Show filters
5,935 Total Results
Displaying 101-110 of 5,935
Sort by:
Attacker Value
Unknown
CVE-2024-38420
Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption while configuring a Hypervisor based input virtual device.
0
Attacker Value
Unknown
CVE-2024-13623
Disclosure Date: January 31, 2025 (last updated January 31, 2025)
The Order Export for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.24 via the 'uploads' directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely in the /wp-content/uploads directory which can contain exported order information. The plugin is only vulnerable when 'Order data storage' is set to 'WordPress posts storage (legacy)', and cannot be exploited when the default option of 'High-performance order storage' is enabled.
0
Attacker Value
Unknown
CVE-2025-23367
Disclosure Date: January 30, 2025 (last updated February 01, 2025)
A flaw was found in the Wildfly Server Role Based Access Control (RBAC) provider. When authorization to control management operations is secured using the Role Based Access Control provider, a user without the required privileges can suspend or resume the server. A user with a Monitor or Auditor role is supposed to have only read access permissions and should not be able to suspend the server.
The vulnerability is caused by the Suspend and Resume handlers not performing authorization checks to validate whether the current user has the required permissions to proceed with the action.
0
Attacker Value
Unknown
CVE-2024-8401
Disclosure Date: January 28, 2025 (last updated January 29, 2025)
CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
vulnerability exists when an authenticated attacker modifies folder names within the context of
the product.
0
Attacker Value
Unknown
CVE-2025-24689
Disclosure Date: January 27, 2025 (last updated January 28, 2025)
Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in codection Import and export users and customers allows Retrieve Embedded Sensitive Data. This issue affects Import and export users and customers: from n/a through 1.27.12.
0
Attacker Value
Unknown
CVE-2025-24667
Disclosure Date: January 27, 2025 (last updated January 28, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eniture Technology Small Package Quotes – Worldwide Express Edition allows SQL Injection. This issue affects Small Package Quotes – Worldwide Express Edition: from n/a through 5.2.17.
0
Attacker Value
Unknown
CVE-2025-24664
Disclosure Date: January 27, 2025 (last updated January 28, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eniture Technology LTL Freight Quotes – Worldwide Express Edition allows SQL Injection. This issue affects LTL Freight Quotes – Worldwide Express Edition: from n/a through 5.0.20.
0
Attacker Value
Unknown
CVE-2025-24611
Disclosure Date: January 24, 2025 (last updated January 25, 2025)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Smackcoders WP Ultimate Exporter allows Absolute Path Traversal. This issue affects WP Ultimate Exporter: from n/a through 2.9.
0
Attacker Value
Unknown
CVE-2024-9499
Disclosure Date: January 24, 2025 (last updated January 25, 2025)
DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress Win 98SE Dev Kit installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.
0
Attacker Value
Unknown
CVE-2024-9498
Disclosure Date: January 24, 2025 (last updated January 25, 2025)
DLL hijacking vulnerabilities, caused by an uncontrolled search path in the USBXpress SDK
installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.
0