Show filters
2,044 Total Results
Displaying 231-240 of 2,044
Sort by:
Attacker Value
Unknown

CVE-2024-0236

Disclosure Date: January 16, 2024 (last updated February 26, 2025)
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve the settings of arbitrary virtual events, including any meeting password set (for example for Zoom)
Attacker Value
Unknown

CVE-2024-0235

Disclosure Date: January 16, 2024 (last updated February 26, 2025)
The EventON WordPress plugin before 4.5.5, EventON WordPress plugin before 2.2.7 do not have authorisation in an AJAX action, allowing unauthenticated users to retrieve email addresses of any users on the blog
Attacker Value
Unknown

CVE-2022-23180

Disclosure Date: January 16, 2024 (last updated February 26, 2025)
The Contact Form & Lead Form Elementor Builder WordPress plugin before 1.7.4 doesn't have authorisation and nonce checks, which could allow any authenticated users, such as subscriber to update and change various settings
Attacker Value
Unknown

CVE-2024-0570

Disclosure Date: January 16, 2024 (last updated February 26, 2025)
A vulnerability classified as critical was found in Totolink N350RT 9.3.5u.6265. This vulnerability affects unknown code of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation leads to improper access controls. The attack can be initiated remotely. It is recommended to upgrade the affected component. VDB-250786 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2024-0569

Disclosure Date: January 16, 2024 (last updated February 26, 2025)
A vulnerability classified as problematic has been found in Totolink T8 4.1.5cu.833_20220905. This affects the function getSysStatusCfg of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation of the argument ssid/key leads to information disclosure. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.1.5cu.862_B20230228 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-250785 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2023-34063

Disclosure Date: January 16, 2024 (last updated February 26, 2025)
Aria Automation contains a Missing Access Control vulnerability. An authenticated malicious actor may exploit this vulnerability leading to unauthorized access to remote organizations and workflows.
Attacker Value
Unknown

CVE-2023-6066

Disclosure Date: January 15, 2024 (last updated February 26, 2025)
The WP Custom Widget area WordPress plugin through 1.2.5 does not properly apply capability and nonce checks on any of its AJAX action callback functions, which could allow attackers with subscriber+ privilege to create, delete or modify menus on the site.
Attacker Value
Unknown

CVE-2023-6048

Disclosure Date: January 15, 2024 (last updated February 26, 2025)
The Estatik Real Estate Plugin WordPress plugin before 4.1.1 does not prevent user with low privileges on the site, like subscribers, from setting any of the site's options to 1, which could be used to break sites and lead to DoS when certain options are reset
Attacker Value
Unknown

CVE-2023-6029

Disclosure Date: January 15, 2024 (last updated February 26, 2025)
The EazyDocs WordPress plugin before 2.3.6 does not have authorization and CSRF checks when handling documents and does not ensure that they are documents from the plugin, allowing unauthenticated users to delete arbitrary posts, as well as add and delete documents/sections.
Attacker Value
Unknown

CVE-2023-5905

Disclosure Date: January 15, 2024 (last updated February 26, 2025)
The DeMomentSomTres WordPress Export Posts With Images WordPress plugin through 20220825 does not check authorization of requests to export the blog data, allowing any logged in user, such as subscribers to export the contents of the blog, including restricted and unpublished posts, as well as passwords of protected posts.