Show filters
961 Total Results
Displaying 131-140 of 961
Sort by:
Attacker Value
Unknown
CVE-2024-38504
Disclosure Date: June 18, 2024 (last updated August 23, 2024)
In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles
0
Attacker Value
Unknown
CVE-2023-52217
Disclosure Date: June 11, 2024 (last updated July 24, 2024)
Missing Authorization vulnerability in weDevs WooCommerce Conversion Tracking.This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.11.
0
Attacker Value
Unknown
CVE-2024-31347
Disclosure Date: June 09, 2024 (last updated June 10, 2024)
Missing Authorization vulnerability in Data443 Tracking Code Manager.This issue affects Tracking Code Manager: from n/a through 2.1.0.
0
Attacker Value
Unknown
CVE-2024-35737
Disclosure Date: June 08, 2024 (last updated July 26, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Loopus WP Visitors Tracker allows Reflected XSS.This issue affects WP Visitors Tracker: from n/a through 2.3.
0
Attacker Value
Unknown
CVE-2024-5037
Disclosure Date: June 05, 2024 (last updated November 11, 2024)
A flaw was found in OpenShift's Telemeter. If certain conditions are in place, an attacker can use a forged token to bypass the issue ("iss") check during JSON web token (JWT) authentication.
0
Attacker Value
Unknown
CVE-2024-22384
Disclosure Date: May 16, 2024 (last updated May 17, 2024)
Out-of-bounds read for some Intel(R) Trace Analyzer and Collector software before version 2022.0.0 published Nov 2023 may allow an authenticated user to potentially enable information disclosure via local access.
0
Attacker Value
Unknown
CVE-2024-35299
Disclosure Date: May 16, 2024 (last updated January 29, 2025)
In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation
0
Attacker Value
Unknown
CVE-2024-4039
Disclosure Date: May 14, 2024 (last updated January 05, 2025)
The The Orders Tracking for WooCommerce plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.10. This is due to the plugin allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. A partial patch was released in 1.2.10, and a complete patch was released in 1.2.11.
0
Attacker Value
Unknown
CVE-2024-34431
Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP-etracker WP etracker allows Reflected XSS.This issue affects WP etracker: from n/a through 1.0.2.
0
Attacker Value
Unknown
CVE-2021-35002
Disclosure Date: May 07, 2024 (last updated May 08, 2024)
BMC Track-It! Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It!. Authentication is required to exploit this vulnerability.
The specific flaw exists within the processing of email attachments. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-14122.
0