Show filters
224 Total Results
Displaying 11-20 of 224
Sort by:
Attacker Value
Unknown

CVE-2024-56236

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Missing Authorization vulnerability in Jakob Bouchard Hestia Nginx Cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hestia Nginx Cache: from n/a through 2.4.0.
0
Attacker Value
Unknown

CVE-2024-12103

Disclosure Date: December 24, 2024 (last updated January 05, 2025)
The Content No Cache: prevent specific content from being cached plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 0.1.2 via the eos_dyn_get_content action due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to extract data from password protected, private, or draft posts that they should not have access to.
Attacker Value
Unknown

CVE-2024-12628

Disclosure Date: December 14, 2024 (last updated December 18, 2024)
The bodi0`s Easy cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cache-folder' parameter in all versions up to, and including, 0.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Attacker Value
Unknown

CVE-2023-1521

Disclosure Date: November 26, 2024 (last updated December 21, 2024)
On Linux the sccache client can execute arbitrary code with the privileges of a local sccache server, by preloading the code in a shared library passed to LD_PRELOAD. If the server is run as root (which is the default when installing the snap package https://snapcraft.io/sccache ), this means a user running the sccache client can get root privileges.
0
Attacker Value
Unknown

CVE-2024-49505

Disclosure Date: November 13, 2024 (last updated November 15, 2024)
A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in openSUSE Tumbleweed MirrorCache allows the execution of arbitrary JS via reflected XSS in the  REGEX and P parameters. This issue affects MirrorCache before 1.083.
Attacker Value
Unknown

CVE-2024-43260

Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in Creative Motion Clearfy Cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clearfy Cache: from n/a through 2.2.4.
0
Attacker Value
Unknown

CVE-2024-43119

Disclosure Date: November 01, 2024 (last updated November 02, 2024)
Missing Authorization vulnerability in Aruba.It Aruba HiSpeed Cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Aruba HiSpeed Cache: from n/a through 2.0.12.
0
Attacker Value
Unknown

CVE-2024-50550

Disclosure Date: October 29, 2024 (last updated October 29, 2024)
Incorrect Privilege Assignment vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Privilege Escalation.This issue affects LiteSpeed Cache: from n/a through 6.5.1.
0
Attacker Value
Unknown

CVE-2024-47637

Disclosure Date: October 16, 2024 (last updated October 17, 2024)
: Relative Path Traversal vulnerability in LiteSpeed Technologies LiteSpeed Cache allows Path Traversal.This issue affects LiteSpeed Cache: from n/a through 6.4.1.
0
Attacker Value
Unknown

CVE-2020-36836

Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized arbitrary file deletion in versions up to, and including, 0.9.0.2 due to a lack of capability checking and insufficient path validation. This makes it possible for authenticated users with minimal permissions to delete arbitrary files from the server.
0