Show filters
2,612 Total Results
Displaying 101-110 of 2,612
Sort by:
Attacker Value
Unknown

CVE-2024-7727

Disclosure Date: September 11, 2024 (last updated February 26, 2025)
The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions called via the 'h5vp_ajax_handler' ajax action in all versions up to, and including, 2.5.32. This makes it possible for unauthenticated attackers to call these functions to manipulate data.
Attacker Value
Unknown

CVE-2024-7721

Disclosure Date: September 11, 2024 (last updated February 26, 2025)
The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_password' function in all versions up to, and including, 2.5.34. This makes it possible for authenticated attackers, with Subscriber-level access and above, to set any options that are not explicitly checked as false to an array, including enabling user registration if it has been disabled.
Attacker Value
Unknown

CVE-2024-33060

Disclosure Date: September 02, 2024 (last updated February 26, 2025)
Memory corruption when two threads try to map and unmap a single node simultaneously.
Attacker Value
Unknown

CVE-2024-33052

Disclosure Date: September 02, 2024 (last updated February 26, 2025)
Memory corruption when user provides data for FM HCI command control operations.
Attacker Value
Unknown

CVE-2024-33043

Disclosure Date: September 02, 2024 (last updated February 26, 2025)
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
Attacker Value
Unknown

CVE-2024-33042

Disclosure Date: September 02, 2024 (last updated February 26, 2025)
Memory corruption when Alternative Frequency offset value is set to 255.
Attacker Value
Unknown

CVE-2024-7856

Disclosure Date: August 29, 2024 (last updated February 26, 2025)
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the removeTempFiles() function and insufficient path validation on the 'file' parameter in all versions up to, and including, 5.7.0.1. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete arbitrary files which can make remote code execution possible when wp-config.php is deleted.
Attacker Value
Unknown

CVE-2023-4027

Disclosure Date: August 17, 2024 (last updated February 26, 2025)
The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_settings function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to update plugin settings.
Attacker Value
Unknown

CVE-2023-4025

Disclosure Date: August 17, 2024 (last updated February 26, 2025)
The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_player function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to update player instances.
Attacker Value
Unknown

CVE-2023-4024

Disclosure Date: August 17, 2024 (last updated February 26, 2025)
The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_player function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to delete player instances.