Show filters
174 Total Results
Displaying 11-20 of 174
Sort by:
Attacker Value
Unknown

CVE-2024-43791

Disclosure Date: August 23, 2024 (last updated September 13, 2024)
RequestStore provides per-request global storage for Rack. The files published as part of request_store 1.3.2 have 0666 permissions, meaning that they are world-writable, which allows local users to execute arbitrary code. This version was published in 2017, and most production environments do not allow access for local users, so the chances of this being exploited are very low, given that the vast majority of users will have upgraded, and those that have not, if any, are not likely to be exposed.
Attacker Value
Unknown

CVE-2024-6231

Disclosure Date: July 23, 2024 (last updated July 23, 2024)
The Request a Quote WordPress plugin before 2.4.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown

CVE-2023-37870

Disclosure Date: June 19, 2024 (last updated June 20, 2024)
Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.1.9.
0
Attacker Value
Unknown

CVE-2023-51496

Disclosure Date: June 14, 2024 (last updated August 08, 2024)
Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.2.7.
Attacker Value
Unknown

CVE-2023-51495

Disclosure Date: June 14, 2024 (last updated August 08, 2024)
Missing Authorization vulnerability in Woo WooCommerce Warranty Requests.This issue affects WooCommerce Warranty Requests: from n/a through 2.2.7.
Attacker Value
Unknown

CVE-2024-35195

Disclosure Date: May 20, 2024 (last updated May 21, 2024)
Requests is a HTTP library. Prior to 2.32.0, when making requests through a Requests `Session`, if the first request is made with `verify=False` to disable cert verification, all subsequent requests to the same host will continue to ignore cert verification regardless of changes to the value of `verify`. This behavior will continue for the lifecycle of the connection in the connection pool. This vulnerability is fixed in 2.32.0.
0
Attacker Value
Unknown

CVE-2024-22382

Disclosure Date: May 16, 2024 (last updated May 17, 2024)
Improper input validation in PprRequestLog module in UEFI firmware for some Intel(R) Server D50DNP Family products may allow a privileged user to enable escalation of privilege via local access.
0
Attacker Value
Unknown

CVE-2024-32731

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
SAP My Travel Requests does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. On successful exploitation, the attacker can upload a malicious attachment to a business trip request which will lead to a low impact on the confidentiality, integrity and availability of the application. 
0
Attacker Value
Unknown

CVE-2024-3262

Disclosure Date: April 04, 2024 (last updated April 10, 2024)
Information exposure vulnerability in RT software affecting version 4.4.1. This vulnerability allows an attacker with local access to the device to retrieve sensitive information about the application, such as vulnerability tickets, because the application stores the information in the browser cache, leading to information exposure despite session termination.
0
Attacker Value
Unknown

CVE-2024-24836

Disclosure Date: February 08, 2024 (last updated February 15, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Audrasjb GDPR Data Request Form allows Stored XSS.This issue affects GDPR Data Request Form: from n/a through 1.6.