Show filters
573 Total Results
Displaying 11-20 of 573
Sort by:
Attacker Value
Unknown
CVE-2024-13454
Disclosure Date: January 20, 2025 (last updated January 21, 2025)
Weak encryption algorithm in Easy-RSA version 3.0.5 through 3.1.7 allows a local attacker to more easily bruteforce the private CA key when created using OpenSSL 3
0
Attacker Value
Unknown
CVE-2025-23483
Disclosure Date: January 16, 2025 (last updated January 17, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Niklas Olsson Universal Analytics Injector allows Stored XSS.This issue affects Universal Analytics Injector: from n/a through 1.0.3.
0
Attacker Value
Unknown
CVE-2025-22813
Disclosure Date: January 09, 2025 (last updated January 10, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ChatBot for WordPress - WPBot Conversational Forms for ChatBot allows Stored XSS.This issue affects Conversational Forms for ChatBot: from n/a through 1.4.2.
0
Attacker Value
Unknown
CVE-2024-11826
Disclosure Date: January 07, 2025 (last updated January 28, 2025)
The Quill Forms | The Best Typeform Alternative | Create Conversational Multi Step Form, Survey, Quiz, Cost Estimation or Donation Form on WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'quillforms-popup' shortcode in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-12652
Disclosure Date: December 26, 2024 (last updated January 05, 2025)
A Improper Control of Generation of Code ('Code Injection') vulnerability in groovy script function in SmartRobot′s Conversational AI Platform before v7.2.0 allows remote authenticated users to perform arbitrary system commands via Groovy code.
0
Attacker Value
Unknown
CVE-2024-54327
Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in universam UNIVERSAM allows Reflected XSS.This issue affects UNIVERSAM: from n/a through n/a.
0
Attacker Value
Unknown
CVE-2024-52959
Disclosure Date: November 27, 2024 (last updated December 21, 2024)
A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to perform arbitrary system commands via a DLL file.
0
Attacker Value
Unknown
CVE-2024-52958
Disclosure Date: November 27, 2024 (last updated December 21, 2024)
A improper verification of cryptographic signature vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to load a malicious DLL via upload plugin function.
0
Attacker Value
Unknown
CVE-2024-9419
Disclosure Date: October 30, 2024 (last updated October 31, 2024)
Client / Server PCs with the HP Smart Universal Printing Driver installed are potentially vulnerable to Remote Code Execution and/or Elevation of Privilege. A client using the HP Smart Universal Printing Driver that sends a print job comprised of a malicious XPS file could potentially lead to Remote Code Execution and/or Elevation of Privilege on the PC.
0
Attacker Value
Unknown
CVE-2024-6333
Disclosure Date: October 17, 2024 (last updated October 18, 2024)
Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products.
0