Unknown · CVSS Not scored
Playground Sessions v2.5.582 (and earlier) for Windows, stores the user credentials in plain text allowing anyone with access to UserProfiles.sol to extract the email and password.
Published Nov 23, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The Canto plugin 1.3.0 for WordPress allows includes/lib/download.php?subdomain= SSRF.
Published Nov 10, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
NeDi 1.9C allows pwsec.php oid XSS.
Published Nov 2, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
pdf2json v0.71 was discovered to contain a NULL pointer dereference in the component ObjectStream::getObject.
Published Nov 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A User Mode Write AV in Editor+0x5ea2 of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tga file.
Published Nov 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A User Mode Write AV in ntdll!RtlpCoalesceFreeBlocks+0x268 of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tiff file.
Published Nov 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A User Mode Write AV in Editor+0x76af of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tiff file.
Published Nov 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A buffer overflow in Nomacs v3.15.0 allows attackers to cause a denial of service (DoS) via a crafted MNG file.
Published Nov 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection vulnerability in eyoucms cms v1.4.7, allows attackers to execute arbitrary code and disclose sensitive information, via the tid parameter to index.php.
Published Nov 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
pdf2xml v2.0 was discovered to contain a memory leak in the function TextPage::testLinkedText.
Published Nov 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A User Mode Write AV starting at Editor!TMethodImplementationIntercept+0x4189c6 of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted ico file.
Published Nov 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A User Mode Write AV in Editor+0x5f91 of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tga file.
Published Nov 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A buffer overflow in WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tga file. Related to Data from Faulting Address controls Code Flow starting at Editor!TMethodImplementationIntercept+0x57a3b.
Published Nov 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A User Mode Write AV in Editor+0x5cd7 of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tiff file.
Published Nov 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A buffer overflow in WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tga file. Related to Data from Faulting Address may be used as a return value starting at Editor!TMethodImplementationIntercept+0x528a3.
Published Nov 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
XnView MP v0.96.4 was discovered to contain a heap overflow which allows attackers to cause a denial of service (DoS) via a crafted pict file. Related to a User Mode Write AV starting at ntdll!RtlpLowFragHeapFree.
Published Nov 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
XnView MP v0.96.4 was discovered to contain a heap overflow which allows attackers to cause a denial of service (DoS) via a crafted ico file. Related to a Read Access Violation starting at USER32!SmartStretchDIBits+0x33.
Published Nov 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A User Mode Write AV in Editor!TMethodImplementationIntercept+0x54dcec of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tga file.
Published Nov 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
pdf2xml v2.0 was discovered to contain a heap-buffer overflow in the function TextPage::dump.
Published Nov 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
pdf2json v0.71 was discovered to contain a stack buffer overflow in the component XRef::fetch.
Published Nov 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A NULL pointer dereference in the function TextPage::restoreState of pdf2xml v2.0 allows attackers to cause a denial of service (DoS).
Published Nov 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A buffer overflow in WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted JPG file. Related to Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at JPGCodec+0x753648.
Published Nov 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
pdf2xml v2.0 was discovered to contain a heap-buffer overflow in the function TextPage::addAttributsNode.
Published Nov 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
FFmpeg N-98388-g76a3ee996b allows attackers to cause a denial of service (DoS) via a crafted audio file due to insufficient verification of data authenticity.
Published Nov 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A User Mode Write AV in Editor!TMethodImplementationIntercept+0x3c3682 of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tiff file.
Published Nov 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A stack buffer overflow in speexenc.c of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file. NOTE: the vendor states "I cannot reproduce it" and it "is a demo program.
Published Nov 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A Divide by Zero vulnerability in the function static int read_samples of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file.
Published Nov 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A User Mode Write AV in Editor!TMethodImplementationIntercept+0x53f6c3 of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted psd file.
Published Nov 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
NeDi 1.9C allows inc/rt-popup.php d XSS.
Published Nov 2, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
pdf2xml v2.0 was discovered to contain a stack buffer overflow in the component getObjectStream.
