Show filters
1,917 Total Results
Displaying 521-530 of 1,917
Sort by:
Attacker Value
Unknown

CVE-2024-45874

Disclosure Date: October 07, 2024 (last updated February 26, 2025)
A DLL hijacking vulnerability in VegaBird Vooki 5.2.9 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL file in the same directory as Vooki.exe.
0
Attacker Value
Unknown

CVE-2024-45873

Disclosure Date: October 07, 2024 (last updated February 26, 2025)
A DLL hijacking vulnerability in VegaBird Yaazhini 2.0.2 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL file in the same directory as Yaazhini.exe.
0
Attacker Value
Unknown

CVE-2024-43363

Disclosure Date: October 07, 2024 (last updated February 26, 2025)
Cacti is an open source performance and fault management framework. An admin user can create a device with a malicious hostname containing php code and repeat the installation process (completing only step 5 of the installation process is enough, no need to complete the steps before or after it) to use a php file as the cacti log file. After having the malicious hostname end up in the logs (log poisoning), one can simply go to the log file url to execute commands to achieve RCE. This issue has been addressed in version 1.2.28 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Attacker Value
Unknown

CVE-2024-46076

Disclosure Date: October 07, 2024 (last updated February 26, 2025)
RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabling the injection of malicious code.
0
Attacker Value
Unknown

CVE-2024-45933

Disclosure Date: October 07, 2024 (last updated February 26, 2025)
OnlineNewsSite v1.0 is vulnerable to Cross Site Scripting (XSS) which allows attackers to execute arbitrary code via the Title and summary fields in the /admin/post/edit/ endpoint.
0
Attacker Value
Unknown

CVE-2024-8254

Disclosure Date: October 02, 2024 (last updated February 26, 2025)
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.7.34. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.
Attacker Value
Unknown

CVE-2024-45186

Disclosure Date: October 02, 2024 (last updated February 26, 2025)
FileSender before 2.49 allows server-side template injection (SSTI) for retrieving credentials.
0
Attacker Value
Unknown

CVE-2024-46080

Disclosure Date: October 01, 2024 (last updated February 26, 2025)
Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function.
0
Attacker Value
Unknown

CVE-2024-44744

Disclosure Date: October 01, 2024 (last updated February 26, 2025)
An issue in Malwarebytes Premium Security v5.0.0.883 allows attackers to execute arbitrary code via placing crafted binaries into unspecified directories. NOTE: Malwarebytes argues that this issue requires admin privileges and that the contents cannot be altered by non-admin users.
0
Attacker Value
Unknown

CVE-2024-28811

Disclosure Date: September 30, 2024 (last updated February 26, 2025)
An issue was discovered in Infinera hiT 7300 5.60.50. A web application allows a remote privileged attacker to execute applications contained in a specific OS directory via HTTP invocations.
0