π¨ CVE-2023-2271
The Tiempo.com WordPress plugin through 0.1.2 does not have CSRF check when deleting its shortcode, which could allow attackers to make logged in admins delete arbitrary shortcode via a CSRF attack
π@cveNotify
The Tiempo.com WordPress plugin through 0.1.2 does not have CSRF check when deleting its shortcode, which could allow attackers to make logged in admins delete arbitrary shortcode via a CSRF attack
π@cveNotify
WPScan
Tiempo.com <= 0.1.2 - Shortcode Deletion via CSRF
See details on the Tiempo.com <= 0.1.2 - Shortcode Deletion via CSRF. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2023-2254
The Ko-fi Button WordPress plugin before 1.3.3 does not properly some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup), and we consider it a low risk.
π@cveNotify
The Ko-fi Button WordPress plugin before 1.3.3 does not properly some of its settings, which could allow high-privilege users to perform Stored Cross-Site Scripting (XSS) attacks even when the unfiltered_html capability is disallowed (for example in multisite setup), and we consider it a low risk.
π@cveNotify
WPScan
Ko-fi Button < 1.3.3 - Admin+ Stored XSS
See details on the Ko-fi Button < 1.3.3 - Admin+ Stored XSS. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2023-2225
The SEO ALert WordPress plugin through 1.59 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
π@cveNotify
The SEO ALert WordPress plugin through 1.59 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
π@cveNotify
WPScan
SEO ALert <= 1.59 - Admin+ Stored XSS
See details on the SEO ALert <= 1.59 - Admin+ Stored XSS. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2023-2123
The WP Inventory Manager WordPress plugin before 2.1.0.13 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.
π@cveNotify
The WP Inventory Manager WordPress plugin before 2.1.0.13 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting.
π@cveNotify
WPScan
WP Inventory Manager < 2.1.0.13 - Reflected Cross-Site Scripting
See details on the WP Inventory Manager < 2.1.0.13 - Reflected Cross-Site Scripting. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2023-2122
The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitise and escape the iowd_tabs_active parameter before rendering it in the plugin admin panel, leading to a reflected Cross-Site Scripting vulnerability, allowing an attacker to trick a logged in admin to execute arbitrary javascript by clicking a link.
π@cveNotify
The Image Optimizer by 10web WordPress plugin before 1.0.27 does not sanitise and escape the iowd_tabs_active parameter before rendering it in the plugin admin panel, leading to a reflected Cross-Site Scripting vulnerability, allowing an attacker to trick a logged in admin to execute arbitrary javascript by clicking a link.
π@cveNotify
WPScan
Image Optimizer by 10web < 1.0.27 - Reflected Cross-Site Scripting
See details on the Image Optimizer by 10web < 1.0.27 - Reflected Cross-Site Scripting. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2023-1977
The Booking Manager WordPress plugin before 2.0.29 does not validate URLs input in it's admin panel or in shortcodes for showing events from a remote .ics file, allowing an attacker with privileges as low as Subscriber to perform SSRF attacks on the sites internal network.
π@cveNotify
The Booking Manager WordPress plugin before 2.0.29 does not validate URLs input in it's admin panel or in shortcodes for showing events from a remote .ics file, allowing an attacker with privileges as low as Subscriber to perform SSRF attacks on the sites internal network.
π@cveNotify
WPScan
Booking Manager < 2.0.29 - Subscriber+ SSRF
See details on Booking Manager < 2.0.29 - Subscriber+ SSRF CVE 2023-1977. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2023-22957
An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of hard-coded cryptographic key, an attacker with access to backup or configuration files is able to decrypt encrypted values and retrieve sensitive information, e.g., the device root password.
π@cveNotify
An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of hard-coded cryptographic key, an attacker with access to backup or configuration files is able to decrypt encrypted values and retrieve sensitive information, e.g., the device root password.
