CVE-2021-27370
The Contact page in Monica 2.19.1 allows stored XSS via the Last Name field.
Source: CVE-2021-27370
CVE-2021-27370
The Contact page in Monica 2.19.1 allows stored XSS via the Last Name field.
Source: CVE-2021-27370
CVE-2021-3120
An arbitrary file upload vulnerability in the YITH WooCommerce Gift Cards Premium plugin before 3.3.1 for WordPress allows remote attackers to achieve remote code execution on the operating system in the security context of the web server. In order to exploit this vulnerability, an attacker must be able to place a valid Gift Card product into the shopping cart. An uploaded file is placed at a predetermined path on the web server with a user-specified filename and extension. This occurs because the ywgc-upload-picture parameter can have a .php value even though the intention was to only allow uploads of Gift Card images.
Source: CVE-2021-3120
CVE-2021-27371
The Contact page in Monica 2.19.1 allows stored XSS via the Description field.
Source: CVE-2021-27371
CVE-2020-21224
A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0. A remote attacker can send a malicious login packet to the control server
Source: CVE-2020-21224
CVE-2020-19762
Automated Logic Corporation (ALC) WebCTRL System 6.5 and prior allows remote attackers to execute any JavaScript code via a XSS payload for the first parameter in a GET request.
Source: CVE-2020-19762
CVE-2021-27368
The Contact page in Monica 2.19.1 allows stored XSS via the First Name field.
Source: CVE-2021-27368
CVE-2021-27369
The Contact page in Monica 2.19.1 allows stored XSS via the Middle Name field.
Source: CVE-2021-27369
CVE-2020-11297
Denial of service in WLAN module due to improper check of subtypes in logic where excessive frames are dropped in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music
Source: CVE-2020-11297
CVE-2020-11296
Arithmetic overflow can happen while processing NOA IE due to improper error handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
Source: CVE-2020-11296
CVE-2020-11287
Allowing RTT frames to be linked with non randomized MAC address by comparing the sequence numbers can lead to information disclosure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking
Source: CVE-2020-11287