

Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Snap One OVRC cloud uses the MAC address as an identifier to provide information when requested. An attacker can impersonate other devices by supplying enumerated MAC addresses and receive sensitive information about the device.
0
Attacker Value
Unknown

CVE-2024-7689

Disclosure Date: September 09, 2024 (last updated October 08, 2024)
The Snapshot Backup WordPress plugin through 2.1.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
Attacker Value
Unknown

CVE-2024-32805

Disclosure Date: June 09, 2024 (last updated June 10, 2024)
Missing Authorization vulnerability in Social Snap.This issue affects Social Snap: from n/a through 1.3.5.
0
Attacker Value
Unknown

CVE-2024-5436

Disclosure Date: May 31, 2024 (last updated May 31, 2024)
Type confusion in Snapchat LensCore could lead to denial of service or arbitrary code execution prior to version 12.88. We recommend upgrading to version 12.88 or above.
0
Attacker Value
Unknown

CVE-2018-25095

Disclosure Date: January 08, 2024 (last updated January 12, 2024)
The Duplicator WordPress plugin before 1.3.0 does not properly escape values when its installer script replaces values in WordPress configuration files. If this installer script is left on the site after use, it could be use to run arbitrary code on the server.
Attacker Value
Unknown

CVE-2023-43669

Disclosure Date: September 21, 2023 (last updated February 17, 2024)
The Tungstenite crate before 0.20.1 for Rust allows remote attackers to cause a denial of service (minutes of CPU consumption) via an excessive length of an HTTP header in a client handshake. The length affects both how many times a parse is attempted (e.g., thousands of times) and the average amount of data for each parse attempt (e.g., millions of bytes).
Attacker Value
Unknown

CVE-2023-25183

Disclosure Date: May 22, 2023 (last updated October 08, 2023)
In Snap One OvrC Pro versions prior to 7.2, when logged into the superuser account, a new functionality appears that could allow users to execute arbitrary commands on the hub device.
Attacker Value
Unknown

CVE-2023-31245

Disclosure Date: May 22, 2023 (last updated October 08, 2023)
Devices using Snap One OvrC cloud are sent to a web address when accessing a web management interface using a HTTP connection. Attackers could impersonate a device and supply malicious information about the device’s web server interface. By supplying malicious parameters, an attacker could redirect the user to arbitrary and dangerous locations on the web.