Show filters
36 Total Results
Displaying 1-10 of 36
Sort by:
Attacker Value
Unknown
CVE-2024-11082
Disclosure Date: November 28, 2024 (last updated December 21, 2024)
The Tumult Hype Animations plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the hypeanimations_panel() function in all versions up to, and including, 1.9.15. This makes it possible for authenticated attackers, with Author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
0
Attacker Value
Unknown
CVE-2017-20125
Disclosure Date: June 30, 2022 (last updated February 24, 2025)
A vulnerability classified as critical was found in Online Hotel Booking System Pro 1.2. Affected by this vulnerability is an unknown functionality of the file /roomtype-details.php. The manipulation of the argument tid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2017-20124
Disclosure Date: June 30, 2022 (last updated February 24, 2025)
A vulnerability classified as critical has been found in Online Hotel Booking System Pro Plugin 1.0. Affected is an unknown function of the file /front/roomtype-details.php. The manipulation of the argument tid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
0
Attacker Value
Unknown
CVE-2020-15535
Disclosure Date: July 05, 2020 (last updated February 21, 2025)
An issue was discovered in the bestsoftinc Car Rental System plugin through 1.3 for WordPress. Persistent XSS can occur via any of the registration fields.
0
Attacker Value
Unknown
CVE-2018-16737
Disclosure Date: October 10, 2018 (last updated November 08, 2023)
tinc before 1.0.30 has a broken authentication protocol, without even a partial mitigation.
0
Attacker Value
Unknown
CVE-2018-16738
Disclosure Date: October 10, 2018 (last updated November 08, 2023)
tinc 1.0.30 through 1.0.34 has a broken authentication protocol, although there is a partial mitigation. This is fixed in 1.1.
0
Attacker Value
Unknown
CVE-2018-16758
Disclosure Date: October 10, 2018 (last updated November 08, 2023)
Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryption of VPN packets.
0
Attacker Value
Unknown
DistinctDev, Inc., The Moron Test, 6.3.1, 2017-05-04, iOS application uses a ha…
Disclosure Date: August 15, 2018 (last updated November 27, 2024)
DistinctDev, Inc., The Moron Test, 6.3.1, 2017-05-04, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.
0
Attacker Value
Unknown
CVE-2014-4035
Disclosure Date: June 11, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in booking_details.php in Best Soft Inc. (BSI) Advance Hotel Booking System 2.0 allows remote attackers to inject arbitrary web script or HTML via the title parameter.
0
Attacker Value
Unknown
CVE-2013-1428
Disclosure Date: April 26, 2013 (last updated October 05, 2023)
Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc before 1.0.21 and 1.1 before 1.1pre7 allows remote authenticated peers to cause a denial of service (crash) or possibly execute arbitrary code via a large TCP packet.
0