π@cveNotify
SySS GmbH
SySS GmbH - The Pentest Experts
IT Security Anbieter β Schwachstellen erkennen | IT-Sicherheit prΓΌfen | Systeme absichern | Risiken nachhaltig minimieren | Schutz gezielt verbessern | Syss
π¨ CVE-2023-0551
The REST API TO MiniProgram WordPress plugin through 4.6.1 does not have authorisation and CSRF checks in an AJAX action, allowing ay authenticated users, such as subscriber to call and delete arbitrary attachments
π@cveNotify
The REST API TO MiniProgram WordPress plugin through 4.6.1 does not have authorisation and CSRF checks in an AJAX action, allowing ay authenticated users, such as subscriber to call and delete arbitrary attachments
π@cveNotify
WPScan
REST API TO MiniProgram <= 4.6.8.1 - Subscriber+ Attachment Deletion
See details on the REST API TO MiniProgram <= 4.6.8.1 - Subscriber+ Attachment Deletion. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2022-4782
The ClickFunnels WordPress plugin through 3.1.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
π@cveNotify
The ClickFunnels WordPress plugin through 3.1.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
π@cveNotify
WPScan
ClickFunnels <= 3.1.1 - Contributor+ Stored XSS via Shortcode
See details on the ClickFunnels <= 3.1.1 - Contributor+ Stored XSS via Shortcode. View the latest Plugin Vulnerabilities on WPScan.
π¨ CVE-2023-4241
lol-html can cause panics on certain HTML inputs. Anyone processing arbitrary 3rd party HTML with the library is affected.
π@cveNotify
lol-html can cause panics on certain HTML inputs. Anyone processing arbitrary 3rd party HTML with the library is affected.
π@cveNotify
GitHub
lol-html panics on certain HTML inputs
### Impact
lol-html can cause panics on certain HTML inputs. Anyone processing arbitrary 3rd party HTML with the library is affected.
### Patches
The problem has been patched and released as v...
lol-html can cause panics on certain HTML inputs. Anyone processing arbitrary 3rd party HTML with the library is affected.
### Patches
The problem has been patched and released as v...
π¨ CVE-2020-26652
An issue was discovered in function nl80211_send_chandef in rtl8812au v5.6.4.2 allows attackers to cause a denial of service.
π@cveNotify
An issue was discovered in function nl80211_send_chandef in rtl8812au v5.6.4.2 allows attackers to cause a denial of service.
π@cveNotify
GitHub
fuzzing wifi ,network will down, result is net/wireless/nl80211.c:3159 nl80211_send_chandef+0x14b/0x160 [cfg80211] Β· Issue #730β¦
testing environment root@kali:~# uname -r 5.6.0-kali2-amd64 poc: ` #!/usr/bin/env python #coding=utf-8 import time import socket AP_MAC = "00:22:66:88:22:00" STA_MAC = "00:13:ef:f1:0...
π¨ CVE-2021-32420
dpic 2021.01.01 has a Heap-based Buffer Overflow in thestorestring function in dpic.y.
π@cveNotify
dpic 2021.01.01 has a Heap-based Buffer Overflow in thestorestring function in dpic.y.
π@cveNotify
GitLab
Improved robustness to fuzzed input (d317e406) Β· Commits Β· Dwight Aplevich / dpic Β· GitLab
An implementation of the pic "little language," with support for LaTeX, PDF, SVG, Postscript, and xfig 3.2 output.
π¨ CVE-2020-25887
Buffer overflow in mg_resolve_from_hosts_file in Mongoose 6.18, when reading from a crafted hosts file.
π@cveNotify
Buffer overflow in mg_resolve_from_hosts_file in Mongoose 6.18, when reading from a crafted hosts file.
π@cveNotify
GitHub
Buffer overflow in mg_resolve_from_hosts_file function Β· Issue #1140 Β· cesanta/mongoose
Buffer overflow in mg_resolve_from_hosts_file function (line 124) in mongoose/src/mg_resolv.c in Mongoose 6.18, where sscanf copies data from p to alias without limiting the size of the copied data...
π¨ CVE-2020-24294
Buffer Overflow vulnerability in psdParser::UnpackRLE function in PSDParser.cpp in FreeImage 3.19.0 [r1859] allows remote attackers to cuase a denial of service via opening of crafted psd file.
