Show filters
1,911 Total Results
Displaying 471-480 of 1,911
Sort by:
Attacker Value
Unknown

CVE-2024-50450

Disclosure Date: October 28, 2024 (last updated February 26, 2025)
Improper Control of Generation of Code ('Code Injection') vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Code Injection.This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.4.
Attacker Value
Unknown

CVE-2024-9162

Disclosure Date: October 28, 2024 (last updated February 26, 2025)
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code Injection due to missing file type validation during the export in all versions up to, and including, 7.86. This makes it possible for authenticated attackers, with Administrator-level access and above, to create an export file with the .php extension on the affected site's server, adding an arbitrary PHP code to it, which may make remote code execution possible.
0
Attacker Value
Unknown

CVE-2024-50611

Disclosure Date: October 27, 2024 (last updated February 26, 2025)
CycloneDX cdxgen through 10.10.7, when run against an untrusted codebase, may execute code contained within build-related files such as build.gradle.kts, a similar issue to CVE-2022-24441. cdxgen is used by, for example, OWASP dep-scan. NOTE: this has been characterized as a design limitation, rather than an implementation mistake.
0
Attacker Value
Unknown

CVE-2024-9772

Disclosure Date: October 26, 2024 (last updated February 26, 2025)
The The Uix Shortcodes – Compatible with Gutenberg plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.9.9. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
Attacker Value
Unknown

CVE-2024-48236

Disclosure Date: October 25, 2024 (last updated February 26, 2025)
An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of the ofcms-admin\src\main\java\com\ofsoft\cms\core\uitle\FileUtils.java file
0
Attacker Value
Unknown

CVE-2024-48235

Disclosure Date: October 25, 2024 (last updated February 26, 2025)
An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController.java file.
0
Attacker Value
Unknown

CVE-2024-37846

Disclosure Date: October 25, 2024 (last updated February 26, 2025)
MangoOS before 5.2.0 was discovered to contain a Client-Side Template Injection (CSTI) vulnerability via the Platform Management Edit page.
Attacker Value
Unknown

CVE-2024-37845

Disclosure Date: October 25, 2024 (last updated February 26, 2025)
MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Process Command feature.
Attacker Value
Unknown

CVE-2024-48700

Disclosure Date: October 25, 2024 (last updated February 26, 2025)
Kliqqi-CMS has a background arbitrary code execution vulnerability that attackers can exploit to implant backdoors or getShell via the edit_page.php component.
0
Attacker Value
Unknown

CVE-2024-48655

Disclosure Date: October 25, 2024 (last updated February 26, 2025)
An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.
0