Show filters
1,910 Total Results
Displaying 451-460 of 1,910
Sort by:
Attacker Value
Unknown

CVE-2024-51757

Disclosure Date: November 06, 2024 (last updated February 27, 2025)
happy-dom is a JavaScript implementation of a web browser without its graphical user interface. Versions of happy-dom prior to 15.10.2 may execute code on the host via a script tag. This would execute code in the user context of happy-dom. Users are advised to upgrade to version 15.10.2. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown

CVE-2024-10263

Disclosure Date: November 05, 2024 (last updated February 27, 2025)
The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.5.4.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Attacker Value
Unknown

CVE-2024-48061

Disclosure Date: November 04, 2024 (last updated February 27, 2025)
langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the components run on the local machine rather than in a sandbox.
0
Attacker Value
Unknown

CVE-2024-48050

Disclosure Date: November 04, 2024 (last updated February 27, 2025)
In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. Within this function, the line result = eval(s) poses a security risk as it can directly execute user-provided commands.
0
Attacker Value
Unknown

CVE-2024-51329

Disclosure Date: November 04, 2024 (last updated February 27, 2025)
A Host header injection vulnerability in Agile-Board 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link.
Attacker Value
Unknown

CVE-2024-10035

Disclosure Date: November 04, 2024 (last updated February 27, 2025)
Improper Control of Generation of Code ('Code Injection') vulnerability in BG-TEK Informatics Security Technologies CoslatV3 allows Command Injection.This issue affects CoslatV3: through 3.1069. NOTE: The vendor was contacted and it was learned that the product is not supported.
Attacker Value
Unknown

CVE-2024-10761

Disclosure Date: November 04, 2024 (last updated February 27, 2025)
A vulnerability was found in Umbraco CMS up to 10.7.7/12.3.6/13.5.2/14.3.1/15.1.1. It has been classified as problematic. Affected is an unknown function of the file /Umbraco/preview/frame?id{} of the component Dashboard. The manipulation of the argument culture leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 10.8.8, 13.5.3, 14.3.2 and 15.1.2 is able to address this issue. It is recommended to upgrade the affected component.
Attacker Value
Unknown

CVE-2024-48359

Disclosure Date: October 31, 2024 (last updated February 27, 2025)
Qualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parameter.
0
Attacker Value
Unknown

CVE-2024-21537

Disclosure Date: October 31, 2024 (last updated February 27, 2025)
Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the insecure usage of eval in the dynamicImport function. An attacker can exploit this vulnerability by passing a malicious input through the defaultLoaders function.
0
Attacker Value
Unknown

CVE-2024-51427

Disclosure Date: October 30, 2024 (last updated February 27, 2025)
An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the mint function. NOTE: this is disputed by third parties because the impact is limited to function calls.
0