Show filters
99 Total Results
Displaying 11-20 of 99
Sort by:
Attacker Value
Unknown
CVE-2024-42482
Disclosure Date: August 12, 2024 (last updated September 18, 2024)
fish-shop/syntax-check is a GitHub action for syntax checking fish shell files. Improper neutralization of delimiters in the `pattern` input (specifically the command separator `;` and command substitution characters `(` and `)`) mean that arbitrary command injection is possible by modification of the input value used in a workflow. This has the potential for exposure or exfiltration of sensitive information from the workflow runner, such as might be achieved by sending environment variables to an external entity. It is recommended that users update to the patched version `v1.6.12` or the latest release version `v2.0.0`, however remediation may be possible through careful control of workflows and the `pattern` input value used by this action.
0
Attacker Value
Unknown
CVE-2024-32947
Disclosure Date: April 24, 2024 (last updated April 25, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in AlumniOnline Web Services LLC WP ADA Compliance Check Basic.This issue affects WP ADA Compliance Check Basic: from n/a through 3.1.3.
0
Attacker Value
Unknown
CVE-2024-0866
Disclosure Date: March 26, 2024 (last updated April 02, 2024)
The Check & Log Email plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including, 1.0.9 via the check_nonce function. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress under certain circumstances. The action the attacker wishes to execute needs to have a nonce check, and the nonce needs to be known to the attacker. Furthermore, the absence of a capability check is a requirement.
0
Attacker Value
Unknown
CVE-2024-28153
Disclosure Date: March 06, 2024 (last updated January 19, 2025)
Jenkins OWASP Dependency-Check Plugin 5.4.5 and earlier does not escape vulnerability metadata from Dependency-Check reports, resulting in a stored cross-site scripting (XSS) vulnerability.
0
Attacker Value
Unknown
CVE-2024-22143
Disclosure Date: January 31, 2024 (last updated February 03, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in WP Spell Check.This issue affects WP Spell Check: from n/a through 9.17.
0
Attacker Value
Unknown
CVE-2024-22380
Disclosure Date: January 24, 2024 (last updated January 31, 2024)
Electronic Delivery Check System (Ministry of Agriculture, Forestry and Fisheries The Agriculture and Rural Development Project Version) March, Heisei 31 era edition Ver.14.0.001.002 and earlier improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.
0
Attacker Value
Unknown
CVE-2024-21765
Disclosure Date: January 24, 2024 (last updated January 31, 2024)
Electronic Delivery Check System (Doboku) Ver.18.1.0 and earlier, Electronic Delivery Check System (Dentsu) Ver.12.1.0 and earlier, Electronic Delivery Check System (Kikai) Ver.10.1.0 and earlier, and Electronic delivery item Inspection Support SystemVer.4.0.31 and earlier improperly restrict XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.
0
Attacker Value
Unknown
CVE-2024-23686
Disclosure Date: January 19, 2024 (last updated January 27, 2024)
DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows an attacker to recover the NVD API Key from a log file.
0
Attacker Value
Unknown
CVE-2023-39619
Disclosure Date: October 25, 2023 (last updated November 01, 2023)
ReDos in NPMJS Node Email Check v.1.0.4 allows an attacker to cause a denial of service via a crafted string to the scpSyntax component.
0
Attacker Value
Unknown
CVE-2023-39070
Disclosure Date: September 11, 2023 (last updated October 08, 2023)
An issue in Cppcheck 2.12 dev allows a local attacker to execute arbitrary code via the removeContradiction parameter in token.cpp:1934.
0