Show filters
1,402 Total Results
Displaying 261-270 of 1,402
Sort by:
Attacker Value
Unknown
CVE-2024-36120
Disclosure Date: May 31, 2024 (last updated February 26, 2025)
javascript-deobfuscator removes common JavaScript obfuscation techniques. In affected versions crafted payloads targeting expression simplification can lead to code execution. This issue has been patched in version 1.1.0. Users are advised to update. Users unable to upgrade should disable the expression simplification feature.
0
Attacker Value
Unknown
CVE-2024-5565
Disclosure Date: May 31, 2024 (last updated February 26, 2025)
The Vanna library uses a prompt function to present the user with visualized results, it is possible to alter the prompt using prompt injection and run arbitrary Python code instead of the intended visualization code. Specifically - allowing external input to the library’s “ask” method with "visualize" set to True (default behavior) leads to remote code execution.
0
Attacker Value
Unknown
CVE-2024-3924
Disclosure Date: May 30, 2024 (last updated February 26, 2025)
A code injection vulnerability exists in the huggingface/text-generation-inference repository, specifically within the `autodocs.yml` workflow file. The vulnerability arises from the insecure handling of the `github.head_ref` user input, which is used to dynamically construct a command for installing a software package. An attacker can exploit this by forking the repository, creating a branch with a malicious payload as the name, and then opening a pull request to the base repository. Successful exploitation could lead to arbitrary code execution within the context of the GitHub Actions runner. This issue affects versions up to and including v2.0.0 and was fixed in version 2.0.0.
0
Attacker Value
Unknown
CVE-2023-6743
Disclosure Date: May 29, 2024 (last updated February 26, 2025)
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.89 via the template import functionality. This makes it possible for authenticated attackers, with contributor access and above, to execute code on the server.
0
Attacker Value
Unknown
CVE-2024-35226
Disclosure Date: May 28, 2024 (last updated February 26, 2025)
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. In affected versions template authors could inject php code by choosing a malicious file name for an extends-tag. Sites that cannot fully trust template authors should update asap. All users are advised to update. There is no patch for users on the v3 branch. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2024-35581
Disclosure Date: May 28, 2024 (last updated February 26, 2025)
A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Borrower Name input field.
0
Attacker Value
Unknown
CVE-2024-23601
Disclosure Date: May 28, 2024 (last updated February 26, 2025)
A code injection vulnerability exists in the scan_lib.bin functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted scan_lib.bin can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2024-28886
Disclosure Date: May 28, 2024 (last updated February 26, 2025)
OS command injection vulnerability exists in UTAU versions prior to v0.4.19. If a user of the product opens a crafted UTAU project file (.ust file), an arbitrary OS command may be executed.
0
Attacker Value
Unknown
CVE-2024-29415
Disclosure Date: May 27, 2024 (last updated February 26, 2025)
The ip package through 2.0.1 for Node.js might allow SSRF because some IP addresses (such as 127.1, 01200034567, 012.1.2.3, 000:0:0000::01, and ::fFFf:127.0.0.1) are improperly categorized as globally routable via isPublic. NOTE: this issue exists because of an incomplete fix for CVE-2023-42282.
0
Attacker Value
Unknown
CVE-2024-5407
Disclosure Date: May 27, 2024 (last updated February 26, 2025)
A vulnerability in RhinOS 3.0-1190 could allow PHP code injection through the "search" parameter in /portal/search.htm. This vulnerability could allow a remote attacker to perform a reverse shell on the remote system, compromising the entire infrastructure.
0