Show filters
1,910 Total Results
Displaying 461-470 of 1,910
Sort by:
Attacker Value
Unknown

CVE-2024-51424

Disclosure Date: October 30, 2024 (last updated February 27, 2025)
An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the Owned.setOwner function. NOTE: this is disputed by third parties because the impact is limited to function calls.
0
Attacker Value
Unknown

CVE-2024-51243

Disclosure Date: October 30, 2024 (last updated February 27, 2025)
The eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deployment servers of this management system via DeployController.java.
0
Attacker Value
Unknown

CVE-2024-42041

Disclosure Date: October 30, 2024 (last updated February 27, 2025)
The com.videodownload.browser.videodownloader (aka AppTool-Browser-Video All Video Downloader) application 20-30.05.24 for Android allows an attacker to execute arbitrary JavaScript code via the acr.browser.lightning.DefaultBrowserActivity component.
0
Attacker Value
Unknown

CVE-2024-9846

Disclosure Date: October 30, 2024 (last updated February 26, 2025)
The The Enable Shortcodes inside Widgets,Comments and Experts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Attacker Value
Unknown

CVE-2024-10505

Disclosure Date: October 30, 2024 (last updated February 26, 2025)
A vulnerability was found in wuzhicms 4.1.0. It has been classified as critical. Affected is the function add/edit of the file www/coreframe/app/content/admin/block.php. The manipulation leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Initially two separate issues were created by the researcher for the different function calls. The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2024-48138

Disclosure Date: October 29, 2024 (last updated February 26, 2025)
A remote code execution (RCE) vulnerability in the component /PluXml/core/admin/parametres_edittpl.php of PluXml v5.8.16 and lower allows attackers to execute arbitrary code via injecting a crafted payload into a template.
0
Attacker Value
Unknown

CVE-2024-8923

Disclosure Date: October 29, 2024 (last updated February 26, 2025)
ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow deployed an update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. Further, the vulnerability is addressed in the listed patches and hot fixes.
Attacker Value
Unknown

CVE-2024-50498

Disclosure Date: October 28, 2024 (last updated February 26, 2025)
Improper Control of Generation of Code ('Code Injection') vulnerability in LUBUS WP Query Console allows Code Injection.This issue affects WP Query Console: from n/a through 1.0.
Attacker Value
Unknown

CVE-2024-50492

Disclosure Date: October 28, 2024 (last updated February 26, 2025)
Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson ScottCart allows Code Injection.This issue affects ScottCart: from n/a through 1.1.
Attacker Value
Unknown

CVE-2024-50450

Disclosure Date: October 28, 2024 (last updated February 26, 2025)
Improper Control of Generation of Code ('Code Injection') vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Code Injection.This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.4.