Show filters
1,651 Total Results
Displaying 291-300 of 1,651
Sort by:
Attacker Value
Unknown

CVE-2024-8623

Disclosure Date: September 24, 2024 (last updated February 26, 2025)
The The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.3.3.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Attacker Value
Unknown

CVE-2024-46639

Disclosure Date: September 23, 2024 (last updated February 26, 2025)
A cross-site scripting (XSS) vulnerability in HelpDeskZ v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field of Custom Fields message box.
0
Attacker Value
Unknown

CVE-2024-37779

Disclosure Date: September 23, 2024 (last updated February 26, 2025)
WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script functionality.
0
Attacker Value
Unknown

CVE-2024-0004

Disclosure Date: September 23, 2024 (last updated February 26, 2025)
A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to escalate privilege on the array.
Attacker Value
Unknown

CVE-2024-40442

Disclosure Date: September 23, 2024 (last updated February 26, 2025)
An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote attacker to escalate privileges via a crafted REST Request.
0
Attacker Value
Unknown

CVE-2024-47219

Disclosure Date: September 22, 2024 (last updated February 26, 2025)
An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection.
0
Attacker Value
Unknown

CVE-2024-46640

Disclosure Date: September 20, 2024 (last updated February 26, 2025)
SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL slow query method.
0
Attacker Value
Unknown

CVE-2024-46103

Disclosure Date: September 20, 2024 (last updated February 26, 2025)
SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.
0
Attacker Value
Unknown

CVE-2024-9006

Disclosure Date: September 19, 2024 (last updated February 26, 2025)
A vulnerability was found in jeanmarc77 123solar 1.8.4.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file config/config_invt1.php. The manipulation of the argument PASSOx leads to code injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The patch is identified as f4a8c748ec436e5a79f91ccb6a6f73752b336aa5. It is recommended to apply a patch to fix this issue.
Attacker Value
Unknown

CVE-2024-35515

Disclosure Date: September 18, 2024 (last updated February 26, 2025)
Insecure deserialization in sqlitedict up to v2.1.0 allows attackers to execute arbitrary code.
0