Vulnerabilities
66 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-36892 | Eibiz i-Media Server Digital Signage 3.8.0 contains an unauthenticated privilege escalation vulnerability in the updateUser object that allows attackers to modi Eibiz i-Media Server Digital Signage 3.8.0 contains an unauthenticated privilege escalation vulnerability in the updateUser object that allows attackers to modify user roles. Attackers can exploit the /messagebroker/amf endpoint to elevate privileges and take over user accounts by manipulating role settings without authentication. NVD description · AI analysis pending | 9.3 group max | 1% | PoC ×2 |
| — | |
| CVE-2024-8783 | A vulnerability classified as problematic has been found in OpenTibiaBR MyAAC up to 0.8.16. A vulnerability classified as problematic has been found in OpenTibiaBR MyAAC up to 0.8.16. Affected is an unknown function of the file system/pages/forum/new_post.php of the component Post Reply Handler. The manipulation of the argument post_topic leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The patch is identified as bf6ae3df0d32fa22552bb44ca4f8489a6e78cc1c. It is recommended to apply a patch to fix this issue. NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2024-23951 | Multiple improper array index validation vulnerabilities exist in the readMSH functionality of libigl v2.5.0. Multiple improper array index validation vulnerabilities exist in the readMSH functionality of libigl v2.5.0. A specially crafted .msh file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability concerns the `igl::MshLoader::parse_element_field` function while handling an `ascii`.msh` file. NVD description · AI analysis pending | 8.8 group max | <1% |
| — | ||
| CVE-2024-25713 | yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pool_free is part of the pool series allocator, along with pool_malloc and pool_realloc.) NVD description · AI analysis pending | 8.6 | 2% | PoC |
| — | |
| CVE-2024-21750 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scribit Shortcodes Finder allows Reflected XSS.This issue Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Scribit Shortcodes Finder allows Reflected XSS.This issue affects Shortcodes Finder: from n/a through 1.5.5. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2023-47695 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Scribit Shortcodes Finder plugin <= 1.5.3 versions. Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Scribit Shortcodes Finder plugin <= 1.5.3 versions. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2023-45772 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Scribit Proofreading plugin <= 1.0.11 versions. Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Scribit Proofreading plugin <= 1.0.11 versions. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2021-24942 | The Menu Item Visibility Control WordPress plugin through 0.5 doesn't sanitize and validate the "Visibility logic" option for WordPress menu items, which could The Menu Item Visibility Control WordPress plugin through 0.5 doesn't sanitize and validate the "Visibility logic" option for WordPress menu items, which could allow highly privileged users to execute arbitrary PHP code even in a hardened environment. NVD description · AI analysis pending | 7.2 | 1% | PoC |
| — | |
| CVE-2022-41643 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Accessibility plugin <= 1.0.3 on WordPress. Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Accessibility plugin <= 1.0.3 on WordPress. NVD description · AI analysis pending | 4.8 | <1% |
| — | ||
| CVE-2022-0150 | The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before outputting back its base64 decode value The WP Accessibility Helper (WAH) WordPress plugin before 0.6.0.7 does not sanitise and escape the wahi parameter before outputting back its base64 decode value in the page, leading to a Reflected Cross-Site Scripting issue NVD description · AI analysis pending | 6.1 | 2% | PoC |
| — | |
| CVE-2020-20658 +1 in the same advisory: …20657 | Buffer overflow vulnerability in fcovatti libiec_iccp_mod v1.5, allows attackers to cause a denail of service when trying to calloc an unexpectiedly large space Buffer overflow vulnerability in fcovatti libiec_iccp_mod v1.5, allows attackers to cause a denail of service when trying to calloc an unexpectiedly large space. NVD description · AI analysis pending | 7.5 | 1% |
| — | ||
| CVE-2020-20664 | libiec_iccp_mod v1.5 contains a segmentation violation in the component server_example1.c. libiec_iccp_mod v1.5 contains a segmentation violation in the component server_example1.c. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2021-32298 | An issue was discovered in libiff through 20190123. An issue was discovered in libiff through 20190123. A global-buffer-overflow exists in the function IFF_errorId located in error.c. It allows an attacker to cause code Execution. NVD description · AI analysis pending | 8.8 | 2% | PoC |
| — | |
| CVE-2020-20490 | A heap buffer-overflow in the client_example1.c component of libiec_iccp_mod v1.5 leads to a denial of service (DOS). A heap buffer-overflow in the client_example1.c component of libiec_iccp_mod v1.5 leads to a denial of service (DOS). NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2020-18121 | A configuration issue in Indexhibit 2.1.5 allows authenticated attackers to modify .php files, leading to getshell. A configuration issue in Indexhibit 2.1.5 allows authenticated attackers to modify .php files, leading to getshell. NVD description · AI analysis pending | 8.8 group max | <1% | PoC |
| — | |
| CVE-2020-14203 | WebFOCUS Business Intelligence 8.0 (SP6) allows a Cross-Site Request Forgery (CSRF) attack against administrative users within the /ibi_apps/WFServlet(.ibfs) en WebFOCUS Business Intelligence 8.0 (SP6) allows a Cross-Site Request Forgery (CSRF) attack against administrative users within the /ibi_apps/WFServlet(.ibfs) endpoint. The impact may be creation of an administrative user. It can also be exploited in conjunction with CVE-2016-9044. NVD description · AI analysis pending | 8.8 group max | <1% | PoC |
| — | |
| CVE-2019-5029 | An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands surrounded by backticks or $() can be inserted into the editor and will be executed by the Exhibitor process when it launches ZooKeeper. An attacker can execute any command as the user running the Exhibitor process. NVD description · AI analysis pending | 9.8 | 57% | PoC |
| — | |
| CVE-2019-16314 | Indexhibit 2.1.5 allows a product reinstallation, with resultant remote code execution, via /ndxzstudio/install.php?p=2. Indexhibit 2.1.5 allows a product reinstallation, with resultant remote code execution, via /ndxzstudio/install.php?p=2. NVD description · AI analysis pending | 9.8 | 39% | PoC |
| — | |
| CVE-2019-8954 | In Indexhibit 2.1.5, remote attackers can execute arbitrary code via the v parameter (in conjunction with the id parameter) in a upd_jxcode=true action to the n In Indexhibit 2.1.5, remote attackers can execute arbitrary code via the v parameter (in conjunction with the id parameter) in a upd_jxcode=true action to the ndxzstudio/?a=system URI. NVD description · AI analysis pending | 8.8 | 3% | PoC |
| — | |
| CVE-2017-17581 | FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter. FS Quibids Clone 1.0 has SQL Injection via the itechd.php productid parameter. NVD description · AI analysis pending | 9.8 | 3% | PoC ×2 |
| — | |
| CVE-2017-11551 | The id3_field_parse function in field.c in libid3tag 0.15.1b allows remote attackers to cause a denial of service (OOM) via a crafted MP3 file. The id3_field_parse function in field.c in libid3tag 0.15.1b allows remote attackers to cause a denial of service (OOM) via a crafted MP3 file. NVD description · AI analysis pending | 5.5 | 1% |
| — |