Show filters
545 Total Results
Displaying 101-110 of 545
Sort by:
Attacker Value
Unknown

CVE-2024-32775

Disclosure Date: April 24, 2024 (last updated April 24, 2024)
Server-Side Request Forgery (SSRF) vulnerability in Pavex Embed Google Photos album.This issue affects Embed Google Photos album: from n/a through 2.1.9.
0
Attacker Value
Unknown

CVE-2024-20770

Disclosure Date: April 10, 2024 (last updated December 21, 2024)
Photoshop Desktop versions 24.7.2, 25.3.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Attacker Value
Unknown

CVE-2024-1487

Disclosure Date: March 11, 2024 (last updated April 01, 2024)
The Photos and Files Contest Gallery WordPress plugin before 21.3.1 does not sanitize and escape some parameters, which could allow users with a role as low as author to perform Cross-Site Scripting attacks.
0
Attacker Value
Unknown

CVE-2024-28115

Disclosure Date: March 07, 2024 (last updated October 02, 2024)
FreeRTOS is a real-time operating system for microcontrollers. FreeRTOS Kernel versions through 10.6.1 do not sufficiently protect against local privilege escalation via Return Oriented Programming techniques should a vulnerability exist that allows code injection and execution. These issues affect ARMv7-M MPU ports, and ARMv8-M ports with Memory Protected Unit (MPU) support enabled (i.e. `configENABLE_MPU` set to 1). These issues are fixed in version 10.6.2 with a new MPU wrapper.
Attacker Value
Unknown

CVE-2024-25915

Disclosure Date: February 23, 2024 (last updated February 24, 2024)
Server-Side Request Forgery (SSRF) vulnerability in Raaj Trambadia Pexels: Free Stock Photos.This issue affects Pexels: Free Stock Photos: from n/a through 1.2.2.
0
Attacker Value
Unknown

CVE-2024-24263

Disclosure Date: February 05, 2024 (last updated February 08, 2024)
Lotos WebServer v0.1.1 was discovered to contain a Use-After-Free (UAF) vulnerability via the response_append_status_line function at /lotos/src/response.c.
Attacker Value
Unknown

CVE-2024-22088

Disclosure Date: January 05, 2024 (last updated January 11, 2024)
Lotos WebServer through 0.1.1 (commit 3eb36cc) has a use-after-free in buffer_avail() at buffer.h via a long URI, because realloc is mishandled.
Attacker Value
Unknown

CVE-2023-51373

Disclosure Date: December 29, 2023 (last updated January 05, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ian Kennerley Google Photos Gallery with Shortcodes allows Reflected XSS.This issue affects Google Photos Gallery with Shortcodes: from n/a through 4.0.2.
Attacker Value
Unknown

CVE-2023-44709

Disclosure Date: December 14, 2023 (last updated December 20, 2023)
PlutoSVG commit 336c02997277a1888e6ccbbbe674551a0582e5c4 and before was discovered to contain an integer overflow via the component plutosvg_load_from_memory.
Attacker Value
Unknown

CVE-2023-36654

Disclosure Date: December 12, 2023 (last updated December 14, 2023)
Directory traversal in the log-download REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to download host server SSH private keys (associated with a Linux root user) by injecting paths inside REST API endpoint parameters.