Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2023-40582
Disclosure Date: August 30, 2023 (last updated October 08, 2023)
find-exec is a utility to discover available shell commands. Versions prior to 1.0.3 did not properly escape user input and are vulnerable to Command Injection via an attacker controlled parameter. As a result, attackers may run malicious shell commands in the context of the running process. This issue has been addressed in version 1.0.3. users are advised to upgrade. Users unable to upgrade should ensure that all input passed to find-exec comes from a trusted source.
0
Attacker Value
Unknown
CVE-2015-10065
Disclosure Date: January 17, 2023 (last updated February 24, 2025)
A vulnerability classified as critical was found in AenBleidd FiND. This vulnerability affects the function init_result of the file validator/my_validator.cpp. The manipulation leads to buffer overflow. The patch is identified as ee2eef34a83644f286c9adcaf30437f92e9c48f1. It is recommended to apply a patch to fix this issue. VDB-218458 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2022-3850
Disclosure Date: November 28, 2022 (last updated October 08, 2023)
The Find and Replace All WordPress plugin before 1.3 does not have CSRF check when replacing string, which could allow attackers to make a logged admin replace arbitrary string in database tables via a CSRF attack
0
Attacker Value
Unknown
CVE-2022-2311
Disclosure Date: November 28, 2022 (last updated October 08, 2023)
The Find and Replace All WordPress plugin before 1.3 does not sanitize and escape some parameters from its setting page before outputting them back to the user, leading to a Reflected Cross-Site Scripting issue.
0
Attacker Value
Unknown
CVE-2021-24677
Disclosure Date: October 18, 2021 (last updated February 23, 2025)
The Find My Blocks WordPress plugin before 3.4.0 does not have authorisation checks in its REST API, which could allow unauthenticated users to enumerate private posts' titles.
0
Attacker Value
Unknown
CVE-2020-22122
Disclosure Date: August 18, 2021 (last updated February 23, 2025)
A SQL injection vulnerability in /oa.php?c=Staff&a=read of Find a Place LJCMS v 1.3 allows attackers to access sensitive database information via a crafted POST request.
0
Attacker Value
Unknown
CVE-2020-7764
Disclosure Date: November 08, 2020 (last updated February 22, 2025)
This affects the package find-my-way before 2.2.5, from 3.0.0 and before 3.0.5. It accepts the Accept-Version' header by default, and if versioned routes are not being used, this could lead to a denial of service. Accept-Version can be used as an unkeyed header in a cache poisoning attack.
0
Attacker Value
Unknown
CVE-2015-7878
Disclosure Date: November 06, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in the Taxonomy Find module 6.x-2.x through 6.x-1.2 and 7.x-2.x through 7.x-1.0 in Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via taxonomy vocabulary and term names.
0
Attacker Value
Unknown
CVE-2014-7023
Disclosure Date: October 16, 2014 (last updated October 05, 2023)
The Find Color (aka com.chudong.color) application 1.1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0