Show filters
917 Total Results
Displaying 101-110 of 917
Sort by:
Attacker Value
Unknown

CVE-2024-6257

Disclosure Date: June 25, 2024 (last updated June 26, 2024)
HashiCorp’s go-getter library can be coerced into executing Git update on an existing maliciously modified Git Configuration, potentially leading to arbitrary code execution.
0
Attacker Value
Unknown

CVE-2024-33881

Disclosure Date: June 24, 2024 (last updated June 27, 2024)
An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows an NTLMv2 hash leak via a UNC share pathname in the path parameter.
Attacker Value
Unknown

CVE-2024-33880

Disclosure Date: June 24, 2024 (last updated June 27, 2024)
An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. It discloses full pathnames via Virto.SharePoint.FileDownloader/Api/Download.ashx?action=archive.
Attacker Value
Unknown

CVE-2024-33879

Disclosure Date: June 24, 2024 (last updated June 27, 2024)
An issue was discovered in VirtoSoftware Virto Bulk File Download 5.5.44 for SharePoint 2019. The Virto.SharePoint.FileDownloader/Api/Download.ashx isCompleted method allows arbitrary file download and deletion via absolute path traversal in the path parameter.
Attacker Value
Unknown

CVE-2024-2003

Disclosure Date: June 21, 2024 (last updated June 21, 2024)
Local privilege escalation vulnerability allowed an attacker to misuse ESET's file operations during a restore operation from quarantine.
0
Attacker Value
Unknown

CVE-2024-4094

Disclosure Date: June 18, 2024 (last updated July 06, 2024)
The Simple Share Buttons Adder WordPress plugin before 8.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
Attacker Value
Unknown

CVE-2024-30100

Disclosure Date: June 11, 2024 (last updated January 12, 2025)
Microsoft SharePoint Server Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2024-31307

Disclosure Date: June 09, 2024 (last updated June 10, 2024)
Missing Authorization vulnerability in appscreo Easy Social Share Buttons.This issue affects Easy Social Share Buttons: from n/a through 9.4.
0
Attacker Value
Unknown

CVE-2024-32820

Disclosure Date: June 09, 2024 (last updated June 10, 2024)
Missing Authorization vulnerability in Social Share Pro Social Share Icons & Social Share Buttons.This issue affects Social Share Icons & Social Share Buttons: from n/a through 3.6.2.
0
Attacker Value
Unknown

CVE-2024-4997

Disclosure Date: June 04, 2024 (last updated January 05, 2025)
The WPUpper Share Buttons plugin for WordPress is vulnerable to unauthorized access of data when preparing sharing links for posts and pages in all versions up to, and including, 3.43. This makes it possible for unauthenticated attackers to obtain the contents of password protected posts and pages.
0