Show filters
13,141 Total Results
Displaying 131-140 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-45105

Disclosure Date: September 13, 2024 (last updated September 14, 2024)
An internal product security audit discovered a UEFI SMM (System Management Mode) callout vulnerability in some ThinkSystem servers that could allow a local attacker with elevated privileges to execute arbitrary code.
Attacker Value
Unknown

CVE-2024-44798

Disclosure Date: September 13, 2024 (last updated September 17, 2024)
phpgurukul Bus Pass Management System 1.0 is vulnerable to Cross-site scripting (XSS) in /admin/pass-bwdates-reports-details.php via fromdate and todate parameters.
Attacker Value
Unknown

CVE-2022-2446

Disclosure Date: September 13, 2024 (last updated September 27, 2024)
The WP Editor plugin for WordPress is vulnerable to deserialization of untrusted input via the 'current_theme_root' parameter in versions up to, and including 1.2.9. This makes it possible for authenticated attackers with administrative privileges to call files using a PHAR wrapper that will deserialize and call arbitrary PHP Objects that can be used to perform a variety of malicious actions granted a POP chain is also present. It also requires that the attacker is successful in uploading a file with the serialized payload.
Attacker Value
Unknown

CVE-2024-7863

Disclosure Date: September 13, 2024 (last updated September 28, 2024)
The Favicon Generator (CLOSED) WordPress plugin before 2.1 does not validate files to be uploaded and does not have CSRF checks, which could allow attackers to make logged in admin upload arbitrary files such as PHP on the server
Attacker Value
Unknown

CVE-2024-7133

Disclosure Date: September 13, 2024 (last updated September 28, 2024)
The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.7.3 does not validate and escape some of its settings before outputting them back in the page, which could allow users with a high role to perform Stored Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2024-7129

Disclosure Date: September 13, 2024 (last updated September 28, 2024)
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin WordPress plugin before 1.6.7.43 does not escape template syntax provided via user input, leading to Twig Template Injection which further exploited can result to remote code Execution by high privilege such as admins
Attacker Value
Unknown

CVE-2024-6850

Disclosure Date: September 13, 2024 (last updated September 28, 2024)
The Carousel Slider WordPress plugin before 2.2.4 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
Attacker Value
Unknown

CVE-2024-6723

Disclosure Date: September 13, 2024 (last updated September 28, 2024)
The AI Engine WordPress plugin before 2.4.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by admin users when viewing chatbot discussions.
Attacker Value
Unknown

CVE-2024-6617

Disclosure Date: September 13, 2024 (last updated September 28, 2024)
The NinjaTeam Header Footer Custom Code WordPress plugin before 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Attacker Value
Unknown

CVE-2024-6493

Disclosure Date: September 13, 2024 (last updated September 28, 2024)
The NinjaTeam Header Footer Custom Code WordPress plugin before 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)