Show filters
917 Total Results
Displaying 121-130 of 917
Sort by:
Attacker Value
Unknown
CVE-2024-2836
Disclosure Date: April 15, 2024 (last updated April 15, 2024)
The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.64 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
0
Attacker Value
Unknown
CVE-2024-26251
Disclosure Date: April 09, 2024 (last updated December 21, 2024)
Microsoft SharePoint Server Spoofing Vulnerability
0
Attacker Value
Unknown
CVE-2024-31109
Disclosure Date: April 02, 2024 (last updated April 03, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Toastie Studio Woocommerce Social Media Share Buttons allows Stored XSS.This issue affects Woocommerce Social Media Share Buttons: from n/a through 1.3.0.
0
Attacker Value
Unknown
CVE-2024-2086
Disclosure Date: March 30, 2024 (last updated April 02, 2024)
The Integrate Google Drive – Browse, Upload, Download, Embed, Play, Share, Gallery, and Manage Your Google Drive Files Into Your WordPress Site plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on multiple AJAX in all versions up to, and including, 1.3.8. This makes it possible for authenticated attackers to modify plugin settings as well as allowing full read/write/delete access to the Google Drive associated with the plugin.
0
Attacker Value
Unknown
CVE-2024-30196
Disclosure Date: March 27, 2024 (last updated January 05, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Appscreo Easy Social Share Buttons allows Reflected XSS.This issue affects Easy Social Share Buttons: from n/a through 9.4.
0
Attacker Value
Unknown
CVE-2024-29195
Disclosure Date: March 26, 2024 (last updated January 05, 2025)
The azure-c-shared-utility is a C library for AMQP/MQTT communication to Azure Cloud Services. This library may be used by the Azure IoT C SDK for communication between IoT Hub and IoT Hub devices. An attacker can cause an integer wraparound or under-allocation or heap buffer overflow due to vulnerabilities in parameter checking mechanism, by exploiting the buffer length parameter in Azure C SDK, which may lead to remote code execution. Requirements for RCE are 1. Compromised Azure account allowing malformed payloads to be sent to the device via IoT Hub service, 2. By passing IoT hub service max message payload limit of 128KB, and 3. Ability to overwrite code space with remote code. Fixed in commit https://github.com/Azure/azure-c-shared-utility/commit/1129147c38ac02ad974c4c701a1e01b2141b9fe2.
0
Attacker Value
Unknown
CVE-2022-45851
Disclosure Date: March 25, 2024 (last updated April 02, 2024)
Missing Authorization vulnerability in ShareThis ShareThis Dashboard for Google Analytics.This issue affects ShareThis Dashboard for Google Analytics: from n/a through 3.1.4.
0
Attacker Value
Unknown
CVE-2024-2721
Disclosure Date: March 20, 2024 (last updated January 05, 2025)
Deserialization of Untrusted Data vulnerability in Social Media Share Buttons By Sygnoos Social Media Share Buttons.This issue affects Social Media Share Buttons: from n/a through 2.1.0.
0
Attacker Value
Unknown
CVE-2024-1685
Disclosure Date: March 16, 2024 (last updated April 01, 2024)
The Social Media Share Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.0 via deserialization of untrusted input through the attachmentUrl parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.
0
Attacker Value
Unknown
CVE-2024-21426
Disclosure Date: March 12, 2024 (last updated January 12, 2025)
Microsoft SharePoint Server Remote Code Execution Vulnerability
0