CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “att”

425 vulnerabilities found for “att”

Page 1 of 22

CVE-2025-12331
MEDIUM4.7

A weakness has been identified in Willow CMS up to 1.4.0. Impacted is an unknown function of the file /admin/images/add. This manipulation causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.

matthewdeaves / willow_cms
Network
Published Oct 27, 2025
Page 1 of 22
CVE-2025-12330
LOW2.4

A security flaw has been discovered in Willow CMS up to 1.4.0. This issue affects some unknown processing of the file /admin/articles/add of the component Add Post Page. The manipulation of the argument title/body results in cross site scripting. The attack may be launched remotely. The exploit has been released to the public and may be exploited.

matthewdeaves / willow_cms
Network
Published Oct 27, 2025
CVE-2025-27997
HIGH8.4

An issue in Blizzard Battle.net v2.40.0.15267 allows attackers to escalate privileges via placing a crafted shell script or executable into the C:\ProgramData directory.

blizzard / battle.net
Local
Published May 21, 2025
CVE-2024-1310
MEDIUM4.9

The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)

automattic / woocommerce
Network
Published Apr 15, 2024
CVE-2023-47777
MEDIUM6.5

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Automattic WooCommerce, Automattic WooCommerce Blocks allows Stored XSS.This issue affects WooCommerce: from n/a through 8.1.1; WooCommerce Blocks: from n/a through 11.1.1.

automattic / woocommerce+1
Network
Published Nov 30, 2023
CVE-2020-27383
HIGH7.8

Battle.net.exe in Battle.Net 1.27.1.12428 suffers from an elevation of privileges vulnerability which can be used by an "Authenticated User" to modify the existing executable file with a binary of his choice. The vulnerability exist due to weak set of permissions being granted to the "Authenticated Users Group" which grants the (F) Flag aka "Full Control"

blizzard / battle.net
Local
Published Jun 9, 2021
CVE-2020-17479
CRITICAL9.8

jpv (aka Json Pattern Validator) before 2.2.2 does not properly validate input, as demonstrated by a corrupted array.

json_pattern_validator_project / json_pattern_validator
Network
Published Aug 10, 2020
CVE-2019-20853
CRITICAL9.8

An issue was discovered in Mattermost Packages before 5.16.3. A Droplet could allow Internet access to a service that has a remote code execution problem.

mattermost / mattermost_packages
Network
Published Jun 19, 2020
CVE-2019-20852
HIGH7.5

An issue was discovered in Mattermost Mobile Apps before 1.26.0. Local logging is not blocked for sensitive information (e.g., server addresses or message content).

mattermost / mattermost_mobile
Network
Published Jun 19, 2020
CVE-2020-14451
HIGH7.5

An issue was discovered in Mattermost Mobile Apps before 1.29.0. The iOS app allowed Single Sign-On cookies and Local Storage to remain after a logout, aka MMSA-2020-0013.

mattermost / mattermost_mobile
Network
Published Jun 19, 2020
CVE-2019-20849
MEDIUM5.3

An issue was discovered in Mattermost Mobile Apps before 1.26.0. Cookie data can persist on a device after a logout.

mattermost / mattermost_mobile
Network
Published Jun 19, 2020
CVE-2019-20848
HIGH7.5

An issue was discovered in Mattermost Mobile Apps before 1.26.0. The Quick Reply feature mishandles crafted replies.

mattermost / mattermost_mobile
Network
Published Jun 19, 2020
CVE-2020-14449
HIGH7.5

An issue was discovered in Mattermost Mobile Apps before 1.30.0. Authorization tokens can sometimes be disclosed to third-party servers, aka MMSA-2020-0018.

mattermost / mattermost_mobile
Network
Published Jun 19, 2020
CVE-2019-20850
MEDIUM5.3

An issue was discovered in Mattermost Mobile Apps before 1.26.0. A view cache can persist on a device after a logout.

mattermost / mattermost_mobile
Network
Published Jun 19, 2020
CVE-2019-19507
MEDIUM5.3

In jpv (aka Json Pattern Validator) before 2.1.1, compareCommon() can be bypassed because certain internal attributes can be overwritten via a conflicting name, as demonstrated by 'constructor': {'name':'Array'}. This affects validate(). Hence, a crafted payload can overwrite this builtin attribute to manipulate the type detection result.

json_pattern_validator_project / json_pattern_validator
Network
Published Dec 2, 2019
CVE-2015-9335
CRITICAL9.8

The limit-attempts plugin before 1.1.1 for WordPress has SQL injection during IP address handling.

bestwebsoft / limit_attempts
Network
Published Aug 22, 2019
CVE-2015-9255
MEDIUM5.3

Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information about data, software versions, configuration, and virtual machines via a request to a Web Virtual Directory.

datto / alto_3_firmware+7
Network
Published Feb 20, 2018
CVE-2015-2081
CRITICAL9.8

Datto ALTO and SIRIS devices allow Remote Code Execution via unauthenticated requests to PHP scripts.

datto / alto_3_firmware+7
Network
Published Feb 20, 2018
CVE-2015-9256
MEDIUM5.3

Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information via access to device/VM restore mount points, because they do not have ACLs by default.

datto / alto_3_firmware+7
Network
Published Feb 20, 2018
CVE-2015-9254
CRITICAL9.8

Datto ALTO and SIRIS devices have a default VNC password.

datto / alto_3_firmware+7
Network
Published Feb 20, 2018