The Twittee Text Tweet WordPress plugin through 1.0.8 does not properly escape POST values which are printed back to the user inside one of the plugin's administrative page, which allows reflected XSS ...
Continue ReadingJuly 31, 2023
AnaSystem SensMini M4 â Using the configuration tool, an authenticated user can cause Denial of Service for the deviceRead More ...
Continue ReadingJuly 30, 2023
Tadiran Telecom Composit - CWE-1236: Improper Neutralization of Formula Elements in a CSV FileRead More ...
Continue ReadingJuly 30, 2023
Tadiran Telecom Aeonix - CWE-204: Observable Response DiscrepancyRead More ...
Continue ReadingJuly 30, 2023
Tadiran Telecom Aeonix - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')Read More ...
Continue ReadingJuly 30, 2023
Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type -Â A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecified method.Read More ...
Continue ReadingJuly 30, 2023
Sysaid - CWE-552: Files or Directories Accessible to External Parties -Â Authenticated users may exfiltrate files from the server via an unspecified method.Read More ...
Continue ReadingJuly 30, 2023
Synel SYnergy Fingerprint Terminals - CWE-78: 'OS Command Injection'Read More ...
Continue ReadingJuly 30, 2023
Back to Main