Show filters
917 Total Results
Displaying 101-110 of 917
Sort by:
Attacker Value
Unknown
CVE-2024-6257
Disclosure Date: June 25, 2024 (last updated June 26, 2024)
HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2024-33881
Disclosure Date: June 24, 2024 (last updated June 27, 2024)
An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows an NTLMv2 hash leak via a UNC share pathname in the path parameter.
0
Attacker Value
Unknown
CVE-2024-33880
Disclosure Date: June 24, 2024 (last updated June 27, 2024)
An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. It discloses full pathnames via Virto.SharePoint.FileDownloader/Api/Download.ashx?action=archive.
0
Attacker Value
Unknown
CVE-2024-33879
Disclosure Date: June 24, 2024 (last updated June 27, 2024)
An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows arbitrary file download and deletion via absolute path traversal in the path parameter.
0
Attacker Value
Unknown
CVE-2024-2003
Disclosure Date: June 21, 2024 (last updated June 21, 2024)
Local privilege escalation vulnerability allowed an attacker to misuse ESET's file operations during a restore operation from quarantine.
0
Attacker Value
Unknown
CVE-2024-4094
Disclosure Date: June 18, 2024 (last updated July 06, 2024)
The Simple Share Buttons Adder WordPress plugin before 8.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
0
Attacker Value
Unknown
CVE-2024-30100
Disclosure Date: June 11, 2024 (last updated January 12, 2025)
Microsoft SharePoint Server Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2024-31307
Disclosure Date: June 09, 2024 (last updated June 10, 2024)
Missing Authorization vulnerability in appscreo Easy Social Share Buttons.This issue affects Easy Social Share Buttons: from n/a through 9.4.
0
Attacker Value
Unknown
CVE-2024-32820
Disclosure Date: June 09, 2024 (last updated June 10, 2024)
Missing Authorization vulnerability in Social Share Pro Social Share Icons & Social Share Buttons.This issue affects Social Share Icons & Social Share Buttons: from n/a through 3.6.2.
0
Attacker Value
Unknown
CVE-2024-4997
Disclosure Date: June 04, 2024 (last updated January 05, 2025)
The WPUpper Share Buttons plugin for WordPress is vulnerable to unauthorized access of data when preparing sharing links for posts and pages in all versions up to, and including, 3.43. This makes it possible for unauthenticated attackers to obtain the contents of password protected posts and pages.
0