Show filters
1,711 Total Results
Displaying 131-140 of 1,711
Sort by:
Attacker Value
Unknown
CVE-2023-5527
Disclosure Date: June 18, 2024 (last updated February 26, 2025)
The Business Directory Plugin plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.4.3 via the class-csv-exporter.php file. This allows authenticated attackers, with author-level permissions and above, to embed untrusted input into CSV files exported by administrators, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
0
Attacker Value
Unknown
CVE-2023-51516
Disclosure Date: June 14, 2024 (last updated February 26, 2025)
Missing Authorization vulnerability in Business Directory Team Business Directory Plugin.This issue affects Business Directory Plugin: from n/a through 6.3.9.
0
Attacker Value
Unknown
CVE-2024-35249
Disclosure Date: June 11, 2024 (last updated February 26, 2025)
Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2024-35248
Disclosure Date: June 11, 2024 (last updated February 26, 2025)
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
0
Attacker Value
Unknown
CVE-2024-34684
Disclosure Date: June 11, 2024 (last updated February 26, 2025)
On Unix, SAP BusinessObjects Business
Intelligence Platform (Scheduling) allows an authenticated attacker with
administrator access on the local server to access the password of a local
account. As a result, an attacker can obtain non-administrative user
credentials, which will allow them to read or modify the remote server files.
0
Attacker Value
Unknown
CVE-2024-4532
Disclosure Date: May 27, 2024 (last updated February 26, 2025)
The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as deleting cards via CSRF attacks
0
Attacker Value
Unknown
CVE-2024-4531
Disclosure Date: May 27, 2024 (last updated May 27, 2024)
The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as editing cards via CSRF attacks
0
Attacker Value
Unknown
CVE-2024-4530
Disclosure Date: May 27, 2024 (last updated May 27, 2024)
The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as editing card categories via CSRF attacks
0
Attacker Value
Unknown
CVE-2024-4529
Disclosure Date: May 27, 2024 (last updated May 27, 2024)
The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as deleting card categories via CSRF attacks
0
Attacker Value
Unknown
CVE-2024-4443
Disclosure Date: May 22, 2024 (last updated January 05, 2025)
The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘listingfields’ parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
0