Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown

CVE-2023-40582

Disclosure Date: August 30, 2023 (last updated October 08, 2023)
find-exec is a utility to discover available shell commands. Versions prior to 1.0.3 did not properly escape user input and are vulnerable to Command Injection via an attacker controlled parameter. As a result, attackers may run malicious shell commands in the context of the running process. This issue has been addressed in version 1.0.3. users are advised to upgrade. Users unable to upgrade should ensure that all input passed to find-exec comes from a trusted source.
Attacker Value
Unknown

CVE-2015-10065

Disclosure Date: January 17, 2023 (last updated February 24, 2025)
A vulnerability classified as critical was found in AenBleidd FiND. This vulnerability affects the function init_result of the file validator/my_validator.cpp. The manipulation leads to buffer overflow. The patch is identified as ee2eef34a83644f286c9adcaf30437f92e9c48f1. It is recommended to apply a patch to fix this issue. VDB-218458 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-3850

Disclosure Date: November 28, 2022 (last updated October 08, 2023)
The Find and Replace All WordPress plugin before 1.3 does not have CSRF check when replacing string, which could allow attackers to make a logged admin replace arbitrary string in database tables via a CSRF attack
Attacker Value
Unknown

CVE-2022-2311

Disclosure Date: November 28, 2022 (last updated October 08, 2023)
The Find and Replace All WordPress plugin before 1.3 does not sanitize and escape some parameters from its setting page before outputting them back to the user, leading to a Reflected Cross-Site Scripting issue.
Attacker Value
Unknown

CVE-2021-24677

Disclosure Date: October 18, 2021 (last updated February 23, 2025)
The Find My Blocks WordPress plugin before 3.4.0 does not have authorisation checks in its REST API, which could allow unauthenticated users to enumerate private posts' titles.
Attacker Value
Unknown

CVE-2020-22122

Disclosure Date: August 18, 2021 (last updated February 23, 2025)
A SQL injection vulnerability in /oa.php?c=Staff&a=read of Find a Place LJCMS v 1.3 allows attackers to access sensitive database information via a crafted POST request.
Attacker Value
Unknown

CVE-2020-7764

Disclosure Date: November 08, 2020 (last updated February 22, 2025)
This affects the package find-my-way before 2.2.5, from 3.0.0 and before 3.0.5. It accepts the Accept-Version' header by default, and if versioned routes are not being used, this could lead to a denial of service. Accept-Version can be used as an unkeyed header in a cache poisoning attack.
Attacker Value
Unknown

CVE-2015-7878

Disclosure Date: November 06, 2017 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in the Taxonomy Find module 6.x-2.x through 6.x-1.2 and 7.x-2.x through 7.x-1.0 in Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via taxonomy vocabulary and term names.
0
Attacker Value
Unknown

CVE-2014-7023

Disclosure Date: October 16, 2014 (last updated October 05, 2023)
The Find Color (aka com.chudong.color) application 1.1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0