Published Nov 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A User Mode Write AV in Editor+0x576b of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tiff file.
Published Nov 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A User Mode Write AV in Editor+0x5d15 of WildBit Viewer v6.6 allows attackers to cause a denial of service (DoS) via a crafted tga file.
Published Nov 10, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) vulnerability in infusions/member_poll_panel/poll_admin.php in PHP-Fusion 9.03.50, allows attackers to execute arbitrary code, via the polls feature.
Published Nov 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross site scripting (XSS) vulnerability in xujinliang zibbs 1.0, allows attackers to execute arbitrary code via the route parameter to index.php.
Published Nov 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in function StartPage in text2pdf.c in pdfcorner text2pdf 1.1, allows attackers to cause denial of service or possibly other undisclosed impacts.
Published Nov 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross site scripting (XSS) vulnerability in application/controllers/AdminController.php in xujinliang zibbs 1.0, allows attackers to execute arbitrary code via the bbsmeta parameter.
Published Nov 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
SQL Injection vulnerability in 188Jianzhan v2.1.0, allows attackers to execute arbitrary code and gain escalated privileges, via the username parameter to login.php.
Published Nov 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Buffer overflow vulnerability in Renleilei1992 Linux_Network_Project 1.0, allows attackers to execute arbitrary code, via the password field.
Published Nov 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross site request forgery (CSRF) vulnerability in AyaCMS 3.1.2 allows attackers to change an administrators password or other unspecified impacts.
Published Nov 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A command injection vulnerability exists in Moxa Inc VPort 461 Series Firmware Version 3.4 or lower that could allow a remote attacker to execute arbitrary commands in Moxa's VPort 461 Series Industrial Video Servers.
Published Nov 2, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Irfanview v4.53 allows attackers to to cause a denial of service (DoS) via a crafted JPEG 2000 file. Related to "Integer Divide By Zero starting at JPEG2000!ShowPlugInSaveOptions_W+0x00000000000082ea"
Published Nov 5, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
There was a local file disclosure vulnerability in AVideo < 8.9 via the proxy streaming. An unauthenticated attacker can exploit this issue to read an arbitrary file on the server. Which could leak database credentials or other sensitive information such as /etc/passwd file.
Published Nov 16, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Irfanview v4.53 allows attackers to execute arbitrary code via a crafted JPEG 2000 file. Related to a "Data from Faulting Address controls Branch Selection starting at JPEG2000!ShowPlugInSaveOptions_W+0x0000000000032850".
Published Nov 5, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The import.json.php file before 8.9 for Avideo is vulnerable to a File Deletion vulnerability. This allows the deletion of configuration.php, which leads to certain privilege checks not being in place, and therefore a user can escalate privileges to admin.
Published Nov 16, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Irfanview v4.53 was discovered to contain an infinity loop via JPEG2000!ShowPlugInSaveOptions_W+0x1ecd8.
Published Nov 5, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
BEESCMS v4.0 was discovered to contain an arbitrary file upload vulnerability via the component /admin/upload.php. This vulnerability allows attackers to execute arbitrary code via a crafted image file.
Published Nov 8, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An unrestricted file upload vulnerability was discovered in the Microweber 1.1.18 admin account page. An attacker can upload PHP code or any extension (eg- .exe) to the web server by providing image data and the image/jpeg content type with a .php extension.
Published Nov 9, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Buffer overflow vulnerability in function convert_colorspace in heif_colorconversion.cc in libheif v1.6.2, allows attackers to cause a denial of service and disclose sensitive information, via a crafted HEIF file.
Published Nov 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Chamilo LMS version 1.11.10 contains an XSS vulnerability in the personal profile edition form, affecting the user him/herself and social network friends.
Published Nov 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Microweber 1.1.18 is affected by insufficient session expiration. When changing passwords, both sessions for when a user changes email and old sessions in any other browser or device, the session does not expire and remains active.
Published Nov 9, 2020 · Updated Aug 4, 2024