Show filters
1,884 Total Results
Displaying 401-410 of 1,884
Sort by:
Attacker Value
Unknown

CVE-2024-50919

Disclosure Date: November 18, 2024 (last updated February 27, 2025)
Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp. can lead to arbitrary command execution
0
Attacker Value
Unknown

CVE-2024-44757

Disclosure Date: November 18, 2024 (last updated February 27, 2025)
An arbitrary file download vulnerability in the component /Basics/DownloadInpFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to download arbitrary files and access sensitive information via a crafted interface request.
0
Attacker Value
Unknown

CVE-2024-52434

Disclosure Date: November 18, 2024 (last updated February 27, 2025)
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Supsystic Popup by Supsystic allows Command Injection.This issue affects Popup by Supsystic: from n/a through 1.10.29.
Attacker Value
Unknown

CVE-2024-52427

Disclosure Date: November 18, 2024 (last updated February 27, 2025)
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Saso Nikolov Event Tickets with Ticket Scanner allows Server Side Include (SSI) Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through 2.3.11.
Attacker Value
Unknown

CVE-2024-48962

Disclosure Date: November 18, 2024 (last updated February 27, 2025)
Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.17. Users are recommended to upgrade to version 18.12.17, which fixes the issue.
Attacker Value
Unknown

CVE-2024-47208

Disclosure Date: November 18, 2024 (last updated February 27, 2025)
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.17. Users are recommended to upgrade to version 18.12.17, which fixes the issue.
0
Attacker Value
Unknown

CVE-2024-52945

Disclosure Date: November 18, 2024 (last updated February 27, 2025)
An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup components running on a Windows Operating System. If a user executes specific NetBackup commands or an attacker uses social engineering techniques to impel the user to execute the commands, a malicious DLL could be loaded, resulting in execution of the attacker's code in the user's security context.
0
Attacker Value
Unknown

CVE-2024-9839

Disclosure Date: November 16, 2024 (last updated February 27, 2025)
The The Uix Slideshow plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.6.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
0
Attacker Value
Unknown

CVE-2024-10262

Disclosure Date: November 16, 2024 (last updated February 27, 2025)
The The Drop Shadow Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.7.14. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.
Attacker Value
Unknown

CVE-2024-44758

Disclosure Date: November 15, 2024 (last updated February 27, 2025)
An arbitrary file upload vulnerability in the component /Production/UploadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to execute arbitrary code via uploading crafted files.
0