π@cveNotify
Buffer Overflow vulnerability in psdParser::UnpackRLE function in PSDParser.cpp in FreeImage 3.19.0 [r1859] allows remote attackers to cuase a denial of service via opening of crafted psd file.
π@cveNotify
π¨ CVE-2020-23793
An issue was discovered in spice-server spice-server-0.14.0-6.el7_6.1.x86_64 of Redhat's VDI product. There is a security vulnerablility that can restart KVMvirtual machine without any authorization. It is not yet known if there will be other other effects.
π@cveNotify
An issue was discovered in spice-server spice-server-0.14.0-6.el7_6.1.x86_64 of Redhat's VDI product. There is a security vulnerablility that can restart KVMvirtual machine without any authorization. It is not yet known if there will be other other effects.
π@cveNotify
GitHub
GitHub - zelat/spice-security-issues
Contribute to zelat/spice-security-issues development by creating an account on GitHub.
π¨ CVE-2020-22181
A reflected cross site scripting (XSS) vulnerability was discovered on Samsung sww-3400rw Router devices via the m2 parameter of the sess-bin/command.cgi
π@cveNotify
A reflected cross site scripting (XSS) vulnerability was discovered on Samsung sww-3400rw Router devices via the m2 parameter of the sess-bin/command.cgi
π@cveNotify
π¨ CVE-2020-21724
Buffer Overflow vulnerability in ExtractorInformation function in streamExtractor.cpp in oggvideotools 0.9.1 allows remaote attackers to run arbitrary code via opening of crafted ogg file.
π@cveNotify
Buffer Overflow vulnerability in ExtractorInformation function in streamExtractor.cpp in oggvideotools 0.9.1 allows remaote attackers to run arbitrary code via opening of crafted ogg file.
π@cveNotify
π¨ CVE-2020-22524
Buffer Overflow vulnerability in FreeImage_Load function in FreeImage Library 3.19.0(r1828) allows attackers to cuase a denial of service via crafted PFM file.
π@cveNotify
Buffer Overflow vulnerability in FreeImage_Load function in FreeImage Library 3.19.0(r1828) allows attackers to cuase a denial of service via crafted PFM file.
π@cveNotify
π¨ CVE-2020-21699
The web server Tengine 2.2.2 developed in the Nginx version from 0.5.6 thru 1.13.2 is vulnerable to an integer overflow vulnerability in the nginx range filter module, resulting in the leakage of potentially sensitive information triggered by specially crafted requests.
π@cveNotify
The web server Tengine 2.2.2 developed in the Nginx version from 0.5.6 thru 1.13.2 is vulnerable to an integer overflow vulnerability in the nginx range filter module, resulting in the leakage of potentially sensitive information triggered by specially crafted requests.
π@cveNotify
GitHub
Nginx-variants/ιδ»Ά(Tengine).docx at master Β· ZxDecide/Nginx-variants
Here is a variant of Nginx web server that has been tried - ZxDecide/Nginx-variants
π¨ CVE-2020-22217
Buffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via function ares_parse_soa_reply in ares_parse_soa_reply.c.
π@cveNotify
Buffer overflow vulnerability in c-ares before 1_16_1 thru 1_17_0 via function ares_parse_soa_reply in ares_parse_soa_reply.c.
π@cveNotify
GitHub
read-heap-buffer-overflow in ares_parse_soa_reply() Β· Issue #333 Β· c-ares/c-ares
we found read-heap-buffer-overflow by fuzzing c-ares master-branch lenth unchecked before read aptr
π¨ CVE-2020-21686
A stack-use-after-scope issue discovered in expand_mmac_params function in preproc.c in nasm before 2.15.04 allows remote attackers to cause a denial of service via crafted asm file.
π@cveNotify
A stack-use-after-scope issue discovered in expand_mmac_params function in preproc.c in nasm before 2.15.04 allows remote attackers to cause a denial of service via crafted asm file.
π@cveNotify