Show filters
224 Total Results
Displaying 11-20 of 224
Sort by:
Attacker Value
Unknown
CVE-2024-56236
Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Missing Authorization vulnerability in Jakob Bouchard Hestia Nginx Cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hestia Nginx Cache: from n/a through 2.4.0.
0
Attacker Value
Unknown
CVE-2024-12103
Disclosure Date: December 24, 2024 (last updated January 05, 2025)
The Content No Cache: prevent specific content from being cached plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 0.1.2 via the eos_dyn_get_content action due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password protected, private, or draft posts that they should not have access to.
0
Attacker Value
Unknown
CVE-2024-12628
Disclosure Date: December 14, 2024 (last updated December 18, 2024)
The bodi0`s Easy cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cache-folder' parameter in all versions up to, and including, 0.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
0
Attacker Value
Unknown
CVE-2023-1521
Disclosure Date: November 26, 2024 (last updated December 21, 2024)
On Linux the sccache client can execute arbitrary code with the privileges of a local sccache server, by preloading the code in a shared library passed to LD_PRELOAD.
If the server is run as root (which is the default when installing the snap package https://snapcraft.io/sccache ), this means a user running the sccache client can get root privileges.
0
Attacker Value
Unknown
CVE-2024-49505
Disclosure Date: November 13, 2024 (last updated November 15, 2024)
A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in openSUSE Tumbleweed MirrorCache allows the execution of arbitrary JS via reflected XSS in the REGEX and P parameters.
This issue affects MirrorCache before 1.083.
0
Attacker Value
Unknown
CVE-2024-43260
Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in Creative Motion Clearfy Cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clearfy Cache: from n/a through 2.2.4.
0
Attacker Value
Unknown
CVE-2024-43119
Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in Aruba.It Aruba HiSpeed Cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Aruba HiSpeed Cache: from n/a through 2.0.12.
0
Attacker Value
Unknown
CVE-2024-50550
Disclosure Date: October 29, 2024 (last updated October 29, 2024)
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Privilege Escalation.This issue affects LiteSpeed Cache: from n/a through 6.5.1.
0
Attacker Value
Unknown
CVE-2024-47637
Disclosure Date: October 16, 2024 (last updated October 17, 2024)
: Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Path Traversal.This issue affects LiteSpeed Cache: from n/a through 6.4.1.
0
Attacker Value
Unknown
CVE-2020-36836
Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and including, 0.9.0.2 due to a lack of capability checking and insufficient path validation. This makes it possible for authenticated users with minimal permissions to delete arbitrary files from the server.
0