Show filters
1,711 Total Results
Displaying 131-140 of 1,711
Sort by:
Attacker Value
Unknown

CVE-2023-5527

Disclosure Date: June 18, 2024 (last updated February 26, 2025)
The Business Directory Plugin plugin for WordPress is vulnerable to CSV Injection in versions up to, and including, 6.4.3 via the class-csv-exporter.php file. This allows authenticated attackers, with author-level permissions and above, to embed untrusted input into CSV files exported by administrators, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
Attacker Value
Unknown

CVE-2023-51516

Disclosure Date: June 14, 2024 (last updated February 26, 2025)
Missing Authorization vulnerability in Business Directory Team Business Directory Plugin.This issue affects Business Directory Plugin: from n/a through 6.3.9.
Attacker Value
Unknown

CVE-2024-35249

Disclosure Date: June 11, 2024 (last updated February 26, 2025)
Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2024-35248

Disclosure Date: June 11, 2024 (last updated February 26, 2025)
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2024-34684

Disclosure Date: June 11, 2024 (last updated February 26, 2025)
On Unix, SAP BusinessObjects Business Intelligence Platform (Scheduling) allows an authenticated attacker with administrator access on the local server to access the password of a local account. As a result, an attacker can obtain non-administrative user credentials, which will allow them to read or modify the remote server files.
Attacker Value
Unknown

CVE-2024-4532

Disclosure Date: May 27, 2024 (last updated February 26, 2025)
The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as deleting cards via CSRF attacks
0
Attacker Value
Unknown

CVE-2024-4531

Disclosure Date: May 27, 2024 (last updated May 27, 2024)
The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as editing cards via CSRF attacks
0
Attacker Value
Unknown

CVE-2024-4530

Disclosure Date: May 27, 2024 (last updated May 27, 2024)
The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as editing card categories via CSRF attacks
0
Attacker Value
Unknown

CVE-2024-4529

Disclosure Date: May 27, 2024 (last updated May 27, 2024)
The Business Card WordPress plugin through 1.0.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions such as deleting card categories via CSRF attacks
0
Attacker Value
Unknown

CVE-2024-4443

Disclosure Date: May 22, 2024 (last updated January 05, 2025)
The Business Directory Plugin – Easy Listing Directories for WordPress plugin for WordPress is vulnerable to time-based SQL Injection via the ‘listingfields’ parameter in all versions up to, and including, 6.4.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
0