Show filters
1,462 Total Results
Displaying 161-170 of 1,462
Sort by:
Attacker Value
Unknown

CVE-2024-2074

Disclosure Date: March 01, 2024 (last updated February 26, 2025)
A vulnerability was found in Mini-Tmall up to 20231017 and classified as critical. This issue affects some unknown processing of the file ?r=tmall/admin/user/1/1. The manipulation of the argument orderBy leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-255389 was assigned to this vulnerability.
0
Attacker Value
Unknown

CVE-2024-26462

Disclosure Date: February 29, 2024 (last updated February 26, 2025)
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.
Attacker Value
Unknown

CVE-2023-6565

Disclosure Date: February 29, 2024 (last updated February 26, 2025)
The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the limited time window of the backup process.
0
Attacker Value
Unknown

CVE-2024-1636

Disclosure Date: February 28, 2024 (last updated February 26, 2025)
Potential Cross-Site Scripting (XSS) in the page editing area.
Attacker Value
Unknown

CVE-2024-1632

Disclosure Date: February 28, 2024 (last updated February 26, 2025)
Low-privileged users with access to the Sitefinity backend may obtain sensitive information from the site's administrative area.
Attacker Value
Unknown

CVE-2024-1568

Disclosure Date: February 28, 2024 (last updated February 26, 2025)
The Seraphinite Accelerator plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.20.52 via the OnAdminApi_HtmlCheck function. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Attacker Value
Unknown

CVE-2023-33870

Disclosure Date: February 14, 2024 (last updated February 26, 2025)
Insecure inherited permissions in some Intel(R) Ethernet tools and driver install software may allow an authenticated user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2024-1075

Disclosure Date: February 05, 2024 (last updated February 14, 2024)
The Minimal Coming Soon – Coming Soon Page plugin for WordPress is vulnerable to maintenance mode bypass and information disclosure in all versions up to, and including, 2.37. This is due to the plugin improperly validating the request path. This makes it possible for unauthenticated attackers to bypass maintenance mode and view pages that should be hidden.
Attacker Value
Unknown

CVE-2024-25089

Disclosure Date: February 04, 2024 (last updated February 26, 2025)
Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC named pipes.
Attacker Value
Unknown

CVE-2023-4472

Disclosure Date: February 01, 2024 (last updated February 26, 2025)
Objectplanet Opinio version 7.22 and prior uses a cryptographically weak pseudo-random number generator (PRNG) coupled to a predictable seed, which could lead to an unauthenticated account takeover of any user on the application.