Show filters
1,460 Total Results
Displaying 121-130 of 1,460
Sort by:
Attacker Value
Unknown
CVE-2024-37940
Disclosure Date: July 12, 2024 (last updated February 26, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in Seraphinite Solutions Seraphinite Accelerator (Full, premium).This issue affects Seraphinite Accelerator (Full, premium): from n/a through 2.21.13.
0
Attacker Value
Unknown
CVE-2024-4882
Disclosure Date: July 08, 2024 (last updated February 26, 2025)
The user may be redirected to an arbitrary site in Sitefinity 15.1.8321.0 and previous versions.
0
Attacker Value
Unknown
CVE-2024-39689
Disclosure Date: July 05, 2024 (last updated February 26, 2025)
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.5.30 and prior to 2024.7.4 recognized root certificates from `GLOBALTRUST`. Certifi 2024.7.04 removes root certificates from `GLOBALTRUST` from the root store. These are in the process of being removed from Mozilla's trust store. `GLOBALTRUST`'s root certificates are being removed pursuant to an investigation which identified "long-running and unresolved compliance issues."
0
Attacker Value
Unknown
CVE-2024-5672
Disclosure Date: July 03, 2024 (last updated February 26, 2025)
A high privileged remote attacker can execute arbitrary system commands via GET requests due to improper neutralization of special elements used in an OS command.
0
Attacker Value
Unknown
CVE-2024-5796
Disclosure Date: June 28, 2024 (last updated June 29, 2024)
The Infinite theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘project_url’ parameter in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-6273
Disclosure Date: June 23, 2024 (last updated February 26, 2025)
A vulnerability was found in SourceCodester Clinic Queuing System 1.0. It has been declared as problematic. Affected by this vulnerability is the function save_patient of the file patient_side.php. The manipulation of the argument Full Name/Contact/Address leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-269485 was assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2023-27636
Disclosure Date: June 16, 2024 (last updated February 26, 2025)
Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.
0
Attacker Value
Unknown
CVE-2024-24051
Disclosure Date: June 12, 2024 (last updated November 21, 2024)
Improper input validation of printing files in Monoprice Select Mini V2 V37.115.32 allows attackers to instruct the device's movable parts to destinations that exceed the devices' maximum coordinates via the printing of a malicious .gcode file.
0
Attacker Value
Unknown
CVE-2023-38533
Disclosure Date: June 11, 2024 (last updated February 26, 2025)
A vulnerability has been identified in TIA Administrator (All versions < V3 SP2). The affected component creates temporary download files in a directory with insecure permissions. This could allow any authenticated attacker on Windows to disrupt the update process.
0
Attacker Value
Unknown
CVE-2024-37130
Disclosure Date: June 11, 2024 (last updated February 26, 2025)
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains a Local Privilege Escalation vulnerability via XSL Hijacking. A local low-privileged malicious user could potentially exploit this vulnerability and escalate their privilege to the admin user and gain full control of the machine. Exploitation may lead to a complete system compromise.
0