Show filters
278 Total Results
Displaying 11-20 of 278
Sort by:
Attacker Value
Unknown

CVE-2024-11328

Disclosure Date: January 09, 2025 (last updated January 09, 2025)
The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.13.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2024-11444

Disclosure Date: December 06, 2024 (last updated December 21, 2024)
The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.13.2. This is due to missing or incorrect nonce validation on the cluevo_render_module_ui() function. This makes it possible for unauthenticated attackers to delete modules via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2024-12196

Disclosure Date: December 04, 2024 (last updated December 21, 2024)
Incorrect authorization in the permission component in Devolutions Server 2024.3.7.0 and earlier allows an authenticated user to view the password history of an entry without the view password permission.
0
Attacker Value
Unknown

CVE-2024-12151

Disclosure Date: December 04, 2024 (last updated December 21, 2024)
Incorrect permission assignment in the user migration feature in Devolutions Server 2024.3.8.0 and earlier allows users to retain their old permission sets.
0
Attacker Value
Unknown

CVE-2024-12149

Disclosure Date: December 04, 2024 (last updated December 21, 2024)
Incorrect permission assignment in temporary access requests component in Devolutions Remote Desktop Manager 2024.3.19.0 and earlier on Windows allows an authenticated user that request temporary permissions on an entry to obtain more privileges than requested.
0
Attacker Value
Unknown

CVE-2024-12148

Disclosure Date: December 04, 2024 (last updated December 21, 2024)
Incorrect authorization in permission validation component in Devolutions Server 2024.3.6.0 and earlier allows an authenticated user to access some reporting endpoints.
0
Attacker Value
Unknown

CVE-2024-53757

Disclosure Date: November 30, 2024 (last updated December 21, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SocialEvolution WP Find Your Nearest allows Stored XSS.This issue affects WP Find Your Nearest: from n/a through 0.3.1.
0
Attacker Value
Unknown

CVE-2024-11862

Disclosure Date: November 27, 2024 (last updated December 21, 2024)
Non constant time cryptographic operation in Devolutions.XTS.NET 2024.11.19 and earlier allows an attacker to render half of the encryption key obsolete via a timing attacks
0
Attacker Value
Unknown

CVE-2024-11672

Disclosure Date: November 25, 2024 (last updated January 05, 2025)
Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an authenticated malicious user to bypass the "Add" permission via the import in vault feature.
0
Attacker Value
Unknown

CVE-2024-11671

Disclosure Date: November 25, 2024 (last updated January 05, 2025)
Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an authenticated user to bypass the MFA validation via data source switching.
0