Vulnerabilities
45 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-46494 | A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into Name A cross-site scripting (XSS) vulnerability in Typecho v1.2.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into Name parameter under a comment for an Article. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2024-57369 | Clickjacking vulnerability in typecho v1.2.1. Clickjacking vulnerability in typecho v1.2.1. NVD description · AI analysis pending | 6.4 | <1% |
| — | ||
| CVE-2024-42495 +1 in the same advisory: …39278 | Credentials to access device configuration were transmitted using an unencrypted protocol. Credentials to access device configuration were transmitted using an unencrypted protocol. These credentials would allow read-only access to network configuration information and terminal configuration data. NVD description · AI analysis pending | 7.1 group max | <1% |
| — | ||
| CVE-2024-35540 | A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. NVD description · AI analysis pending | 9.0 | 3% | PoC |
| — | |
| CVE-2024-35539 +1 in the same advisory: …35538 | Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerability allows attackers to post several comments before the spam protection checks if the comments are posted too frequently. NVD description · AI analysis pending | 6.5 group max | 1% | PoC |
| — | |
| CVE-2023-6615 | A vulnerability, which was classified as problematic, has been found in Typecho 1.2.1. A vulnerability, which was classified as problematic, has been found in Typecho 1.2.1. Affected by this issue is some unknown functionality of the file /admin/manage-users.php. The manipulation of the argument page leads to information disclosure. The exploit has been disclosed to the public and may be used. VDB-247250 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 5.3 group max | <1% | PoC |
| — | |
| CVE-2023-49967 | Typecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xmlrpc. Typecho v1.2.1 was discovered to be vulnerable to an XML Quadratic Blowup attack via the component /index.php/action/xmlrpc. NVD description · AI analysis pending | 7.5 | <1% | PoC |
| — | |
| CVE-2023-38817 | An issue in Inspect Element Ltd Echo.ac v.5.2.1.0 allows a local attacker to gain privileges via a crafted command to the echo_driver.sys component. An issue in Inspect Element Ltd Echo.ac v.5.2.1.0 allows a local attacker to gain privileges via a crafted command to the echo_driver.sys component. NOTE: the vendor's position is that the reported ability for user-mode applications to execute code as NT AUTHORITY\SYSTEM was "deactivated by Microsoft itself." NVD description · AI analysis pending | 7.8 | <1% | PoC |
| — | |
| CVE-2023-36299 | A File Upload vulnerability in typecho v.1.2.1 allows a remote attacker to execute arbitrary code via the upload and options-general parameters in index.php. A File Upload vulnerability in typecho v.1.2.1 allows a remote attacker to execute arbitrary code via the upload and options-general parameters in index.php. NVD description · AI analysis pending | 8.8 | 2% | PoC |
| — | |
| CVE-2020-21038 | Open redirect vulnerability in typecho 1.1-17.10.30-release via the referer parameter to Login.php. Open redirect vulnerability in typecho 1.1-17.10.30-release via the referer parameter to Login.php. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2023-30184 | A stored cross-site scripting (XSS) vulnerability in Typecho v1.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected int A stored cross-site scripting (XSS) vulnerability in Typecho v1.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the url parameter at /index.php/archives/1/comment. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2023-27711 | Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via the Comment Manager /admin/manage-comments.ph Cross Site Scripting vulnerability found in Typecho v.1.2.0 allows a remote attacker to execute arbitrary code via the Comment Manager /admin/manage-comments.php component. NVD description · AI analysis pending | 4.8 | <1% | PoC ×2 |
| — | |
