Show filters
1,651 Total Results
Displaying 291-300 of 1,651
Sort by:
Attacker Value
Unknown
CVE-2024-8623
Disclosure Date: September 24, 2024 (last updated February 26, 2025)
The The MDTF – Meta Data and Taxonomies Filter plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.3.3.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
0
Attacker Value
Unknown
CVE-2024-46639
Disclosure Date: September 23, 2024 (last updated February 26, 2025)
A cross-site scripting (XSS) vulnerability in HelpDeskZ v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field of Custom Fields message box.
0
Attacker Value
Unknown
CVE-2024-37779
Disclosure Date: September 23, 2024 (last updated February 26, 2025)
WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script functionality.
0
Attacker Value
Unknown
CVE-2024-0004
Disclosure Date: September 23, 2024 (last updated February 26, 2025)
A condition exists in FlashArray Purity whereby an user with array admin role can execute arbitrary commands remotely to escalate privilege on the array.
0
Attacker Value
Unknown
CVE-2024-40442
Disclosure Date: September 23, 2024 (last updated February 26, 2025)
An issue in Doccano Open source annotation tools for machine learning practitioners v.1.8.4 and Doccano Auto Labeling Pipeline module to annotate a document automatically v.0.1.23 allows a remote attacker to escalate privileges via a crafted REST Request.
0
Attacker Value
Unknown
CVE-2024-47219
Disclosure Date: September 22, 2024 (last updated February 26, 2025)
An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection.
0
Attacker Value
Unknown
CVE-2024-46640
Disclosure Date: September 20, 2024 (last updated February 26, 2025)
SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file through the MySQL slow query method.
0
Attacker Value
Unknown
CVE-2024-46103
Disclosure Date: September 20, 2024 (last updated February 26, 2025)
SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.
0
Attacker Value
Unknown
CVE-2024-9006
Disclosure Date: September 19, 2024 (last updated February 26, 2025)
A vulnerability was found in jeanmarc77 123solar 1.8.4.5. It has been rated as critical. Affected by this issue is some unknown functionality of the file config/config_invt1.php. The manipulation of the argument PASSOx leads to code injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The patch is identified as f4a8c748ec436e5a79f91ccb6a6f73752b336aa5. It is recommended to apply a patch to fix this issue.
0
Attacker Value
Unknown
CVE-2024-35515
Disclosure Date: September 18, 2024 (last updated February 26, 2025)
Insecure deserialization in sqlitedict up to v2.1.0 allows attackers to execute arbitrary code.
0