Show filters
436 Total Results
Displaying 11-20 of 436
Sort by:
Attacker Value
Unknown

CVE-2024-12047

Disclosure Date: January 04, 2025 (last updated January 05, 2025)
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘custom_server’ parameter in all versions up to, and including, 6.30.03 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2024-37511

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in SWTE Swift Performance Lite allows Cross Site Request Forgery.This issue affects Swift Performance Lite: from n/a through 2.3.6.20.
0
Attacker Value
Unknown

CVE-2024-11597

Disclosure Date: December 11, 2024 (last updated January 24, 2025)
Under specific circumstances, insecure permissions in Ivanti Performance Manager before version 2024.3 HF1, 2024.1 HF1, or 2023.3 HF1 allows a local authenticated attacker to achieve local privilege escalation.
Attacker Value
Unknown

CVE-2024-10516

Disclosure Date: December 06, 2024 (last updated December 21, 2024)
The Swift Performance Lite plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 2.3.7.1 via the 'ajaxify' function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
0
Attacker Value
Unknown

CVE-2024-46956

Disclosure Date: November 10, 2024 (last updated November 15, 2024)
An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.
Attacker Value
Unknown

CVE-2024-46955

Disclosure Date: November 10, 2024 (last updated November 14, 2024)
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space.
Attacker Value
Unknown

CVE-2024-46953

Disclosure Date: November 10, 2024 (last updated November 14, 2024)
An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.
Attacker Value
Unknown

CVE-2024-46951

Disclosure Date: November 10, 2024 (last updated November 14, 2024)
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.
Attacker Value
Unknown

CVE-2024-22034

Disclosure Date: October 16, 2024 (last updated October 17, 2024)
Attackers could put the special files in .osc into the actual package sources (e.g. _apiurl). This allows the attacker to change the configuration of osc for the victim
0
Attacker Value
Unknown

CVE-2024-22029

Disclosure Date: October 16, 2024 (last updated October 17, 2024)
Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root
0