| CVE-2023-24114 | typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php. typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php. NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2021-4124 | janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2021-4020 | janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2021-33578 | Echo ShareCare 8.15.5 is susceptible to SQL injection vulnerabilities when processing remote input from both authenticated and unauthenticated users, leading to Echo ShareCare 8.15.5 is susceptible to SQL injection vulnerabilities when processing remote input from both authenticated and unauthenticated users, leading to the ability to bypass authentication, exfiltrate Structured Query Language (SQL) records, and manipulate data. NVD description · AI analysis pending | 9.8 group max | 1% |
| — | ||
| CVE-2021-29061 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Vfsjfilechooser2 version 0.2.9 and below which occurs when the application attemp A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Vfsjfilechooser2 version 0.2.9 and below which occurs when the application attempts to validate crafted URIs. NVD description · AI analysis pending | 7.5 | 2% | PoC ×3 |
| — | |
| CVE-2020-14034 +1 in the same advisory: …14033 | An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_get_codec_from_pt in utils.c has a Buffer Overflow via long value in an SDP Offer packet. NVD description · AI analysis pending | 9.8 | 2% |
| — | ||
| CVE-2020-13901 | An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. An issue was discovered in janus-gateway (aka Janus WebRTC Server) through 0.10.0. janus_sdp_merge in sdp.c has a stack-based buffer overflow. NVD description · AI analysis pending | 9.8 group max | 3% | PoC |
| — | |
| CVE-2020-10574 | An issue was discovered in Janus through 0.9.1. An issue was discovered in Janus through 0.9.1. janus.c tries to use a string that doesn't actually exist during a "query_logger" Admin API request, because of a typo in the JSON validation. NVD description · AI analysis pending | 9.8 group max | 1% |
| — | ||
| CVE-2018-18753 | Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF. Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF. NVD description · AI analysis pending | 9.8 | 3% | PoC |
| — | |
| CVE-2018-13832 | Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plugin 4.6 for WordPress allow remote attac Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plugin 4.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via Apple-Text, GIF-Text, ICO-Text, PNG-Text, or JPG-Text. NVD description · AI analysis pending | 4.8 | 2% | PoC ×2 |
| — | |
| CVE-2017-16230 | In admin/write-post.php in Typecho through 1.1, one can log in to the background page, write a new article, and add payload in the article content, resulting in In admin/write-post.php in Typecho through 1.1, one can log in to the background page, write a new article, and add payload in the article content, resulting in XSS via index.php/action/contents-post-edit. NVD description · AI analysis pending | 5.4 | <1% | PoC |
| — | |
| CVE-2017-2228 | Untrusted search path vulnerability in Teikihoukokusho Sakuseishien Tool v4.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified dir Untrusted search path vulnerability in Teikihoukokusho Sakuseishien Tool v4.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. NVD description · AI analysis pending | 7.8 | 1% |
| — | ||
| CVE-2017-10823 | Untrusted search path vulnerability in Installer for Shin Kinkyuji Houkoku Data Nyuryoku Program (program released on 2011 March 10) Distributed on the website Untrusted search path vulnerability in Installer for Shin Kinkyuji Houkoku Data Nyuryoku Program (program released on 2011 March 10) Distributed on the website till 2017 May 17 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. NVD description · AI analysis pending | 7.8 | 1% |
| — | ||
| CVE-2017-10822 | Untrusted search path vulnerability in Installer for Shin Sekiyu Yunyu Chousa Houkoku Data Nyuryoku Program (program released on 2013 September 30) distributed Untrusted search path vulnerability in Installer for Shin Sekiyu Yunyu Chousa Houkoku Data Nyuryoku Program (program released on 2013 September 30) distributed on the website until 2017 May 17 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. NVD description · AI analysis pending | 7.8 | 1% |
| — | ||
| CVE-2017-10821 | Untrusted search path vulnerability in Installer for Shin Kikan Toukei Houkoku Data Nyuryokuyou Program (program released on 2013 September 30) Distributed on t Untrusted search path vulnerability in Installer for Shin Kikan Toukei Houkoku Data Nyuryokuyou Program (program released on 2013 September 30) Distributed on the website until 2017 May 17 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. NVD description · AI analysis pending | 7.8 | 1% |
| — |