Show filters
121 Total Results
Displaying 11-20 of 121
Sort by:
Attacker Value
Unknown
CVE-2024-7107
Disclosure Date: September 26, 2024 (last updated October 03, 2024)
Files or Directories Accessible to External Parties vulnerability in National Keep Cyber Security Services CyberMath allows Collect Data from Common Resource Locations.This issue affects CyberMath: before CYBM.240816253.
0
Attacker Value
Unknown
CVE-2022-3459
Disclosure Date: September 14, 2024 (last updated September 28, 2024)
The WooCommerce Multiple Free Gift plugin for WordPress is vulnerable to gift manipulation in all versions up to, and including, 1.2.3. This is due to plugin not enforcing server-side checks on the products that can be added as a gift. This makes it possible for unauthenticated attackers to add non-gift items to their cart as a gift.
0
Attacker Value
Unknown
CVE-2024-45390
Disclosure Date: September 03, 2024 (last updated September 13, 2024)
@blakeembrey/template is a string template library. Prior to version 1.2.0, it is possible to inject and run code within the template if the attacker has access to write the template name. Version 1.2.0 contains a patch. As a workaround, don't pass untrusted input as the template display name, or don't use the display name feature.
0
Attacker Value
Unknown
CVE-2024-42466
Disclosure Date: August 16, 2024 (last updated August 29, 2024)
Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Abuse.This issue affects upKeeper Manager: through 5.1.9.
0
Attacker Value
Unknown
CVE-2024-42465
Disclosure Date: August 16, 2024 (last updated August 29, 2024)
Improper Restriction of Excessive Authentication Attempts vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Abuse.This issue affects upKeeper Manager: through 5.1.9.
0
Attacker Value
Unknown
CVE-2024-42464
Disclosure Date: August 16, 2024 (last updated August 29, 2024)
Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Utilizing REST's Trust in the System Resource to Obtain Sensitive Data.This issue affects upKeeper Manager: through 5.1.9.
0
Attacker Value
Unknown
CVE-2024-42463
Disclosure Date: August 16, 2024 (last updated August 29, 2024)
Authorization Bypass Through User-Controlled Key vulnerability in upKeeper Solutions product upKeeper Manager allows Utilizing REST's Trust in the System Resource to Obtain Sensitive Data.This issue affects upKeeper Manager: through 5.1.9.
0
Attacker Value
Unknown
CVE-2024-42462
Disclosure Date: August 16, 2024 (last updated August 29, 2024)
Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This issue affects upKeeper Manager: through 5.1.9.
0
Attacker Value
Unknown
CVE-2024-4022
Disclosure Date: April 21, 2024 (last updated April 22, 2024)
A vulnerability was found in Keenetic KN-1010, KN-1410, KN-1711, KN-1810 and KN-1910 up to 4.1.2.15. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /version.js of the component Version Data Handler. The manipulation leads to information disclosure. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-261674 is the identifier assigned to this vulnerability. NOTE: The vendor is aware of this issue and plans to fix it by the end of 2024.
0
Attacker Value
Unknown
CVE-2024-4021
Disclosure Date: April 21, 2024 (last updated April 22, 2024)
A vulnerability was found in Keenetic KN-1010, KN-1410, KN-1711, KN-1810 and KN-1910 up to 4.1.2.15. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /ndmComponents.js of the component Configuration Setting Handler. The manipulation leads to information disclosure. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-261673 was assigned to this vulnerability. NOTE: The vendor is aware of this issue and plans to fix it by the end of 2024.
0