Show filters
30 Total Results
Displaying 1-10 of 30
Sort by:
Attacker Value
Unknown
CVE-2025-26604
Disclosure Date: February 18, 2025 (last updated February 19, 2025)
Discord-Bot-Framework-Kernel is a Discord bot framework built with interactions.py, featuring modular extension management and secure execution. Because of the nature of arbitrary user-submited code execution, this allows user to execute potentially malicious code to perform damage or extract sensitive information. By loading the module containing the following code and run the command, the bot token can be extracted. Then the attacker can load a blocking module to sabotage the bot (DDoS attack) and the token can be used to make the fake bot act as the real one. If the bot has very high privilege, the attacker basically has full control before the user kicks the bot. Any Discord user that hosts Discord-Bot-Framework-Kernel before commit f0d9e70841a0e3170b88c4f8d562018ccd8e8b14 is affected. Users are advised to upgrade. Users unable to upgrade may attempt to limit their discord bot's access via configuration options.
0
Attacker Value
Unknown
CVE-2023-2675
Disclosure Date: November 07, 2023 (last updated November 14, 2023)
Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 2023.Q1.1223.
0
Attacker Value
Unknown
CVE-2023-1665
Disclosure Date: March 27, 2023 (last updated October 08, 2023)
Improper Restriction of Excessive Authentication Attempts in GitHub repository linagora/twake prior to 0.0.0.
0
Attacker Value
Unknown
CVE-2023-0028
Disclosure Date: January 01, 2023 (last updated November 01, 2023)
Cross-site Scripting (XSS) - Stored in GitHub repository linagora/twake prior to 2023.Q1.1200+.
0
Attacker Value
Unknown
CVE-2020-25605
Disclosure Date: February 17, 2021 (last updated February 22, 2025)
Cleartext transmission of sensitive information in Agora Video SDK prior to 3.1 allows a remote attacker to obtain access to audio and video of any ongoing Agora video call through observation of cleartext network traffic.
0
Attacker Value
Unknown
CVE-2019-1010205
Disclosure Date: July 23, 2019 (last updated November 27, 2024)
LINAGORA hublin latest (commit 72ead897082403126bf8df9264e70f0a9de247ff) is affected by: Directory Traversal. The impact is: The vulnerability allows an attacker to access any file (with a fixed extension) on the server. The component is: A web-view renderer; details here: https://lgtm.com/projects/g/linagora/hublin/snapshot/af9f1ce253b4ee923ff8da8f9d908d02a8e95b7f/files/backend/webserver/views.js?sort=name&dir=ASC&mode=heatmap&showExcluded=false#xb24eb0101d2aec21:1. The attack vector is: Attacker sends a specially crafted HTTP request.
0
Attacker Value
Unknown
CVE-2017-6560
Disclosure Date: March 09, 2017 (last updated November 26, 2024)
XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=misc&action=[XSS]&editObjId=[XSS] attack.
0
Attacker Value
Unknown
CVE-2017-6562
Disclosure Date: March 09, 2017 (last updated November 26, 2024)
XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=file&targetObjId=fileFolder-2&targetObjIdChild=[XSS] attack.
0
Attacker Value
Unknown
CVE-2017-6559
Disclosure Date: March 09, 2017 (last updated November 26, 2024)
XSS in Agora-Project 3.2.2 exists with an index.php?disconnect=1&msgNotif[]=[XSS] attack.
0
Attacker Value
Unknown
CVE-2017-6561
Disclosure Date: March 09, 2017 (last updated November 26, 2024)
XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=object&action=[XSS] attack.
0