Show filters
331 Total Results
Displaying 1-10 of 331
Sort by:
Attacker Value
Unknown
CVE-2024-8475
Disclosure Date: December 17, 2024 (last updated December 18, 2024)
Authentication Bypass by Assumed-Immutable Data vulnerability in Digital Operation Services WiFiBurada allows Manipulating User-Controlled Variables.This issue affects WiFiBurada: before 1.0.5.
0
Attacker Value
Unknown
CVE-2024-8429
Disclosure Date: December 17, 2024 (last updated December 18, 2024)
Improper Restriction of Excessive Authentication Attempts vulnerability in Digital Operation Services WiFiBurada allows Use of Known Domain Credentials.This issue affects WiFiBurada: before 1.0.5.
0
Attacker Value
Unknown
CVE-2023-32126
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in WPoperation SALERT allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SALERT: from n/a through 1.2.1.
0
Attacker Value
Unknown
CVE-2024-24803
Disclosure Date: February 10, 2024 (last updated February 17, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPoperation Ultra Companion – Companion plugin for WPoperation Themes allows Stored XSS.This issue affects Ultra Companion – Companion plugin for WPoperation Themes: from n/a through 1.1.9.
0
Attacker Value
Unknown
CVE-2023-32118
Disclosure Date: June 12, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPoperation SALERT – Fake Sales Notification WooCommerce plugin <= 1.2.1 versions.
0
Attacker Value
Unknown
CVE-2018-16135
Disclosure Date: December 26, 2022 (last updated October 08, 2023)
The Opera Mini application 47.1.2249.129326 for Android allows remote attackers to spoof the Location Permission dialog via a crafted web site.
0
Attacker Value
Unknown
CVE-2021-20851
Disclosure Date: December 01, 2021 (last updated October 07, 2023)
Cross-site request forgery (CSRF) vulnerability in Browser and Operating System Finder versions prior to 1.2 allows a remote unauthenticated attacker to hijack the authentication of an administrator via unspecified vectors.
0
Attacker Value
Unknown
CVE-2021-23253
Disclosure Date: January 11, 2021 (last updated November 28, 2024)
Opera Mini for Android below 53.1 displays URL left-aligned in the address field. This allows a malicious attacker to craft a URL with a long domain name, e.g. www.safe.opera.com.attacker.com. With the URL being left-aligned, the user will only see the front part (e.g. www.safe.opera.com…) The exact amount depends on the phone screen size but the attacker can craft a number of different domains and target different phones. Starting with version 53.1 Opera Mini displays long URLs with the top-level domain label aligned to the right of the address field which mitigates the issue.
0
Attacker Value
Unknown
CVE-2020-6159
Disclosure Date: December 23, 2020 (last updated November 28, 2024)
URLs using “javascript:” have the protocol removed when pasted into the address bar to protect users from cross-site scripting (XSS) attacks, but in certain circumstances this removal was not performed. This could allow users to be socially engineered to run an XSS attack against themselves. This vulnerability affects Opera for Android versions below 61.0.3076.56532.
0
Attacker Value
Unknown
CVE-2020-6157
Disclosure Date: November 13, 2020 (last updated November 28, 2024)
Opera Touch for iOS before version 2.4.5 is vulnerable to an address bar spoofing attack. The vulnerability allows a malicious page to trick the browser into showing an address of a different page. This may allow the malicious page to impersonate another page and trick a user into providing sensitive data.
0