Show filters
4,125 Total Results
Displaying 261-270 of 4,125
Sort by:
Attacker Value
Unknown
CVE-2024-0067
Disclosure Date: September 10, 2024 (last updated February 26, 2025)
Marinus Pfund, member of the AXIS OS Bug Bounty Program,
has found the VAPIX API ledlimit.cgi was vulnerable for path traversal attacks allowing to list folder/file names on the local file system of the Axis device.
Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
0
Attacker Value
Unknown
CVE-2024-44113
Disclosure Date: September 10, 2024 (last updated February 26, 2025)
Due to missing authorization checks, SAP Business Warehouse (BEx Analyzer) allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation the attacker can enumerate information causing a limited impact on confidentiality of the application.
0
Attacker Value
Unknown
CVE-2024-41729
Disclosure Date: September 10, 2024 (last updated February 26, 2025)
Due to missing authorization checks, SAP BEx Analyzer allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation the attacker can enumerate information causing a limited impact on confidentiality of the application.
0
Attacker Value
Unknown
CVE-2024-7689
Disclosure Date: September 09, 2024 (last updated February 26, 2025)
The Snapshot Backup WordPress plugin through 2.1.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
0
Attacker Value
Unknown
CVE-2024-7688
Disclosure Date: September 09, 2024 (last updated February 26, 2025)
The AZIndex WordPress plugin through 0.8.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin delete arbitrary indexes via a CSRF attack
0
Attacker Value
Unknown
CVE-2024-7687
Disclosure Date: September 09, 2024 (last updated February 26, 2025)
The AZIndex WordPress plugin through 0.8.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
0
Attacker Value
Unknown
CVE-2024-6925
Disclosure Date: September 08, 2024 (last updated February 26, 2025)
The TrueBooker WordPress plugin before 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
0
Attacker Value
Unknown
CVE-2024-6856
Disclosure Date: September 08, 2024 (last updated February 26, 2025)
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
0
Attacker Value
Unknown
CVE-2024-6855
Disclosure Date: September 08, 2024 (last updated February 26, 2025)
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating exit popups, which could allow attackers to make logged admins perform such action via a CSRF attack
0
Attacker Value
Unknown
CVE-2024-6853
Disclosure Date: September 08, 2024 (last updated February 26, 2025)
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating welcome popups, which could allow attackers to make logged admins perform such action via a CSRF attack
0