CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
A cross-site scripting vulnerability was discovered in the Comments parameter in Textpattern CMS 4.8.4 which allows remote attackers to execute arbitrary code via a crafted payload entered into the URL field. The vulnerability is triggered by users visiting https://site.com/articles/welcome-to-your-site#comments-head.
A persistent cross-site scripting vulnerability was discovered in Local Services Search Engine Management System Project 1.0 which allows remote attackers to execute arbitrary code via crafted payloads entered into the Name and Address fields.
A SQL injection vulnerability was discovered in the editid parameter in Local Services Search Engine Management System Project 1.0. This vulnerability gives admin users the ability to dump all data from the database.
Appspace 6.2.4 is vulnerable to a broken authentication mechanism where pages such as /medianet/mail.aspx can be called directly and the framework is exposed with layouts, menus and functionalities.
Appspace 6.2.4 is vulnerable to stored cross-site scripting (XSS) in multiple parameters within /medianet/sgcontentset.aspx.
In Pluck-4.7.15 admin background a remote command execution vulnerability exists when uploading files.
Remote Code Execution (RCE) vulnerability exists in MaxSite CMS v107.5 via the Documents page.
SQL injection exists in Piwigo before 11.4.0 via the language parameter to admin.php?page=languages.
Alps Alpine Touchpad Driver 10.3201.101.215 is vulnerable to DLL Injection.
Dolphin CMS 7.4.2 is vulnerable to stored XSS via the Page Builder "width" parameter.
