Cross-Site Request Forgery (CSRF) vulnerability in Eric Teubert Archivist – Custom Archive Templates plugin <= 1.7.4 versions.
Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could potentially exploit this vulnerability leading to exposure of some SMRAM stack/data/code in System Management Mode, leading to arbitrary code execution or escalation of privilege.
The affected products have a CSRF vulnerability that could allow an attacker to execute code and upload malicious files.
In Snap One OvrC Pro versions prior to 7.2, when logged into the superuser account, a new functionality appears that could allow users to execute arbitrary commands on the hub device.
Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to execute arbitrary code in first/second name field.
Cross-Site Request Forgery (CSRF) vulnerability in Inkthemescom ColorWay theme <=Â 4.2.3 versions.
Files present on firmware images could allow an attacker to gain unauthorized access as a root user using hard-coded credentials.
Cross-Site Request Forgery (CSRF) vulnerability in SecondLineThemes Auto YouTube Importer plugin <=Â 1.0.3 versions.
Cross-Site Request Forgery (CSRF) vulnerability in Joseph C Dolson My Calendar plugin <=Â 3.4.3 versions.
Cross-Site Request Forgery (CSRF) vulnerability in Bob Goetz WP-TopBar plugin <=Â 5.36 versions.