Show filters
4,125 Total Results
Displaying 261-270 of 4,125
Sort by:
Attacker Value
Unknown

CVE-2024-0067

Disclosure Date: September 10, 2024 (last updated February 26, 2025)
Marinus Pfund, member of the AXIS OS Bug Bounty Program, has found the VAPIX API ledlimit.cgi was vulnerable for path traversal attacks allowing to list folder/file names on the local file system of the Axis device. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
0
Attacker Value
Unknown

CVE-2024-44113

Disclosure Date: September 10, 2024 (last updated February 26, 2025)
Due to missing authorization checks, SAP Business Warehouse (BEx Analyzer) allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation the attacker can enumerate information causing a limited impact on confidentiality of the application.
0
Attacker Value
Unknown

CVE-2024-41729

Disclosure Date: September 10, 2024 (last updated February 26, 2025)
Due to missing authorization checks, SAP BEx Analyzer allows an authenticated attacker to access information over the network which is otherwise restricted. On successful exploitation the attacker can enumerate information causing a limited impact on confidentiality of the application.
0
Attacker Value
Unknown

CVE-2024-7689

Disclosure Date: September 09, 2024 (last updated February 26, 2025)
The Snapshot Backup WordPress plugin through 2.1.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
Attacker Value
Unknown

CVE-2024-7688

Disclosure Date: September 09, 2024 (last updated February 26, 2025)
The AZIndex WordPress plugin through 0.8.1 does not have CSRF checks in some places, which could allow attackers to make logged in admin delete arbitrary indexes via a CSRF attack
Attacker Value
Unknown

CVE-2024-7687

Disclosure Date: September 09, 2024 (last updated February 26, 2025)
The AZIndex WordPress plugin through 0.8.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
Attacker Value
Unknown

CVE-2024-6925

Disclosure Date: September 08, 2024 (last updated February 26, 2025)
The TrueBooker WordPress plugin before 1.0.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack.
Attacker Value
Unknown

CVE-2024-6856

Disclosure Date: September 08, 2024 (last updated February 26, 2025)
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Attacker Value
Unknown

CVE-2024-6855

Disclosure Date: September 08, 2024 (last updated February 26, 2025)
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating exit popups, which could allow attackers to make logged admins perform such action via a CSRF attack
Attacker Value
Unknown

CVE-2024-6853

Disclosure Date: September 08, 2024 (last updated February 26, 2025)
The WP MultiTasking WordPress plugin through 0.1.12 does not have CSRF check when updating welcome popups, which could allow attackers to make logged admins perform such action via a CSRF attack