Show filters
1,231 Total Results
Displaying 11-20 of 1,231
Sort by:
Attacker Value
Unknown
CVE-2024-55193
Disclosure Date: January 23, 2025 (last updated January 30, 2025)
OpenImageIO v3.1.0.0dev was discovered to contain a segmentation violation via the component /OpenImageIO/string_view.h.
0
Attacker Value
Unknown
CVE-2024-55192
Disclosure Date: January 23, 2025 (last updated January 30, 2025)
OpenImageIO v3.1.0.0dev was discovered to contain a heap overflow via the component OpenImageIO_v3_1_0::farmhash::inlined::Fetch64(char const*).
0
Attacker Value
Unknown
CVE-2025-22737
Disclosure Date: January 15, 2025 (last updated January 16, 2025)
Missing Authorization vulnerability in MagePeople Team WpTravelly allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WpTravelly: from n/a through 1.8.5.
0
Attacker Value
Unknown
CVE-2024-12412
Disclosure Date: January 11, 2025 (last updated January 12, 2025)
The Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently | WordPress plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘active_tab’ parameter in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-49294
Disclosure Date: January 07, 2025 (last updated January 07, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in MagePeople Team Bus Ticket Booking with Seat Reservation allows Cross Site Request Forgery.This issue affects Bus Ticket Booking with Seat Reservation: from n/a through 5.4.3.
0
Attacker Value
Unknown
CVE-2024-54266
Disclosure Date: December 13, 2024 (last updated January 13, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ImageRecycle ImageRecycle pdf & image compression allows Reflected XSS.This issue affects ImageRecycle pdf & image compression: from n/a through 3.1.16.
0
Attacker Value
Unknown
CVE-2024-50584
Disclosure Date: December 12, 2024 (last updated December 18, 2024)
An authenticated attacker with the user/role "Poweruser" can perform an SQL injection by accessing the /class/template_io.php file and supplying malicious GET parameters. The "templates" parameter is vulnerable against blind boolean-based SQL injection attacks. SQL syntax must be injected into the JSON syntax of the templates parameter.
0
Attacker Value
Unknown
CVE-2024-28146
Disclosure Date: December 12, 2024 (last updated December 18, 2024)
The application uses several hard-coded credentials to encrypt config files during backup, to decrypt the new firmware during an update and some passwords allow a direct connection to the database server of the affected device.
0
Attacker Value
Unknown
CVE-2024-28145
Disclosure Date: December 12, 2024 (last updated December 18, 2024)
An unauthenticated attacker can perform an SQL injection by accessing the /class/dbconnect.php file and supplying malicious GET parameters. The HTTP GET parameters search, table, field, and value are vulnerable. For example, one SQL injection can be performed on the parameter "field" with the UNION keyword.
0
Attacker Value
Unknown
CVE-2024-28144
Disclosure Date: December 12, 2024 (last updated December 18, 2024)
An attacker who can spoof the IP address and the User-Agent of a logged-in user can takeover the session because of flaws in the self-developed session management. If two users access the web interface from the same IP they are logged in as the other user.
0