Show filters
22 Total Results
Displaying 1-10 of 22
Sort by:
Attacker Value
Unknown
CVE-2024-53747
Disclosure Date: December 01, 2024 (last updated February 27, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NuttTaro Video Player for WPBakery allows Stored XSS.This issue affects Video Player for WPBakery: from n/a through 1.0.1.
0
Attacker Value
Unknown
CVE-2021-45414
Disclosure Date: February 28, 2022 (last updated October 07, 2023)
A Remote Code Execution (RCE) vulnerability exists in DataRobot through 2021-10-28 because it allows submission of a Docker environment or Java driver.
0
Attacker Value
Unknown
CVE-2021-3804
Disclosure Date: September 17, 2021 (last updated February 23, 2025)
taro is vulnerable to Inefficient Regular Expression Complexity
0
Attacker Value
Unknown
CVE-2017-9432
Disclosure Date: June 05, 2017 (last updated November 26, 2024)
Document Liberation Project libstaroffice before 2017-04-07 has an out-of-bounds write caused by a stack-based buffer overflow related to the DatabaseName::read function in lib/StarWriterStruct.cxx.
0
Attacker Value
Unknown
CVE-2014-6834
Disclosure Date: September 30, 2014 (last updated October 05, 2023)
The Instaroid - Instagram Viewer (aka net.muik.instaroid) application 1.2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2012-3238
Disclosure Date: July 09, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the Backup/Restore component in WebAdmin in Astaro Security Gateway before 8.305 allows remote attackers to inject arbitrary web script or HTML via the "Comment (optional)" field.
0
Attacker Value
Unknown
CVE-2009-1054
Disclosure Date: March 24, 2009 (last updated October 04, 2023)
Unspecified vulnerability in JustSystems Ichitaro 13, 2004 through 2008, Lite2, and Ichitaro viewer 5.1.5.0 and earlier allows remote attackers to execute arbitrary code via a crafted file, as exploited in the wild by Trojan.Tarodrop.H in March 2009.
0
Attacker Value
Unknown
CVE-2008-4487
Disclosure Date: October 08, 2008 (last updated October 04, 2023)
SQL injection vulnerability in ap-save.php in Atarone CMS 1.2.0 allows remote attackers to execute arbitrary SQL commands via the (1) site_name, (2) email, (3) theme_chosen, (4) hp, (5) c_meta, (6) id, and (7) c_js parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2008-4489
Disclosure Date: October 08, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in ap-save.php in Atarone CMS 1.2.0 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the theme_chosen parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2008-4488
Disclosure Date: October 08, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in ap-pages.php in Atarone CMS 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the (1) name and (2) id parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0