Show filters
1,382 Total Results
Displaying 101-110 of 1,382
Sort by:
Attacker Value
Unknown
CVE-2024-9455
Disclosure Date: October 05, 2024 (last updated October 05, 2024)
The WP Cleanup and Basic Functions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses the SVG file.
0
Attacker Value
Unknown
CVE-2024-24117
Disclosure Date: October 02, 2024 (last updated November 14, 2024)
Insecure Permissions vulnerability in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release (9736) allows a remote attacker to gain privileges via the login check state component.
0
Attacker Value
Unknown
CVE-2024-24116
Disclosure Date: October 02, 2024 (last updated November 14, 2024)
An issue in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release(9736) allows a remote attacker to gain privileges via the system/config_menu.htm.
0
Attacker Value
Unknown
CVE-2024-8239
Disclosure Date: September 30, 2024 (last updated October 08, 2024)
The Starbox WordPress plugin before 3.5.3 does not properly render social media profiles URLs in certain contexts, like the malicious user's profile or pages where the starbox shortcode is used, which may be abused by users with at least the contributor role to conduct Stored XSS attacks.
0
Attacker Value
Unknown
CVE-2024-47075
Disclosure Date: September 26, 2024 (last updated September 27, 2024)
LayUI is a native minimalist modular Web UI component library. Versions prior to 2.9.17 have a DOM Clobbering vulnerability that can lead to Cross-site Scripting (XSS) on web pages where attacker-controlled HTML elements (e.g., `img` tags with unsanitized `name` attributes) are present. Version 2.9.17 fixes this issue.
0
Attacker Value
Unknown
CVE-2021-27917
Disclosure Date: September 18, 2024 (last updated September 28, 2024)
Prior to this patch, a stored XSS vulnerability existed in the contact tracking and page hits report.
0
Attacker Value
Unknown
CVE-2024-47058
Disclosure Date: September 18, 2024 (last updated September 28, 2024)
With access to edit a Mautic form, the attacker can add Cross-Site Scripting stored in the html filed. This could be used to steal sensitive information from the user's current session.
0
Attacker Value
Unknown
CVE-2024-47050
Disclosure Date: September 18, 2024 (last updated September 28, 2024)
Prior to this patch being applied, Mautic's tracking was vulnerable to Cross-Site Scripting through the Page URL variable.
0
Attacker Value
Unknown
CVE-2022-25776
Disclosure Date: September 18, 2024 (last updated September 25, 2024)
Prior to the patched version, logged in users of Mautic are able to access areas of the application that they should be prevented from accessing.
Users could potentially access sensitive data such as names and surnames, company names and stage names.
0
Attacker Value
Unknown
CVE-2022-25775
Disclosure Date: September 18, 2024 (last updated September 24, 2024)
Prior to the patched version, logged in users of Mautic are vulnerable to an SQL injection vulnerability in the Reports bundle.
The user could retrieve and alter data like sensitive data, login, and depending on database permission the attacker can manipulate file systems.
0