Show filters
26 Total Results
Displaying 1-10 of 26
Sort by:
Attacker Value
Unknown

CVE-2024-9064

Disclosure Date: October 10, 2024 (last updated February 26, 2025)
The Elementor Inline SVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
Attacker Value
Unknown

CVE-2023-41011

Disclosure Date: September 14, 2023 (last updated February 25, 2025)
Command Execution vulnerability in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the shortcut_telnet.cg component.
Attacker Value
Unknown

CVE-2023-41012

Disclosure Date: September 05, 2023 (last updated February 25, 2025)
An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the authentication mechanism.
Attacker Value
Unknown

CVE-2023-26986

Disclosure Date: April 10, 2023 (last updated October 08, 2023)
An issue in China Mobile OA Mailbox PC v2.9.23 allows remote attackers to execute arbitrary commands on a victim host via user interaction with a crafted EML file sent to their OA mailbox.
Attacker Value
Unknown

CVE-2020-18331

Disclosure Date: January 26, 2023 (last updated February 24, 2025)
Directory traversal vulnerability in ChinaMobile PLC Wireless Router model GPN2.4P21-C-CN running the firmware version W2000EN-01(hardware platform Gpn2.4P21-C_WIFI-V0.05), via the getpage parameter to /cgi-bin/webproc.
Attacker Value
Unknown

CVE-2020-18330

Disclosure Date: January 26, 2023 (last updated February 24, 2025)
An issue was discovered in the default configuration of ChinaMobile PLC Wireless Router model GPN2.4P21-C-CN running the firmware version W2000EN-01(hardware platform Gpn2.4P21-C_WIFI-V0.05), allows attackers to gain access to the configuration interface.
Attacker Value
Unknown

CVE-2021-33965

Disclosure Date: January 18, 2022 (last updated February 23, 2025)
China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRMesh/set_ZRMesh which receives parameters by POST request, and the parameter mesh_enable and mesh_device have a command injection vulnerability. An attacker can use the vulnerability to execute remote commands.
Attacker Value
Unknown

CVE-2021-33964

Disclosure Date: January 18, 2022 (last updated February 23, 2025)
China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRRuleFilter/set_firewall_level which receives parameters by POST request, and the parameter firewall_level has a command injection vulnerability. An attacker can use the vulnerability to execute remote commands.
Attacker Value
Unknown

CVE-2021-33963

Disclosure Date: January 15, 2022 (last updated February 23, 2025)
China Mobile An Lianbao WF-1 v1.0.1 router web interface through /api/ZRMacClone/mac_addr_clone receives parameters by POST request, and the parameter macType has a command injection vulnerability. An attacker can use the vulnerability to execute remote commands.
Attacker Value
Unknown

CVE-2021-33962

Disclosure Date: January 14, 2022 (last updated February 23, 2025)
China Mobile An Lianbao WF-1 router v1.0.1 is affected by an OS command injection vulnerability in the web interface /api/ZRUsb/pop_usb_device component.