Show filters
419 Total Results
Displaying 1-10 of 419
Sort by:
Attacker Value
Unknown

CVE-2024-11881

Disclosure Date: December 18, 2024 (last updated December 18, 2024)
The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easywaveformplayer' shortcode in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2024-54008

Disclosure Date: December 10, 2024 (last updated December 21, 2024)
An authenticated Remote Code Execution (RCE) vulnerability exists in the AirWave CLI. Successful exploitation of this vulnerability could allow a remote authenticated threat actor to run arbitrary commands as a privileged user on the underlying host.
0
Attacker Value
Unknown

CVE-2024-51561

Disclosure Date: November 04, 2024 (last updated November 07, 2024)
This vulnerability exists in Aero due to improper implementation of OTP validation mechanism in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by intercepting and manipulating the responses exchanged during the second factor authentication process. Successful exploitation of this vulnerability could allow the attacker to bypass OTP verification for accessing other user accounts.
Attacker Value
Unknown

CVE-2024-51560

Disclosure Date: November 04, 2024 (last updated November 09, 2024)
This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at certain API endpoint. An authenticated remote attacker could exploit this vulnerability by providing invalid inputs for “userId” parameter in the API request leading to generation of error message containing sensitive information on the targeted system.
Attacker Value
Unknown

CVE-2024-51559

Disclosure Date: November 04, 2024 (last updated November 22, 2024)
This vulnerability exists in the Wave 2.0 due to improper authorization checks on certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters to gain unauthorized access and perform malicious activities on other user accounts.
Attacker Value
Unknown

CVE-2024-51558

Disclosure Date: November 04, 2024 (last updated November 09, 2024)
This vulnerability exists in the Wave 2.0 due to missing restrictions for excessive failed authentication attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack against legitimate user OTP, MPIN or password, which could lead to gain unauthorized access and compromise other user accounts.
Attacker Value
Unknown

CVE-2024-51557

Disclosure Date: November 04, 2024 (last updated November 09, 2024)
This vulnerability exists in the Wave 2.0 due to missing rate limiting on OTP requests in an API endpoint. An authenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoint which could lead to the OTP bombing/flooding on the targeted system.
Attacker Value
Unknown

CVE-2024-51556

Disclosure Date: November 04, 2024 (last updated November 22, 2024)
This vulnerability exists in the Wave 2.0 due to insufficient encryption of sensitive data received at the API response. An authenticated remote attacker could exploit this vulnerability by manipulating API input parameters through API request URL/payload leading to unauthorized access to sensitive information belonging to other users.
Attacker Value
Unknown

CVE-2024-48257

Disclosure Date: October 14, 2024 (last updated October 17, 2024)
Wavelog 1.8.5 allows Oqrs_model.php get_worked_modes station_id SQL injectioin.
Attacker Value
Unknown

CVE-2024-48251

Disclosure Date: October 14, 2024 (last updated October 17, 2024)
Wavelog 1.8.5 allows Activated_gridmap_model.php get_band_confirmed SQL injection via band, sat, propagation, or mode.