Show filters
101 Total Results
Displaying 11-20 of 101
Sort by:
Attacker Value
Unknown
CVE-2024-47396
Disclosure Date: October 01, 2024 (last updated January 23, 2025)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in moveaddons Move Addons for Elementor allows Stored XSS.This issue affects Move Addons for Elementor: from n/a through 1.3.3.
0
Attacker Value
Unknown
CVE-2024-6576
Disclosure Date: July 29, 2024 (last updated July 30, 2024)
Improper Authentication vulnerability in Progress MOVEit Transfer (SFTP module) can lead to Privilege Escalation.This issue affects MOVEit Transfer: from 2023.0.0 before 2023.0.12, from 2023.1.0 before 2023.1.7, from 2024.0.0 before 2024.0.3.
0
Attacker Value
Unknown
CVE-2024-5855
Disclosure Date: July 09, 2024 (last updated January 05, 2025)
The Media Hygiene: Remove or Delete Unused Images and More! plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the bulk_action_delete and delete_single_image_call AJAX actions in all versions up to, and including, 3.0.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary attachments. A nonce check was added in version 3.0.1, however, it wasn't until version 3.0.2 that a capability check was added.
0
Attacker Value
Unknown
CVE-2024-5805
Disclosure Date: June 25, 2024 (last updated August 21, 2024)
Improper Authentication vulnerability in Progress MOVEit Gateway (SFTP modules) allows Authentication Bypass.This issue affects MOVEit Gateway: 2024.0.0.
0
Attacker Value
Unknown
CVE-2024-35252
Disclosure Date: June 11, 2024 (last updated January 12, 2025)
Azure Storage Movement Client Library Denial of Service Vulnerability
0
Attacker Value
Unknown
CVE-2024-25092
Disclosure Date: June 09, 2024 (last updated October 12, 2024)
Missing Authorization vulnerability in XLPlugins NextMove Lite.This issue affects NextMove Lite: from n/a through 2.17.0.
0
Attacker Value
Unknown
CVE-2024-30525
Disclosure Date: June 04, 2024 (last updated June 12, 2024)
Missing Authorization vulnerability in moveaddons Move Addons for Elementor.This issue affects Move Addons for Elementor: from n/a through 1.2.9.
0
Attacker Value
Unknown
CVE-2024-4563
Disclosure Date: May 22, 2024 (last updated January 12, 2025)
The Progress MOVEit Automation configuration export function prior to 2024.0.0 uses a cryptographic method with insufficient bit length.
0
Attacker Value
Unknown
CVE-2024-4695
Disclosure Date: May 21, 2024 (last updated January 25, 2025)
The Move Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widgets in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-2846
Disclosure Date: May 14, 2024 (last updated January 05, 2025)
The Visual Footer Credit Remover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'selector' parameter in all versions up to, and including, 2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
0