Show filters
1,916 Total Results
Displaying 501-510 of 1,916
Sort by:
Attacker Value
Unknown
CVE-2023-39593
Disclosure Date: October 17, 2024 (last updated February 26, 2025)
Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.
0
Attacker Value
Unknown
CVE-2023-26785
Disclosure Date: October 17, 2024 (last updated February 26, 2025)
MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create function" statement. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.
0
Attacker Value
Unknown
CVE-2024-10073
Disclosure Date: October 17, 2024 (last updated February 26, 2025)
A vulnerability, which was classified as critical, was found in flairNLP flair 0.14.0. Affected is the function ClusteringModel of the file flair\models\clustering.py of the component Mode File Loader. The manipulation leads to code injection. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-49579
Disclosure Date: October 17, 2024 (last updated February 26, 2025)
In JetBrains YouTrack before 2024.3.47197 insecure plugin iframe allowed arbitrary JavaScript execution and unauthorized API requests
0
Attacker Value
Unknown
CVE-2024-45766
Disclosure Date: October 17, 2024 (last updated February 26, 2025)
Dell OpenManage Enterprise, version(s) OME 4.1 and prior, contain(s) an Improper Control of Generation of Code ('Code Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution.
0
Attacker Value
Unknown
CVE-2024-48744
Disclosure Date: October 16, 2024 (last updated February 26, 2025)
A Reflected Cross Site Scripting (XSS) vulnerability was found in /trms/listed- teachers.php in PHPGurukul Teachers Record Management System v2.1, which allows remote attackers to execute arbitrary code via "searchinput" POST request parameter.
0
Attacker Value
Unknown
CVE-2024-49254
Disclosure Date: October 16, 2024 (last updated February 26, 2025)
Improper Control of Generation of Code ('Code Injection') vulnerability in Sunjianle allows Code Injection.This issue affects ajax-extend: from n/a through 1.0.
0
Attacker Value
Unknown
CVE-2024-49271
Disclosure Date: October 16, 2024 (last updated February 26, 2025)
: Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows : Command Injection.This issue affects Unlimited Elements For Elementor (Free Widgets, Addons, Templates): from n/a through 1.5.121.
0
Attacker Value
Unknown
CVE-2024-9061
Disclosure Date: October 16, 2024 (last updated February 26, 2025)
The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary shortcode execution via the wp_ajax_nopriv_shortcode_Api_Add AJAX action in all versions up to, and including, 1.3.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. NOTE: This vulnerability was partially fixed in version 1.3.5 with a nonce check, which effectively prevented access to the affected function. However, version 1.3.6 incorporates the correct authorization check to prevent unauthorized access.
0
Attacker Value
Unknown
CVE-2023-31493
Disclosure Date: October 15, 2024 (last updated February 26, 2025)
RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted payload and escalate privileges allowing execution of any commands on the remote system.
0