Show filters
349 Total Results
Displaying 101-110 of 349
Sort by:
Attacker Value
Unknown
CVE-2024-21765
Disclosure Date: January 24, 2024 (last updated February 26, 2025)
Electronic Delivery Check System (Doboku) Ver.18.1.0 and earlier, Electronic Delivery Check System (Dentsu) Ver.12.1.0 and earlier, Electronic Delivery Check System (Kikai) Ver.10.1.0 and earlier, and Electronic delivery item Inspection Support SystemVer.4.0.31 and earlier improperly restrict XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.
0
Attacker Value
Unknown
CVE-2024-23686
Disclosure Date: January 19, 2024 (last updated February 26, 2025)
DependencyCheck for Maven 9.0.0 to 9.0.6, for CLI version 9.0.0 to 9.0.5, and for Ant versions 9.0.0 to 9.0.5, when used in debug mode, allows an attacker to recover the NVD API Key from a log file.
0
Attacker Value
Unknown
CVE-2023-6740
Disclosure Date: January 12, 2024 (last updated February 26, 2025)
Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
0
Attacker Value
Unknown
CVE-2023-6735
Disclosure Date: January 12, 2024 (last updated February 26, 2025)
Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
0
Attacker Value
Unknown
CVE-2023-31211
Disclosure Date: January 12, 2024 (last updated February 26, 2025)
Insufficient authentication flow in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows attacker to use locked credentials
0
Attacker Value
Unknown
CVE-2023-52143
Disclosure Date: January 05, 2024 (last updated February 25, 2025)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Naa986 WP Stripe Checkout.This issue affects WP Stripe Checkout: from n/a through 1.2.2.37.
0
Attacker Value
Unknown
CVE-2023-51469
Disclosure Date: December 31, 2023 (last updated February 25, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mestres do WP Checkout Mestres WP.This issue affects Checkout Mestres WP: from n/a through 7.1.9.6.
0
Attacker Value
Unknown
CVE-2014-125108
Disclosure Date: December 23, 2023 (last updated February 25, 2025)
A vulnerability was found in w3c online-spellchecker-py up to 20140130. It has been rated as problematic. This issue affects some unknown processing of the file spellchecker. The manipulation leads to cross site scripting. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The identifier of the patch is d6c21fd8187c5db2a50425ff80694149e75d722e. It is recommended to apply a patch to fix this issue. The identifier VDB-248849 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-31210
Disclosure Date: December 13, 2023 (last updated February 25, 2025)
Usage of user controlled LD_LIBRARY_PATH in agent in Checkmk 2.2.0p10 up to 2.2.0p16 allows malicious Checkmk site user to escalate rights via injection of malicious libraries
0
Attacker Value
Unknown
CVE-2023-48281
Disclosure Date: November 30, 2023 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Super Blog Me Broken Link Checker for YouTube allows Cross Site Request Forgery.This issue affects Broken Link Checker for YouTube: from n/a through 1.3.
0