Show filters
2,044 Total Results
Displaying 231-240 of 2,044
Sort by:
Attacker Value
Unknown
CVE-2024-0236
Disclosure Date: January 16, 2024 (last updated February 26, 2025)
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve the settings of arbitrary virtual events, including any meeting password set (for example for Zoom)
0
Attacker Value
Unknown
CVE-2024-0235
Disclosure Date: January 16, 2024 (last updated February 26, 2025)
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog
0
Attacker Value
Unknown
CVE-2022-23180
Disclosure Date: January 16, 2024 (last updated February 26, 2025)
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn't have authorisation and nonce checks, which could allow any authenticated users, such as subscriber to update and change various settings
0
Attacker Value
Unknown
CVE-2024-0570
Disclosure Date: January 16, 2024 (last updated February 26, 2025)
A vulnerability classified as critical was found in Totolink N350RT 9.3.5u.6265. This vulnerability affects unknown code of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. It is recommended to upgrade the affected component. VDB-250786 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2024-0569
Disclosure Date: January 16, 2024 (last updated February 26, 2025)
A vulnerability classified as problematic has been found in Totolink T8 4.1.5cu.833_20220905. This affects the function getSysStatusCfg of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument ssid/key leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.5cu.862_B20230228 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-250785 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-34063
Disclosure Date: January 16, 2024 (last updated February 26, 2025)
Aria Automation contains a Missing Access Control vulnerability.
An authenticated malicious actor may
exploit this vulnerability leading to unauthorized access to remote
organizations and workflows.
0
Attacker Value
Unknown
CVE-2023-6066
Disclosure Date: January 15, 2024 (last updated February 26, 2025)
The WP Custom Widget area WordPress plugin through 1.2.5 does not properly apply capability and nonce checks on any of its AJAX action callback functions, which could allow attackers with subscriber+ privilege to create, delete or modify menus on the site.
0
Attacker Value
Unknown
CVE-2023-6048
Disclosure Date: January 15, 2024 (last updated February 26, 2025)
The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not prevent user with low privileges on the site, like subscribers, from setting any of the site's options to 1, which could be used to break sites and lead to DoS when certain options are reset
0
Attacker Value
Unknown
CVE-2023-6029
Disclosure Date: January 15, 2024 (last updated February 26, 2025)
The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure that they are documents from the plugin, allowing unauthenticated users to delete arbitrary posts, as well as add and delete documents/sections.
0
Attacker Value
Unknown
CVE-2023-5905
Disclosure Date: January 15, 2024 (last updated February 26, 2025)
The DeMomentSomTres WordPress Export Posts With Images WordPress plugin through 20220825 does not check authorization of requests to export the blog data, allowing any logged in user, such as subscribers to export the contents of the blog, including restricted and unpublished posts, as well as passwords of protected posts.
0