Show filters
808 Total Results
Displaying 111-120 of 808
Sort by:
Attacker Value
Unknown
CVE-2024-2415
Disclosure Date: March 13, 2024 (last updated January 05, 2025)
Command injection vulnerability in Movistar 4G router affecting version ES_WLD71-T1_v2.0.201820. This vulnerability allows an authenticated user to execute commands inside the router by making a POST request to the URL '/cgi-bin/gui.cgi'.
0
Attacker Value
Unknown
CVE-2024-2414
Disclosure Date: March 13, 2024 (last updated January 05, 2025)
The primary channel is unprotected on Movistar 4G router affecting E version S_WLD71-T1_v2.0.201820. This device has the 'adb' service open on port 5555 and provides access to a shell with root privileges.
0
Attacker Value
Unknown
CVE-2024-1273
Disclosure Date: March 11, 2024 (last updated April 01, 2024)
The Starbox WordPress plugin before 3.5.0 does not sanitise and escape some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks
0
Attacker Value
Unknown
CVE-2023-6806
Disclosure Date: February 29, 2024 (last updated February 29, 2024)
The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Job Settings user profile fields in all versions up to, and including, 3.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2023-5617
Disclosure Date: February 28, 2024 (last updated February 15, 2025)
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.1.0.0 and 9.3.0.6, including 9.5.x and 8.3.x, display the version of Tomcat when a server error is encountered.
0
Attacker Value
Unknown
CVE-2024-0256
Disclosure Date: February 07, 2024 (last updated February 15, 2024)
The Starbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Profile Display Name and Social Settings in all versions up to, and including, 3.4.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-0366
Disclosure Date: February 05, 2024 (last updated February 14, 2024)
The Starbox – the Author Box for Humans plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.4.7 via the action function due to missing validation on a user controlled key. This makes it possible for subscribers to view plugin preferences and potentially other user settings.
0
Attacker Value
Unknown
CVE-2024-24838
Disclosure Date: February 05, 2024 (last updated February 08, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Five Star Plugins Five Star Restaurant Reviews allows Stored XSS.This issue affects Five Star Restaurant Reviews: from n/a through 2.3.5.
0
Attacker Value
Unknown
CVE-2024-24756
Disclosure Date: February 01, 2024 (last updated February 10, 2024)
Crafatar serves Minecraft avatars based on the skin for use in external applications. Files outside of the `lib/public/` directory can be requested from the server. Instances running behind Cloudflare (including crafatar.com) are not affected. Instances using the Docker container as shown in the README are affected, but only files within the container can be read. By default, all of the files within the container can also be found in this repository and are not confidential. This vulnerability is patched in 2.1.5.
0
Attacker Value
Unknown
CVE-2023-6384
Disclosure Date: January 22, 2024 (last updated January 27, 2024)
The WP User Profile Avatar WordPress plugin before 1.0.1 does not properly check for authorisation, allowing authors to delete and update arbitrary avatar
0