Show filters
303 Total Results
Displaying 11-20 of 303
Sort by:
Attacker Value
Unknown
CVE-2025-22348
Disclosure Date: January 07, 2025 (last updated January 07, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RTO GmbH DynamicTags allows Blind SQL Injection.This issue affects DynamicTags: from n/a through 1.4.0.
0
Attacker Value
Unknown
CVE-2024-11808
Disclosure Date: December 21, 2024 (last updated December 21, 2024)
The Pingmeter Uptime Monitoring plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_wpnonce' parameter in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
0
Attacker Value
Unknown
CVE-2024-38864
Disclosure Date: December 19, 2024 (last updated December 20, 2024)
Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p23, < 2.2.0p38 and <= 2.1.0p49 (EOL) allows a local attacker to read sensitive data.
0
Attacker Value
Unknown
CVE-2024-54229
Disclosure Date: December 16, 2024 (last updated December 18, 2024)
Incorrect Privilege Assignment vulnerability in Straightvisions GmbH SV100 Companion allows Privilege Escalation.This issue affects SV100 Companion: from n/a through 2.0.02.
0
Attacker Value
Unknown
CVE-2024-56011
Disclosure Date: December 16, 2024 (last updated December 18, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ilja Zaglov | IMBAA GmbH Responsive Google Maps | by imbaa allows Stored XSS.This issue affects Responsive Google Maps | by imbaa: from n/a through 1.2.5.
0
Attacker Value
Unknown
CVE-2024-54259
Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DELUCKS GmbH DELUCKS SEO allows Path Traversal.This issue affects DELUCKS SEO: from n/a through 2.5.5.
0
Attacker Value
Unknown
CVE-2023-34381
Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Missing Authorization vulnerability in Gesundheit Bewegt GmbH Zippy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zippy: from n/a through 1.6.2.
0
Attacker Value
Unknown
CVE-2024-50584
Disclosure Date: December 12, 2024 (last updated December 18, 2024)
An authenticated attacker with the user/role "Poweruser" can perform an SQL injection by accessing the /class/template_io.php file and supplying malicious GET parameters. The "templates" parameter is vulnerable against blind boolean-based SQL injection attacks. SQL syntax must be injected into the JSON syntax of the templates parameter.
0
Attacker Value
Unknown
CVE-2024-28146
Disclosure Date: December 12, 2024 (last updated December 18, 2024)
The application uses several hard-coded credentials to encrypt config files during backup, to decrypt the new firmware during an update and some passwords allow a direct connection to the database server of the affected device.
0
Attacker Value
Unknown
CVE-2024-28145
Disclosure Date: December 12, 2024 (last updated December 18, 2024)
An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, and value are vulnerable. For example, one SQL injection can be performed on the parameter "field" with the UNION keyword.
0