Show filters
46 Total Results
Displaying 11-20 of 46
Sort by:
Attacker Value
Unknown
CVE-2024-10625
Disclosure Date: November 09, 2024 (last updated January 06, 2025)
The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_tmp_uploaded_file() function in all versions up to, and including, 17.7. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
0
Attacker Value
Unknown
CVE-2024-2478
Disclosure Date: March 15, 2024 (last updated January 24, 2025)
A vulnerability was found in BradWenqiang HR 2.0. It has been rated as critical. Affected by this issue is the function selectAll of the file /bishe/register of the component Background Management. The manipulation of the argument userName leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-256886 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2023-4792
Disclosure Date: September 07, 2023 (last updated November 09, 2023)
The Duplicate Post Page Menu & Custom Post Type plugin for WordPress is vulnerable to unauthorized page and post duplication due to a missing capability check on the duplicate_ppmc_post_as_draft function in versions up to, and including, 2.3.1. This makes it possible for authenticated attackers with subscriber access or higher to duplicate posts and pages.
0
Attacker Value
Unknown
CVE-2023-32571
Disclosure Date: June 22, 2023 (last updated October 08, 2023)
Dynamic Linq 1.0.7.10 through 1.2.25 before 1.3.0 allows attackers to execute arbitrary code and commands when untrusted input to methods including Where, Select, OrderBy is parsed.
0
Attacker Value
Unknown
CVE-2022-30350
Disclosure Date: March 30, 2023 (last updated October 08, 2023)
Avanquest Software RAD PDF (PDFEscape Online) 3.19.2.2 is vulnerable to Information Leak / Disclosure. The PDFEscape Online tool provides users with a "white out" functionality for redacting images, text, and other graphics from a PDF document. However, this mechanism does not remove underlying text or PDF object specification information from the PDF. As a result, for example, redacted text may be copy-pasted by a PDF reader.
0
Attacker Value
Unknown
CVE-2021-25116
Disclosure Date: June 13, 2022 (last updated October 07, 2023)
The Enqueue Anything WordPress plugin through 1.0.1 does not have authorisation and CSRF checks in the remove_asset AJAX action, and does not ensure that the item to be deleted is actually an asset. As a result, low privilege users such as subscriber could delete arbitrary assets, as well as put arbitrary posts in the trash.
0
Attacker Value
Unknown
CVE-2021-41591
Disclosure Date: October 04, 2021 (last updated February 23, 2025)
ACINQ Eclair before 0.6.3 allows loss of funds because of dust HTLC exposure.
0
Attacker Value
Unknown
CVE-2021-37911
Disclosure Date: August 30, 2021 (last updated February 23, 2025)
The management interface of BenQ smart wireless conference projector does not properly control user's privilege. Attackers can access any system directory of this device through the interface and execute arbitrary commands if he enters the local subnetwork.
0
Attacker Value
Unknown
CVE-2021-38608
Disclosure Date: August 16, 2021 (last updated February 23, 2025)
Incorrect Access Control in Tranquil WAPT Enterprise - before 1.8.2.7373 and before 2.0.0.9450 allows guest OS users to escalate privileges via WAPT Agent.
0
Attacker Value
Unknown
CVE-2020-36437
Disclosure Date: August 08, 2021 (last updated February 23, 2025)
An issue was discovered in the conqueue crate before 0.4.0 for Rust. There are unconditional implementations of Send and Sync for QueueSender<T>.
0