Show filters
961 Total Results
Displaying 131-140 of 961
Sort by:
Attacker Value
Unknown

CVE-2024-38504

Disclosure Date: June 18, 2024 (last updated August 23, 2024)
In JetBrains YouTrack before 2024.2.34646 the Guest User Account was enabled for attaching files to articles
Attacker Value
Unknown

CVE-2023-52217

Disclosure Date: June 11, 2024 (last updated July 24, 2024)
Missing Authorization vulnerability in weDevs WooCommerce Conversion Tracking.This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.11.
Attacker Value
Unknown

CVE-2024-31347

Disclosure Date: June 09, 2024 (last updated June 10, 2024)
Missing Authorization vulnerability in Data443 Tracking Code Manager.This issue affects Tracking Code Manager: from n/a through 2.1.0.
0
Attacker Value
Unknown

CVE-2024-35737

Disclosure Date: June 08, 2024 (last updated July 26, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Loopus WP Visitors Tracker allows Reflected XSS.This issue affects WP Visitors Tracker: from n/a through 2.3.
Attacker Value
Unknown

CVE-2024-5037

Disclosure Date: June 05, 2024 (last updated November 11, 2024)
A flaw was found in OpenShift's Telemeter. If certain conditions are in place, an attacker can use a forged token to bypass the issue ("iss") check during JSON web token (JWT) authentication.
Attacker Value
Unknown

CVE-2024-22384

Disclosure Date: May 16, 2024 (last updated May 17, 2024)
Out-of-bounds read for some Intel(R) Trace Analyzer and Collector software before version 2022.0.0 published Nov 2023 may allow an authenticated user to potentially enable information disclosure via local access.
0
Attacker Value
Unknown

CVE-2024-35299

Disclosure Date: May 16, 2024 (last updated January 29, 2025)
In JetBrains YouTrack before 2024.1.29548 the SMTPS protocol communication lacked proper certificate hostname validation
Attacker Value
Unknown

CVE-2024-4039

Disclosure Date: May 14, 2024 (last updated January 05, 2025)
The The Orders Tracking for WooCommerce plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.10. This is due to the plugin allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. A partial patch was released in 1.2.10, and a complete patch was released in 1.2.11.
0
Attacker Value
Unknown

CVE-2024-34431

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP-etracker WP etracker allows Reflected XSS.This issue affects WP etracker: from n/a through 1.0.2.
0
Attacker Value
Unknown

CVE-2021-35002

Disclosure Date: May 07, 2024 (last updated May 08, 2024)
BMC Track-It! Unrestricted File Upload Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of BMC Track-It!. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of email attachments. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this vulnerability to execute code in the context of the service account. Was ZDI-CAN-14122.
0