Unknown · CVSS Not scored
Microweber 1.1.18 is affected by broken authentication and session management. Local session hijacking may occur, which could result in unauthorized access to system data or functionality, or a complete system compromise.
Published Nov 9, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
A cross-site scripting (XSS) vulnerability in Beijing Liangjing Zhicheng Technology Co., Ltd ljcmsshop version 1.14 allows remote attackers to inject arbitrary web script or HTML via user.php by registering an account directly in the user center, and then adding the payload to the delivery address.
Published Nov 18, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Shimo Document v2.0.1 contains a cross-site scripting (XSS) vulnerability which allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the table content text field.
Published Nov 22, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Neoflex Video Subscription System Version 2.0 is affected by CSRF which allows the Website's Settings to be changed (such as Payment Settings)
Published Nov 4, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
WeForms Wordpress Plugin 1.4.7 allows CSV injection via a form's entry.
Published Nov 4, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
phpMyAdmin through 5.0.2 allows CSV injection via Export Section. NOTE: the vendor disputes this because "the CSV file is accurately generated based on the database contents.
Published Nov 4, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Easy Registration Forms (ER Forms) Wordpress Plugin 2.0.6 allows an attacker to submit an entry with malicious CSV commands. After that, when the system administrator generates CSV output from the forms information, there is no check on this inputs and the codes are executable.
Published Nov 4, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the pjActionLoadCss function.
Published Nov 5, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Import and export users and customers WordPress Plugin through 1.15.5.11 allows CSV injection via a customer's profile.
Published Nov 4, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoadForm function.
Published Nov 5, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoad function.
Published Nov 5, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionSetAmount function.
Published Nov 5, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
JomSocial (Joomla Social Network Extention) 4.7.6 allows CSV injection via a customer's profile.
Published Nov 4, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In YzmCMS v5.5 the member contribution function in the editor contains a cross-site scripting (XSS) vulnerability.
Published Nov 19, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the pjActionPreview function.
Published Nov 5, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In fastadmin V1.0.0.20191212_beta, when a user with administrator rights has logged in, a malicious parameter can be passed for SQL injection in URL /admin/ajax/weigh.
Published Nov 17, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Ruijie RG-UAC 6000-E50 commit 9071227 was discovered to contain a cross-site scripting (XSS) vulnerability via the rule_name parameter. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
Published Nov 16, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Ruijie RG-UAC commit 9071227 was discovered to contain a vulnerability in the component /current_action.php?action=reboot, which allows attackers to cause a denial of service (DoS) via unspecified vectors.
Published Nov 16, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discoverered in in abhijitnathwani image-processing v0.1.0, allows local attackers to cause a denial of service via a crafted image file.
Published Nov 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Buffer overflow vulnerability in function src_parser_trans_stage_1_2_3 trgil gilcc before commit 803969389ca9c06237075a7f8eeb1a19e6651759, allows attackers to cause a denial of service.
Published Nov 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In fastadmin-tp6 v1.0, in the file app/admin/controller/Ajax.php the 'table' parameter passed is not filtered so a malicious parameter can be passed for SQL injection.
Published Nov 13, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Buffer overflow vulnerability in YotsuyaNight c-http v0.1.0, allows attackers to cause a denial of service via a long url request which is passed to the delimitedread function.
Published Nov 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
iCMS v7.0.15 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admincp.php?app=members&do=add.
Published Nov 12, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
EC Cloud E-Commerce System v1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) which allows attackers to arbitrarily add admin accounts via /admin.html?do=user&act=add.
Published Nov 4, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
PDFResurrect before 0.20 lack of header validation checks causes heap-buffer-overflow in pdf_get_version().
Published Nov 20, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross Site Scripting (XSS) vulnerability in shadoweb wdja v1.5.1, allows attackers to execute arbitrary code and gain escalated privileges, via the backurl parameter to /php/passport/index.php.
Published Nov 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Buffer overflow vulnerability in fcovatti libiec_iccp_mod v1.5, allows attackers to cause a denail of service when trying to calloc an unexpectiedly large space.
Published Nov 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Buffer overflow vulnerability in fcovatti libiec_iccp_mod v1.5, allows attackers to cause a denial of service via an unexpected packet while trying to connect.
Published Nov 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of remote server path or stack address.
Published Nov 20, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Unverified indexs into the array lead to out of bound access in the gif_out_code function in fromgif.c in libsixel 1.8.6.
Published Nov 20, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Stack-based buffer overflow and unconditional jump in ReadXPMImage in coders/xpm.c in ImageMagick 7.0.10-7.
Published Nov 20, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discoverered in in function edit_save_f in framework/admin/tpl_control.php in qinggan phpok 5.1, allows attackers to write arbitrary files or get a shell.
Published Nov 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Buffer overflow vulnerability in framework/init.php in qinggan phpok 5.1, allows attackers to execute arbitrary code.
Published Nov 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
PHP-CMS v1.0 was discovered to contain a SQL injection vulnerability in the component search.php via the search parameter. This vulnerability allows attackers to access sensitive database information.
Published Nov 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ED01-CMS v1.0 was discovered to contain a SQL injection in the component cposts.php via the cid parameter.
Published Nov 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An arbitrary file upload vulnerability in the image upload function of ED01-CMS v1.0 allows attackers to execute arbitrary commands.
Published Nov 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in qinggan phpok 5.1, allows attackers to disclose sensitive information, via the title parameter to admin.php.
Published Nov 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
ED01-CMS v1.0 was discovered to contain a reflective cross-site scripting (XSS) vulnerability in the component sposts.php. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload inserted into the Post title or Post content fields.
Published Nov 3, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user.
Published Nov 30, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Apache Shiro before 1.7.0, when using Apache Shiro with Spring, a specially crafted HTTP request may cause an authentication bypass.
Published Nov 5, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The TLS module within SaltStack Salt through 3002 creates certificates with weak file permissions.
Published Nov 6, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Untangle Firewall NG before 16.0 uses MD5 for passwords.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered on Canon MF237w 06.07 devices. An "Improper Handling of Length Parameter Inconsistency" issue in the IPv4/ICMPv4 component, when handling a packet sent by an unauthenticated network attacker, may expose Sensitive Information.
Published Nov 30, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Mitsubishi MELSEC iQ-R Series PLCs with firmware 49 allow an unauthenticated attacker to halt the industrial process by sending a crafted packet over the network. This denial of service attack exposes Improper Input Validation. After halting, physical access to the PLC is required in order to restore production, and the device state is lost. This is related to R04CPU, RJ71GF11-T2, R04CPU, and RJ71GF11-T2.
Published Nov 30, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
In Arm software implementing the Armv8-M processors (all versions), the stack selection mechanism could be influenced by a stack-underflow attack in v8-M TrustZone based processors. An attacker can cause a change to the stack pointer used by the Secure World from a non-secure application if the stack is not initialized. This vulnerability affects only the software that is based on Armv8-M processors with the Security Extension.
Published Nov 12, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this code into a log file and then traverse to that file.
Published Nov 14, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Out of bounds read in ANGLE allowed a remote attacker to obtain sensitive data via a crafted HTML page.
Published Nov 2, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Use after free in autofill in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published Nov 3, 2020 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 86.0.4240.75 allowed a local attacker to bypass navigation restrictions via crafted Intents.
Published Nov 3, 2020 · Updated Aug 4, 2024