Show filters
2,041 Total Results
Displaying 101-110 of 2,041
Sort by:
Attacker Value
Unknown

CVE-2024-12686

Disclosure Date: December 18, 2024 (last updated January 15, 2025)
A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user.
Attacker Value
Unknown

CVE-2024-11295

Disclosure Date: December 18, 2024 (last updated December 18, 2024)
The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.29 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as logged-in users.
Attacker Value
Unknown

CVE-2024-8326

Disclosure Date: December 17, 2024 (last updated December 18, 2024)
The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 241114 via the 'sc_get_details' function. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive data including user data and database configuration information, which can lead to reading, updating, or dropping database tables. The vulnerability was partially patched in version 241114.
Attacker Value
Unknown

CVE-2024-6001

Disclosure Date: December 16, 2024 (last updated December 18, 2024)
An improper certificate validation vulnerability was reported in LADM that could allow a network attacker with the ability to redirect an update request to a remote server and execute code with elevated privileges.
Attacker Value
Unknown

CVE-2024-4762

Disclosure Date: December 16, 2024 (last updated December 18, 2024)
An improper validation vulnerability was reported in the firmware update mechanism of LADM and LDCC that could allow a local attacker to escalate privileges.
Attacker Value
Unknown

CVE-2023-41869

Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Missing Authorization vulnerability in Alex Volkov WP Accessibility Helper (WAH) allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Accessibility Helper (WAH): from n/a through 0.6.2.4.
0
Attacker Value
Unknown

CVE-2024-49142

Disclosure Date: December 12, 2024 (last updated January 18, 2025)
Microsoft Access Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2024-11351

Disclosure Date: December 11, 2024 (last updated December 21, 2024)
The Restrict – membership, site, content and user access restrictions for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.8 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-level roles such as administrator.
Attacker Value
Unknown

CVE-2024-11643

Disclosure Date: December 04, 2024 (last updated December 21, 2024)
The Accessibility by AllAccessible plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'AllAccessible_save_settings' function in all versions up to, and including, 1.3.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary options on the WordPress site. This can be leveraged to update the default role for registration to administrator and enable user registration for attackers to gain administrative user access to a vulnerable site.
0
Attacker Value
Unknown

CVE-2024-49806

Disclosure Date: November 29, 2024 (last updated January 30, 2025)
IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.