Show filters
9,937 Total Results
Displaying 151-160 of 9,937
Sort by:
Attacker Value
Unknown

CVE-2024-13462

Disclosure Date: February 19, 2025 (last updated February 19, 2025)
The WP Wiki Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wiki' shortcode in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2025-0633

Disclosure Date: February 19, 2025 (last updated February 19, 2025)
Heap-based Buffer Overflow vulnerability in iniparser_dumpsection_ini() in iniparser allows attacker to read out of bound memory
0
Attacker Value
Unknown

CVE-2024-13636

Disclosure Date: February 18, 2025 (last updated February 24, 2025)
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-24926. Reason: This candidate is a reservation duplicate of CVE-2024-24926. Notes: All CVE users should reference CVE-2024-24926 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.
Attacker Value
Unknown

CVE-2024-13464

Disclosure Date: February 18, 2025 (last updated February 25, 2025)
The Library Bookshelves plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bookshelf' shortcode in all versions up to, and including, 5.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2025-1389

Disclosure Date: February 17, 2025 (last updated February 17, 2025)
Orca HCM from Learning Digital has a SQL Injection vulnerability, allowing attackers with regular privileges to inject arbitrary SQL commands to read, modify, and delete database contents.
Attacker Value
Unknown

CVE-2025-1388

Disclosure Date: February 17, 2025 (last updated February 17, 2025)
Orca HCM from LEARNING DIGITAL has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privileges to upload and run web shells
Attacker Value
Unknown

CVE-2025-1387

Disclosure Date: February 17, 2025 (last updated February 17, 2025)
Orca HCM from LEARNING DIGITAL has an Improper Authentication vulnerability, allowing unauthenticated remote attackers to log in to the system as any user.
Attacker Value
Unknown

CVE-2025-26765

Disclosure Date: February 16, 2025 (last updated February 17, 2025)
Missing Authorization vulnerability in enituretechnology Distance Based Shipping Calculator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Distance Based Shipping Calculator: from n/a through 2.0.22.
0
Attacker Value
Unknown

CVE-2025-22291

Disclosure Date: February 16, 2025 (last updated February 17, 2025)
Missing Authorization vulnerability in enituretechnology LTL Freight Quotes – Worldwide Express Edition allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects LTL Freight Quotes – Worldwide Express Edition: from n/a through 5.0.20.
0
Attacker Value
Unknown

CVE-2025-22290

Disclosure Date: February 16, 2025 (last updated February 17, 2025)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology LTL Freight Quotes – FreightQuote Edition allows SQL Injection. This issue affects LTL Freight Quotes – FreightQuote Edition: from n/a through 2.3.11.
0