Show filters
2,134 Total Results
Displaying 121-130 of 2,134
Sort by:
Attacker Value
Unknown

CVE-2024-21464

Disclosure Date: January 06, 2025 (last updated January 13, 2025)
Memory corruption while processing IPA statistics, when there are no active clients registered.
Attacker Value
Unknown

CVE-2024-12279

Disclosure Date: January 04, 2025 (last updated January 05, 2025)
The WP Social AutoConnect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.6.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2024-9950

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
A vulnerability in Forescout SecureConnector v11.3.07.0109 on Windows allows unauthenticated user to modify compliance scripts due to insecure temporary directory.
0
Attacker Value
Unknown

CVE-2023-40327

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Missing Authorization vulnerability in Putler / Storeapps Putler Connector for WooCommerce.This issue affects Putler Connector for WooCommerce: from n/a through 2.12.0.
0
Attacker Value
Unknown

CVE-2024-56255

Disclosure Date: January 02, 2025 (last updated January 03, 2025)
Missing Authorization vulnerability in AyeCode AyeCode Connect allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AyeCode Connect: from n/a through 1.3.8.
0
Attacker Value
Unknown

CVE-2024-56233

Disclosure Date: December 31, 2024 (last updated January 02, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kinhelios Kintpv Wooconnect allows Stored XSS.This issue affects Kintpv Wooconnect: from n/a through 8.129.
0
Attacker Value
Unknown

CVE-2024-12745

Disclosure Date: December 24, 2024 (last updated January 05, 2025)
A SQL injection in the Amazon Redshift Python Connector v2.1.4 allows a user to gain escalated privileges via the get_schemas, get_tables, or get_columns Metadata APIs. Users are recommended to upgrade to the driver version 2.1.5 or revert to driver version 2.1.3.
0
Attacker Value
Unknown

CVE-2024-12582

Disclosure Date: December 24, 2024 (last updated February 14, 2025)
A flaw was found in the skupper console, a read-only interface that renders cluster network, traffic details, and metrics for a network application that a user sets up across a hybrid multi-cloud environment. When the default authentication method is used, a random password is generated for the "admin" user and is persisted in either a Kubernetes secret or a podman volume in a plaintext file. This authentication method can be manipulated by an attacker, leading to the reading of any user-readable file in the container filesystem, directly impacting data confidentiality. Additionally, the attacker may induce skupper to read extremely large files into memory, resulting in resource exhaustion and a denial of service attack.
0
Attacker Value
Unknown

CVE-2024-56058

Disclosure Date: December 18, 2024 (last updated December 19, 2024)
Deserialization of Untrusted Data vulnerability in Gueststream VRPConnector allows Object Injection.This issue affects VRPConnector: from n/a through 2.0.1.
0
Attacker Value
Unknown

CVE-2024-54343

Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Howard Ehrenberg Connect Contact Form 7 to Constant Contact allows Reflected XSS.This issue affects Connect Contact Form 7 to Constant Contact: from n/a through 1.4.
0