Show filters
303 Total Results
Displaying 11-20 of 303
Sort by:
Attacker Value
Unknown

CVE-2025-22348

Disclosure Date: January 07, 2025 (last updated January 07, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RTO GmbH DynamicTags allows Blind SQL Injection.This issue affects DynamicTags: from n/a through 1.4.0.
0
Attacker Value
Unknown

CVE-2024-11808

Disclosure Date: December 21, 2024 (last updated December 21, 2024)
The Pingmeter Uptime Monitoring plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_wpnonce' parameter in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2024-38864

Disclosure Date: December 19, 2024 (last updated December 20, 2024)
Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p23, < 2.2.0p38 and <= 2.1.0p49 (EOL) allows a local attacker to read sensitive data.
0
Attacker Value
Unknown

CVE-2024-54229

Disclosure Date: December 16, 2024 (last updated December 18, 2024)
Incorrect Privilege Assignment vulnerability in Straightvisions GmbH SV100 Companion allows Privilege Escalation.This issue affects SV100 Companion: from n/a through 2.0.02.
0
Attacker Value
Unknown

CVE-2024-56011

Disclosure Date: December 16, 2024 (last updated December 18, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ilja Zaglov | IMBAA GmbH Responsive Google Maps | by imbaa allows Stored XSS.This issue affects Responsive Google Maps | by imbaa: from n/a through 1.2.5.
0
Attacker Value
Unknown

CVE-2024-54259

Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in DELUCKS GmbH DELUCKS SEO allows Path Traversal.This issue affects DELUCKS SEO: from n/a through 2.5.5.
0
Attacker Value
Unknown

CVE-2023-34381

Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Missing Authorization vulnerability in Gesundheit Bewegt GmbH Zippy allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Zippy: from n/a through 1.6.2.
0
Attacker Value
Unknown

CVE-2024-50584

Disclosure Date: December 12, 2024 (last updated December 18, 2024)
An authenticated attacker with the user/role "Poweruser" can perform an SQL injection by accessing the /class/template_io.php file and supplying malicious GET parameters. The "templates" parameter is vulnerable against blind boolean-based SQL injection attacks. SQL syntax must be injected into the JSON syntax of the templates parameter.
0
Attacker Value
Unknown

CVE-2024-28146

Disclosure Date: December 12, 2024 (last updated December 18, 2024)
The application uses several hard-coded credentials to encrypt config files during backup, to decrypt the new firmware during an update and some passwords allow a direct connection to the database server of the affected device.
0
Attacker Value
Unknown

CVE-2024-28145

Disclosure Date: December 12, 2024 (last updated December 18, 2024)
An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, and value are vulnerable. For example, one SQL injection can be performed on the parameter "field" with the UNION keyword.
0