Show filters
1,911 Total Results
Displaying 471-480 of 1,911
Sort by:
Attacker Value
Unknown
CVE-2024-50450
Disclosure Date: October 28, 2024 (last updated February 26, 2025)
Improper Control of Generation of Code ('Code Injection') vulnerability in realmag777 WordPress Meta Data and Taxonomies Filter (MDTF) allows Code Injection.This issue affects WordPress Meta Data and Taxonomies Filter (MDTF): from n/a through 1.3.3.4.
0
Attacker Value
Unknown
CVE-2024-9162
Disclosure Date: October 28, 2024 (last updated February 26, 2025)
The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to arbitrary PHP Code Injection due to missing file type validation during the export in all versions up to, and including, 7.86. This makes it possible for authenticated attackers, with Administrator-level access and above, to create an export file with the .php extension on the affected site's server, adding an arbitrary PHP code to it, which may make remote code execution possible.
0
Attacker Value
Unknown
CVE-2024-50611
Disclosure Date: October 27, 2024 (last updated February 26, 2025)
CycloneDX cdxgen through 10.10.7, when run against an untrusted codebase, may execute code contained within build-related files such as build.gradle.kts, a similar issue to CVE-2022-24441. cdxgen is used by, for example, OWASP dep-scan. NOTE: this has been characterized as a design limitation, rather than an implementation mistake.
0
Attacker Value
Unknown
CVE-2024-9772
Disclosure Date: October 26, 2024 (last updated February 26, 2025)
The The Uix Shortcodes – Compatible with Gutenberg plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.9.9. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
0
Attacker Value
Unknown
CVE-2024-48236
Disclosure Date: October 25, 2024 (last updated February 26, 2025)
An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of the ofcms-admin\src\main\java\com\ofsoft\cms\core\uitle\FileUtils.java file
0
Attacker Value
Unknown
CVE-2024-48235
Disclosure Date: October 25, 2024 (last updated February 26, 2025)
An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController.java file.
0
Attacker Value
Unknown
CVE-2024-37846
Disclosure Date: October 25, 2024 (last updated February 26, 2025)
MangoOS before 5.2.0 was discovered to contain a Client-Side Template Injection (CSTI) vulnerability via the Platform Management Edit page.
0
Attacker Value
Unknown
CVE-2024-37845
Disclosure Date: October 25, 2024 (last updated February 26, 2025)
MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Process Command feature.
0
Attacker Value
Unknown
CVE-2024-48700
Disclosure Date: October 25, 2024 (last updated February 26, 2025)
Kliqqi-CMS has a background arbitrary code execution vulnerability that attackers can exploit to implant backdoors or getShell via the edit_page.php component.
0
Attacker Value
Unknown
CVE-2024-48655
Disclosure Date: October 25, 2024 (last updated February 26, 2025)
An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.
0